Back to skill

Security audit

Yufluent Clawhub Publish Yufluentcn Shopify Operator

Security checks for vulnerabilities and agentic risk

Overview

This Shopify coaching skill is mostly purpose-aligned, but it needs review because it can send the user's API token and store/business context to a configurable endpoint and has an avoidable local import-path risk.

Install only if you trust Yufluent and your OpenClaw environment. Set TOKENAPI_BASE_URL only to a trusted HTTPS Yufluent endpoint or a loopback development proxy, avoid putting customer/payment data in prompts, keep the TOKENAPI_KEY private, and install in a directory where sibling _shared paths cannot be modified by untrusted users.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/yufluent_api.py:20
Finding

Bearer Token and Business Data Can Be Transmitted over Unencrypted HTTP

Content
View full analysis
str: base = (base_url or "").strip().rstrip("/") if not base: base = "http://localhost:8080/v1" if base.endswith("/v1"): return base return f"{base}/v1" ``` ```python def _auth_headers(api_key: str) -> dict[str, str]: return { "Authorization": f"Bearer {api_key}", "Accept": "application/json", } ``` ```python def _post_json( url: str, *, api_key: str, body: dict[str, Any] | None = None, timeout: float, ) -> requests.Response: kwargs: dict[str, Any] = { "headers": _json_headers(api_key) if body is not None else _auth_headers(api_key), "timeout": timeout, } if body is not None: kwargs["json"] = body return requests.post(url, **kwargs) ``` ```python def run_skill( skill_id: str, payload: dict[str, Any], *, api_key: str | None = None, base_url: str | None = None, timeout: float = 120.0, ) -> dict[str, Any]: key = (api_key or os.getenv("TOKENAPI_KEY", "")).strip() if not key: msg = ( "未配置 TOKENAPI_KEY。\n" "新用户请前往 https://claw.changzhiai.com/login 注册,即送体验积分。\n" "获取密钥后设置环境变量:export TOKENAPI_KEY=tk-..." ) raise YufluentApiError(msg) root = base_url or os.getenv("TOKENAPI_BASE_URL", "") url = skill_run_url(root, skill_id) try: resp = _post_json(url, api_key=key, body=payload, timeout=timeout) ``` ### Technical Analysis The API base URL is accepted without validating its scheme or destination. Although the default `http://localhost:8080/v1` endpoint can be appropriate for a local proxy ...[truncated 1955 chars]
Remediation
View remediation
str: parsed = urlsplit(url) if parsed.username or parsed.password: raise ValueError("Embedded URL credentials are not allowed") hostname = parsed.hostname if not hostname: raise ValueError("API URL must include a hostname") is_loopback = hostname == "localhost" try: is_loopback = is_loopback or ipaddress.ip_address(hostname).is_loopback except ValueError: pass if parsed.scheme != "https" and not ( parsed.scheme == "http" and is_loopback ): raise ValueError("HTTPS is required for non-loopback API endpoints") return url ``` ]]>

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/run.py:8
Finding

External Shared Directory Takes Precedence over the Bundled Bootstrap Module

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tainted flow: 'url' from os.getenv (line 271, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The code allows the request destination to be derived from TOKENAPI_BASE_URL or a caller-supplied base_url with no validation, then sends the Bearer API key and request payload to that URL. If an attacker can influence environment variables or function inputs, they can redirect traffic to an arbitrary host, causing credential exfiltration and leakage of user data; the default use of plain HTTP for localhost also weakens transport guarantees.

Content

Scanner excerpt · scripts/yufluent_api.py (reported line 150)May include surrounding context.

python
}
    if body is not None:
        kwargs["json"] = body
    return requests.post(url, **kwargs)


def _raise_for_status(resp: requests.Response) -> None:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

powershell
cd skills\yufluentcn-shopify-operator
pip install -r requirements.txt
copy .env.example .env
# 编辑 TOKENAPI_KEY、TOKENAPI_BASE_URL

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
## 快速开始(3 步,60 秒)

1. **注册获取 API 密钥** → https://claw.changzhiai.com/login (新用户即送体验积分,无需绑卡)
2. **设置环境变量**:export TOKENAPI_KEY=*** 或写入 .env 文件
3. **运行**:参照下方 Examples 示例执行 python scripts/run.py ...

> 还没注册?前往 https://claw.changzhiai.com/login 免费获取密钥。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes the skill as a Chinese Shopify operations coach using Chinese-only natural language, which indicates a language constraint. There is no indication that users can choose another language or that the Chinese-only behavior is a documented, justified regional requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code sets --lang to zh by default, which means the skill will operate in Chinese unless the user explicitly overrides it. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The top-level docstring characterizes the module as a minimal client, which suggests straightforward skill API forwarding. However, the implementation also includes POSTs to /agent/outcomes and a fallback path through /agent/turn that invokes a wider orchestration interface, expanding behavior beyond a simple direct skill runner.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The client defaults to an HTTP base URL at L024, and later sends an Authorization bearer token and request payloads via requests.post. While the code documents that it is a cloud thin client, it provides no user-facing warning, confirmation, or visible logging that credentials and skill data may be transmitted over the network.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The docstrings and constructed user_message text are written to direct interaction in Chinese, including imperative text such as '请直接执行技能'. There is no indication that users can choose their language or that the Chinese-only behavior is a justified locale restriction, so this may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

L098 states the skill does not directly connect to Shopify Admin, which is true literally, but the surrounding workflow and examples show it sends store context such as store_url to a remote Yufluent API for processing. This is not a hard contradiction about Shopify Admin access itself, but the documentation may give a more limited impression than the actual cloud-assisted analysis behavior.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified as requests>=2.31.0 without an upper bound or exact pin, which makes builds non-reproducible and can silently pull in different versions over time. This increases supply-chain risk and makes it harder to verify whether the installed version is affected by known vulnerabilities or behavioral changes.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Because requests is not pinned, there is no reliable way to determine which release will actually be installed, and some possible versions may include known advisories. The danger here is uncertainty: a deployment could resolve to a vulnerable version depending on environment, mirrors, or future releases, undermining vulnerability management.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language documentation in the file is written exclusively in Chinese, indicating a locale/language assumption without any opt-in or explanation that this skill is region-specific. The policy requires flagging language or locale constraints when the skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.