Back to skill

Security audit

探店搭子

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Chinese restaurant recommendation skill that uses Baidu Maps for location search and a bundled fallback database, with privacy and dependency caveats but no hidden or destructive behavior found.

Install only if you are comfortable sending the location or address you provide, plus restaurant-search preferences, to Baidu Maps. Prefer coarse locations when possible, keep the Baidu API key in an environment variable, and consider pinning `requests` before production use. Do not rely on the advertised budget filtering as a strict constraint in this version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned Third-Party Dependency Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 6-9
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

yaml
metadata:
  openclaw:
    emoji: 🍜
    requires:
      bins: ["python"]
      pip: ["requests"]

Technical Analysis

The Skill declares requests as an installation requirement without specifying a reviewed version, dependency lockfile, package hash, or trusted package-index restriction. Consequently, dependency resolution can select a different package release over time, making the installed code differ from the version originally audited.

Although the declared package name is legitimate and no malicious dependency is included in the repository, this configuration exposes the installation process to mutable upstream releases and package-index compromise. Python packages can execute code during installation and subsequently when imported by baidu_map_client.py. A malicious dependency release or compromised package source could therefore introduce code that was not present during this audit.

Attack Path

  1. An attacker compromises the configured Python package index, an upstream dependency release, or the dependency distribution process.
  2. The attacker publishes or serves a malicious version of requests or one of its transitive dependencies.
  3. The Skill is installed or provisioned in a new environment using the unpinned pip: ["requests"] requirement.
  4. The package resolver selects the attacker-controlled release because no version or integrity hash is enforced.
  5. Malicious package code executes during installation or when requests is imported by baidu_map_client.py.
  6. The malicious code operates with the permissions of the account running the Skill installation or Agent process.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the Skill installer or Agent r ...[truncated 385 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin requests to a specifically reviewed version rather than allowing unconstrained resolution, for example:
    yaml
    pip: ["requests==2.32.5"]
    
  2. Use a dependency lockfile that records all transitive dependency versions.
  3. Require cryptographic hashes for downloaded distributions, such as through a hash-locked requirements file and pip install --require-hashes.
  4. Install dependencies only from an approved HTTPS package index, and disable untrusted supplemental indexes.
  5. Periodically review and deliberately update pinned versions after vulnerability and provenance checks.
  6. Perform installation in an isolated, least-privileged environment without unnecessary credentials or access to sensitive host files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior understates what the skill actually needs to do operationally: it relies on external network transmission and local environment/file access while presenting itself mainly as a recommendation assistant. That mismatch can mislead reviewers and users about data handling and trust boundaries, increasing the chance that location data is shared without fully informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is entirely framed in Chinese and presents the assistant persona and usage examples only in Chinese, with no indication that other languages are supported or that the user can opt into a preferred locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares capabilities implying network access, environment-variable access, file reads, and shell availability, but does not explicitly scope or constrain those tools. This weakens least-privilege protections and makes unintended or expanded data access harder to audit, especially because the workflow involves external requests and local file fallback.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L003 将触发条件描述为“当用户想去某个地方吃饭、探店,或者询问附近有什么好吃的时使用”,范围非常宽,覆盖大量日常闲聊式表达,但没有给出明确边界或排除条件。文档虽在后文给出示例,但未说明哪些相似表达不应触发,也未限制为特定命令或上下文。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow instructs the skill to collect user location and send it to an external map provider, but it lacks a clear upfront notice that the location will be transmitted off-platform. Location data is sensitive, and silent or implicit sharing can expose a user's whereabouts and habits to third parties without meaningful consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This external transmission point sends user-supplied address/location information to the Baidu geocoding API. In context, the transmission is functional rather than malicious, but it still exposes sensitive location data to a third party and therefore creates privacy and compliance risk if not transparently disclosed and constrained.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
### 步骤2:解析位置 + 确认

- 调用百度地理编码API,将用户输入的地址转换为经纬度坐标
- API端点:`https://api.map.baidu.com/geocoding/v3/`
- 确认定位结果,如:"定位到杭州西湖断桥附近,对吗?"
- 如果定位失败,请用户重新描述或提供更具体的位置

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This external transmission point sends geolocation and search preferences to the Baidu Places API to retrieve nearby restaurants. Although core to the skill's function, it reveals sensitive contextual information such as a user's whereabouts and dining interests to an external service.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
### 步骤5:查询餐厅

- 调用百度地图周边搜索API
- API端点:`https://api.map.baidu.com/place/v2/search`
- 参数:
  - `ak`: API Key
  - `query`: 搜索关键词(根据用户选择的美食类型)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The API documentation embeds a concrete external geocoding endpoint and normalized request structure for transmitting addresses. This is not malicious, but it confirms the skill design includes third-party sharing of potentially sensitive location inputs, which is risky without strong disclosure and permission boundaries.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

将地址转换为经纬度坐标

text
GET https://api.map.baidu.com/geocoding/v3/
参数:
  - ak: API Key
  - address: 用户输入的地址

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documented nearby-search endpoint transmits coordinates and food preferences externally. In a food-discovery skill this is expected contextually, which makes it less suspicious than in an unrelated skill, but it still represents genuine privacy-sensitive data flow to a third party.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

根据坐标搜索附近餐厅

text
GET https://api.map.baidu.com/place/v2/search
参数:
  - ak: API Key
  - query: 搜索关键词(如"美食"、"火锅"、"日料")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill’s stated purpose is to recommend nearby restaurants based on location and preferences. While using a map API is expected, spawning a local subprocess to query Windows user environment variables is not an obvious requirement of that purpose and introduces an additional host-interaction capability beyond normal API client behavior.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · baidu_map_client.py (reported line 54)May include surrounding context.

python
# 方式2:Windows用户环境变量(解决子进程继承问题)
        try:
            import subprocess
            result = subprocess.run(
                ['powershell', '-Command', 
                 '[Environment]::GetEnvironmentVariable("BAIDU_MAP_API_KEY", "User")'],
                capture_output=True, text=True, timeout=5

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description says it can recommend restaurants based on location, time, taste preference, and budget. In the actual recommend flow, the budget parameter is accepted and echoed back in the result, but it is never used in keyword generation, API search, filtering, or scoring, so the behavior does not match the claimed budget-sensitive functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends user-provided location data to an external map service for geocoding and nearby search, but the code provides no explicit consent notice or privacy warning at the point of collection. Because precise location can be sensitive personal data, silent transmission increases privacy risk, especially if users are unaware a third party will receive it.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/baidu_map_api.md (reported line 7)May include surrounding context.

请求地址

text
https://api.map.baidu.com/geocoding/v3/?address={address}&output=json&ak={your-ak}

请求参数

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/baidu_map_api.md (reported line 39)May include surrounding context.

请求地址

text
https://api.map.baidu.com/geocoding/v3/?address={address}&output=json&ak={your-ak}

请求参数

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest metadata uses only Chinese-language tags such as "美食" and "餐厅推荐", which indicates the skill is categorized for a specific language/locale without any accompanying note that users can choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This JSON data uses Chinese city names and descriptions throughout, which effectively fixes the skill content to a specific language/locale. Under the policy, language constraints should either be user-selectable or clearly documented as region-specific and justified; this file provides neither context nor opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

User-facing text, prompts, help output, and documentation strings are consistently Chinese-only, and the skill does not provide any opt-in or language selection mechanism. This can violate language or locale policy when a skill forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file presents all instructions and API descriptions only in Chinese, which may impose a language constraint without any stated user opt-in or justification. Under the policy rule for natural-language violations, forcing a specific language can be an issue when the intended audience or locale limitation is not explicitly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

该 markdown 文件标题及全文均以中文撰写,且未声明这是面向特定中文场景的限定说明,也未提及是否支持其他语言。按照语言/locale 政策检查标准,这可能被理解为默认强制特定语言而缺少用户选择或明确 justification。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.