Back to skill

Security audit

跨境卫士客户端

Security checks for vulnerabilities and agentic risk

Overview

This API helper is mostly coherent, but it ships what appears to be a real app ID and secret and tells agents to look for broad local credentials.

Install only after the publisher removes and rotates the embedded app credentials and narrows credential lookup to service-specific variables. If you use it before then, review every generated curl command, avoid generic tokens in the environment, and do not let it read unrelated local config.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/auth.md:13
Finding

Plaintext API Credentials Embedded in Authentication Documentation

Content
View full analysis

Vulnerability Details

File Location: references/auth.md, lines 13–15
Vulnerability Type: Hardcoded credentials and plaintext sensitive data
Risk Level: High

markdown
- `x-app-id`:   TinqIbRCZdwzpkaD
- `x-app-secret`:  BcTmTA6gN8phMvSI2wZj5YO7

二者均为必填。

Technical Analysis

The authentication documentation contains a complete application identifier and application secret in plaintext. These values appear to be directly usable in the required x-app-id and x-app-secret request headers.

Embedding credentials in a distributable Skill package exposes them to every person or process with access to the package, its source archive, cached copies, or repository history. This also conflicts with the secret-handling guidance in SKILL.md, which states that secrets must never be printed in full.

The bundled OpenAPI specification defines authenticated operations for listing, opening, and closing shops. If the exposed credentials remain valid and an attacker can reach the actual API service, they may use the credentials to invoke those operations.

Attack Path

  1. An attacker obtains or reads the Skill package.
  2. The attacker opens references/auth.md and extracts the plaintext x-app-id and x-app-secret.
  3. The attacker identifies the actual API base URL through deployment information, local configuration, logs, or related documentation.
  4. The attacker submits both values as authentication headers.
  5. The attacker calls GET /v1/shops to enumerate accessible shops.
  6. The attacker calls POST /v1/shops/{id}/open or POST /v1/shops/{id}/close.
  7. Opening a shop may return Selenium connection details, including an address and port, as defined by the bundled OpenAPI specification.

Impact Assessment

Successful exploitation could provide unauthorized authenticated access within the privileges assigned to the exposed application credentials. Based on the documented endpoints, the poten ...[truncated 480 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed application identifier and secret immediately.
  2. Remove all real credential values from the current package and repository history.
  3. Replace credentials in documentation with unmistakable placeholders, such as:
    text
    x-app-id: ${KJW_APP_ID}
    x-app-secret: ${KJW_APP_SECRET}
    
  4. Store operational credentials in an approved secret manager or dedicated environment variables.
  5. Ensure credentials are injected only at runtime and are never written to generated commands, logs, transcripts, or error messages in full.
  6. Add automated secret scanning to the development and release process.
  7. Restrict the credentials server-side using least privilege, network allowlists, expiration, rotation, and per-client audit logging.
  8. Review API access logs for unauthorized use of the exposed values.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:49
Finding

Overbroad Discovery and Use of Local Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 49–63
Vulnerability Type: Excessive credential access scope
Risk Level: Medium

markdown
- If credentials are already available in environment variables or local config, use them.
- Never print secret values in full.
- If a token or key must be shown for debugging, redact the middle portion.

Common environment variable patterns to check:

- `BASE_URL`
- `API_APP_ID`
- `API_APP_SECRET`
- `X_APP_ID`
- `X_APP_SECRET`
- `API_KEY`
- `ACCESS_TOKEN`
- `BEARER_TOKEN`

Technical Analysis

The Skill instructs the Agent to use credentials found in environment variables or unspecified local configuration. It also suggests generic names such as API_KEY, ACCESS_TOKEN, and BEARER_TOKEN.

Generic credential variables may belong to unrelated applications or services. Searching unspecified local configuration and selecting credentials based only on broad variable names violates least-privilege principles and does not establish that the credential was intended for this API.

The documented API requires an application identifier and secret through the x-app-id and x-app-secret headers. Generic bearer tokens and unrelated API keys are not required by the specification. Consequently, the broader discovery instructions create unnecessary access to secrets outside the Skill’s legitimate task scope and may cause an unrelated credential to be disclosed to the configured API endpoint.

Attack Path

  1. The Skill is invoked in an environment containing credentials for multiple services.
  2. Following the Skill instructions, the Agent checks environment variables or local configuration.
  3. The Agent discovers a generic variable such as API_KEY, ACCESS_TOKEN, or BEARER_TOKEN.
  4. Without reliable service binding or explicit user authorization, the Agent treats the value as a candidate credential for this API.
  5. The Agent may use or expose t ...[truncated 1040 chars]
Remediation
View remediation

Remediation Suggestions

  1. Restrict credential lookup to dedicated, service-specific variable names, such as KJW_APP_ID and KJW_APP_SECRET.
  2. Remove generic credential candidates including API_KEY, ACCESS_TOKEN, and BEARER_TOKEN.
  3. Prohibit scanning unspecified local configuration files.
  4. Require explicit user approval before reading credentials from any local source not specifically configured for this Skill.
  5. Validate that credentials are bound to the expected API origin before transmission.
  6. Maintain an allowlist of approved API hosts and require HTTPS for non-loopback remote endpoints.
  7. Avoid displaying complete credentials in generated curl commands; use environment-variable references instead.
  8. Ensure debug output redacts header values and does not persist credentials in logs or conversation history.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation includes what appear to be concrete API credentials (x-app-id and x-app-secret) rather than placeholders, which exposes secrets to anyone with access to the skill package. In the context of an API client skill, this is especially dangerous because users or downstream agents may treat these values as valid production credentials and use them directly, enabling unauthorized API access, abuse, or credential theft.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is presented entirely around a Chinese-language client name and context, and nowhere indicates that users may choose another language or locale for interaction. Under the policy for natural-language violations, forced language/locale behavior without opt-in should be flagged unless clearly justified as region-specific; that justification is not stated in this file.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: 跨境卫士客户端
description: Use this skill when the user wants to call, test, debug, or integrate the 跨境卫士客户端 API defined by the bundled OpenAPI specification. Handles endpoint discovery, request construction, authentication, parameter validation, curl generation, and response interpretation for this API.
version: 1.0.0
metadata:
  openclaw:

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openapi.yaml (reported line 128)May include surrounding context.

yaml
type: integer
          example: 10

    ShopListResponse:
      type: object
      required:
        - model

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openapi.yaml (reported line 182)May include surrounding context.

yaml
type: integer
          example: 10

    ShopListResponse:
      type: object
      required:
        - model

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The API title and descriptive text are presented exclusively in Chinese, and the specification does not state that the skill is region-specific or that users may choose another language. This can violate language/locale policy when a skill effectively forces one language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.