Back to skill

Security audit

明日DMP智能组合圈人

Security checks for vulnerabilities and agentic risk

Overview

The skill’s DMP audience-building purpose is legitimate, but its packaged scripts can perform authenticated account-changing creation actions without the documented approval enforcement and can execute a loosely discovered authentication helper.

Review before installing. Use this only if you are comfortable granting it access to DMP credentials and allowing it to create DMP audience resources. Prefer a version that verifies the exact mingdata-dmp-auth package before execution and enforces a user-approved final plan before any final audience creation.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/find_auth_skill.py:32
Finding

Authentication Helper Discovery Can Execute a Spoofed Skill Script

Content
View full analysis

Vulnerability Details

File Location: scripts/find_auth_skill.py:32-48, with the execution sink at scripts/dmp_api_client.py:47-55
Vulnerability Type: Untrusted tool discovery and execution
Risk Level: High

Complete Code Snippet

Discovery logic in scripts/find_auth_skill.py:

python
scan_dirs = [
    Path.home() / ".skills",
    Path.home() / ".openclaw" / "workspace" / "skills",
    Path.home() / ".openclaw" / "skills",
    Path.cwd() / ".skills",
]
for scan_dir in scan_dirs:
    if scan_dir.exists():
        for skill_dir in scan_dir.iterdir():
            if skill_dir.is_dir():
                auth_path = skill_dir / "scripts" / "minri_dmp_api.py"
                if auth_path.exists():
                    try:
                        with open(auth_path, 'r', encoding='utf-8') as f:
                            content = f.read(500)
                            if "明日DMP" in content or "mingdata" in content.lower():
                                return auth_path
                    except (OSError, UnicodeDecodeError):
                        continue

Execution sink in scripts/dmp_api_client.py:

python
def _call(self, method: str, endpoint: str, body: Optional[Dict[str, Any]] = None) -> Dict[str, Any]:
    """通过subprocess调用鉴权技能的minri_dmp_api.py"""
    cmd = ["python3", str(self.auth_skill_path), method.upper(), endpoint]
    if body is not None:
        cmd.append(json.dumps(body, ensure_ascii=False))
    result = subprocess.run(
        cmd, capture_output=True, text=True, timeout=self.timeout
    )

Technical Analysis

The fallback discovery mechanism scans every immediate child directory under several skill roots, including .skills beneath the current working directory. It does not require the child directory to be named mingdata-dmp-auth. A candidate is accepted merely because it contains scripts/minri_dmp_api.py and one of two easily forged strings appears in the first 500 characters.

DmpClient sub ...[truncated 1867 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the keyword-based dynamic scan and only accept the exact canonical installation path for mingdata-dmp-auth.
  2. Resolve the selected path with Path.resolve() and verify that it remains beneath the expected trusted skill directory.
  3. Reject symlinks and files or parent directories writable by unauthorized local principals.
  4. Verify the helper against a trusted signed manifest or pinned cryptographic digest before execution.
  5. Validate package metadata and require the skill directory name and identifier to match mingdata-dmp-auth.
  6. Do not search relative to Path.cwd() for authentication code.
  7. Prefer importing or invoking the helper through a trusted registry that returns verified package identities rather than searching the filesystem.
  8. Fail closed when the verified helper is unavailable instead of selecting a loosely matched replacement.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_combined_crowd.py:24
Finding

Direct Final-Creation Entry Point Does Not Enforce Required User Approval

Content
View full analysis

Vulnerability Details

File Location: scripts/create_combined_crowd.py:24-49
Vulnerability Type: Missing authorization gate for a remote state-changing operation
Risk Level: Medium

Complete Code Snippet

python
def main():
    ap = argparse.ArgumentParser()
    add_auth_args(ap)
    ap.add_argument("--brand-id", nargs="+", default=None, help="可选:品牌ID/名称列表;不传则按默认不传")

    ap.add_argument("--name", required=True)
    ap.add_argument("--track-type", required=True, choices=["MOBILE", "PC", "OTT"])
    ap.add_argument("--id-types", required=True, nargs="+")
    ap.add_argument("--data", required=True, help="data规则:JSON字符串或JSON文件路径")
    args = ap.parse_args()

    data_rules = load_json_arg(args.data)
    if not isinstance(data_rules, list) or len(data_rules) == 0:
        raise SystemExit("data 必须为非空 list")

    # 兼容:若用户/上游给出brandId则透传;未给则按默认不传
    body = {"name": args.name, "trackType": args.track_type, "idTypes": args.id_types, "data": data_rules}
    try:
        if hasattr(args, 'brand_id') and args.brand_id:
            body["brandId"] = args.brand_id
    except Exception:
        pass

    client = DmpClient.from_config(ak=args.ak, sk=args.sk, base_url=args.base_url)
    resp = client.post(CREATE_PATH, body)
    ensure_ok(resp)
    audience_id = (resp.get("data") or {}).get("audienceId")

The corresponding requirement in SKILL.md:88-89 is:

text
5. Step 13: 方案确认是强制卡点;未确认不得执行最终创建。

Technical Analysis

The Skill specification declares final-plan confirmation to be a mandatory gate before creating the final audience. However, the actual final-creation script accepts ordinary creation parameters and immediately sends an authenticated request to /audience/manage/combine/create.

The script does not require:

  • A confirmation flag.
  • A plan identifier approved during Step 13.
  • A cryptographically bound approval artifact.
  • A digest tying approval to the exact name, rules, tracking type, and identifier types.
  • An interacti ...[truncated 1930 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make final creation accessible only through the workflow driver and complete its implementation through Step 14.
  2. Require a driver-issued approval artifact generated only after Step 13 confirmation.
  3. Bind the approval artifact to a canonical digest of the exact:
    • Audience name.
    • Rule payload.
    • Tracking type.
    • Identifier types.
    • Brand identifiers, if present.
  4. Recompute and verify the digest immediately before the API request, rejecting any post-approval change.
  5. Include expiration, run identifier, and single-use protections in the approval artifact.
  6. Default the standalone script to dry-run behavior and require an explicit verified approval token for remote mutation.
  7. Log the approved plan digest and resulting audience ID without recording credentials.
  8. Reject direct calls that cannot demonstrate completion of the required Step 13 gate.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (81)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims full workflow execution and final creation readiness, but the documentation itself notes important later steps are not implemented. In a privileged agent environment, such overclaiming is dangerous because it can conceal missing approvals and validation before state-changing actions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/api_reference.md:27