Back to skill

Security audit

Yufluent Clawhub Publish Yufluentcn Review Intel

Security checks for vulnerabilities and agentic risk

Overview

This review-analysis skill is mostly coherent, but it can send both the user’s API token and review contents to an arbitrary configured endpoint without HTTPS or destination validation.

Install only if you trust Yufluent/OpenClaw with the reviews you submit and the TOKENAPI_KEY account. Do not include buyer PII or confidential business data unless your policy allows cloud processing, and avoid setting TOKENAPI_BASE_URL unless it points to a trusted HTTPS endpoint or a trusted local proxy. Rotate the token if it may have been used with an untrusted endpoint.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/yufluent_api.py:21
Finding

Bearer Token and Review Data Can Be Transmitted over an Untrusted Plaintext Endpoint

Content
View full analysis
str: base = (base_url or "").strip().rstrip("/") if not base: base = "http://localhost:8080/v1" if base.endswith("/v1"): return base return f"{base}/v1" ``` ```python def _auth_headers(api_key: str) -> dict[str, str]: return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", } def _json_headers(api_key: str) -> dict[str, str]: return {**_auth_headers(api_key), "Content-Type": "application/json"} ``` ```python def _post_json( url: str, *, api_key: str, body: dict[str, Any] | None = None, timeout: float, ) -> requests.Response: kwargs: dict[str, Any] = { "headers": _json_headers(api_key) if body is not None else _auth_headers(api_key), "timeout": timeout, } if body is not None: kwargs["json"] = body return requests.post(url, **kwargs) ``` ```python root = base_url or os.getenv("TOKENAPI_BASE_URL", "") url = skill_run_url(root, skill_id) try: resp = _post_json(url, api_key=key, body=payload, timeout=timeout) ``` ### Technical Analysis The client obtains its API endpoint from the `TOKENAPI_BASE_URL` environment variable and accepts the value without validating its scheme or destination. The URL can therefore identify an arbitrary HTTP or HTTPS server. Every request includes the `TOKENAPI_KEY` bearer credential in the `Authorization` header. Skill requests also contain the complete review payload, including any product information or personal data inadvertently present in the supplied reviews. The default `http://localhost:8080/v1 ...[truncated 2031 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependency Produces Non-Reproducible Installations

Content
View full analysis
=2.31.0 ``` The same open-ended requirement is also present in the installation metadata in `SKILL.md:17`: ```text "packages":["requests>=2.31.0"] ``` ### Technical Analysis The dependency declaration specifies only a minimum version. Any future `requests` release satisfying the constraint can consequently be selected at installation time. No lock file or package hash is supplied to establish the exact reviewed artifact. The package name is legitimate, and the audit found no evidence of typosquatting, dependency confusion, or a currently malicious dependency. The concern is supply-chain hardening: installations performed at different times can resolve different code that was not part of this audit. Because `requests` is imported by `scripts/yufluent_api.py`, a compromised or unexpectedly incompatible selected release would operate in the Skill process and have access to its environment, bearer token, review payload, filesystem permissions, and network permissions. ### Attack Path 1. A future dependency release or configured package index becomes compromised, or returns an unauthorized artifact matching `requests>=2.31.0`. 2. A user installs the project using `pip install -r requirements.txt` without a trusted lock file or hash verification. 3. The resolver installs the matching unreviewed artifact. 4. The Skill imports `requests` when `scripts/yufluent_api.py` is loaded. 5. Malicious package code executes with the privileges of the user running the Skill. 6. That code could access the process environment, including `TOKENAPI_KEY`, inspect submitted reviews, or make unauthorized network requests. This path depends on compromise of the dependency distribution channel or a future matching artifact; no such compromise was established during this static audit. ...[truncated 675 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (12)

Tainted flow: 'url' from os.getenv (line 271, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The code allows the HTTP destination to be derived from TOKENAPI_BASE_URL or a caller-supplied base_url and then sends authenticated requests with the Bearer API key to that URL. If an attacker can influence that configuration, they can redirect requests to an attacker-controlled host and exfiltrate the credential or force the client to contact internal services, making this a real SSRF/credential-leak risk in untrusted deployment contexts.

Content

Scanner excerpt · scripts/yufluent_api.py (reported line 150)May include surrounding context.

python
}
    if body is not None:
        kwargs["json"] = body
    return requests.post(url, **kwargs)


def _raise_for_status(resp: requests.Response) -> None:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
## 快速开始(3 步,60 秒)

1. **注册获取 API 密钥** → https://claw.changzhiai.com/login (新用户即送体验积分,无需绑卡)
2. **设置环境变量**:export TOKENAPI_KEY=*** 或写入 .env 文件
3. **运行**:参照下方 Examples 示例执行 python scripts/run.py ...

> 还没注册?前往 https://claw.changzhiai.com/login 免费获取密钥。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and description are entirely Chinese and describe the skill as a Chinese review-analysis workflow, while the example invocation also fixes --lang zh. There is no visible opt-in, language-choice guidance, or documented justification that the skill is intentionally region- or locale-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The metadata and workflow constrain language handling to a fixed set of languages (zh, en, es, de, fr, ja) and the instructions tell the agent to confirm lang only from that set. This can constitute a language/locale policy issue because the skill imposes a language restriction rather than offering broader user choice or clearly justifying the limitation as a region-specific requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are broad enough to match ordinary review-analysis requests such as 'analyze these reviews' or 'what are customers complaining about,' which can cause the skill to activate unexpectedly in unrelated contexts. Over-broad invocation increases the chance of unintentional routing of user data to this cloud-backed skill and weakens user control over when external processing occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language strings in the module docstring and function docstrings are written exclusively in Chinese, which imposes a specific language choice on users or maintainers without offering a language option or documenting a region-specific reason. This matches the policy category for language or locale constraints lacking user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The --lang argument defaults to zh, which imposes a specific language choice unless the user overrides it manually. This is a natural-language policy concern because the skill does not prompt for or otherwise obtain explicit user opt-in to the default locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends review text and optional product information to a remote cloud API via run_skill(), but it provides no explicit warning, consent prompt, or data-handling notice before transmission. In a review-analysis context, users may paste proprietary, personal, or regulated content, so silent network exfiltration to a third-party service creates a real confidentiality and compliance risk even if the feature is expected behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code constructs a fixed Chinese user_message such as “请直接执行技能...” and parameter lines, which imposes a specific language on downstream interaction. There is no opt-in, fallback, or documented rationale that this skill is intentionally China/Chinese-only, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown includes setting TOKENAPI_KEY and invoking a cloud-based review analysis command, but it does not warn users that they are supplying a sensitive credential or that review data will be sent to a remote service. For a README describing a cloud execution workflow, a brief disclosure about credential handling and remote data transmission is expected.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified as requests>=2.31.0, which permits installation of many future versions and does not guarantee a reproducible, reviewed package set. In a security-sensitive skill, this increases supply-chain risk because vulnerable or behavior-changing releases could be pulled in without explicit validation.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest references requests without pinning an exact version, while known advisories exist for some releases of that package. Because the resolved version is unverifiable from this file alone, deployments may install an affected version, exposing the skill to known issues such as credential leakage or other request-handling flaws depending on the environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.