Back to skill

Security audit

Road Trip Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed China road-trip planning skill that uses Amap APIs and a stated external dependency, with some install and QR-download cautions but no hidden or destructive behavior found.

Install only if you need mainland China driving-route planning with Amap. Verify that the personal-map dependency is the intended @lbs-amap package, use a scoped Amap API key, and avoid sharing sensitive trip details if you do not want them sent to Amap or official live-information sources.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned External Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29–40
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet

markdown
| `lbs-amap/personal-map` | [ClawHub](https://clawhub.ai/lbs-amap/personal-map) | Amap Web Service API wrapper / 高德 Web 服务 API 封装。安装命令:`openclaw skills install personal-map`。提供 `AMapPersonalMapClient` 类(import 路径 `scripts.amap_personal_map_client`),本仓库自身不含该脚本。 |
text
1. personal-map skill installed? → No → 提示: "请先安装 personal-map skill,运行: openclaw skills install personal-map"

The same unpinned command is reiterated at SKILL.md:339.

Technical Analysis

The Skill instructs users or agents to install an external dependency using the short, unversioned identifier personal-map. Although the documentation identifies the expected project as lbs-amap/personal-map, the installation command does not include that namespace, a reviewed version, an immutable digest, or a signature verification step.

Consequently, dependency resolution may retrieve a mutable future release or, depending on registry name-resolution behavior, an unintended package. This project contains no local implementation of AMapPersonalMapClient, so the externally installed component supplies all executable behavior associated with API access, route processing, and QR-code generation.

The dependency is expected to read AMAP_API_KEY and perform network operations. A malicious or compromised release would therefore execute in a security-sensitive context.

Attack Path

  1. An attacker compromises the mutable personal-map package, publishes a malicious future release, or registers a package that wins ambiguous short-name resolution.
  2. A user or agent follows the documented command:
    bash
    openclaw skills install personal-map
    
  3. The package manager installs the attacker-controlled dependency because no version, digest, or verified publisher identity is required ...[truncated 829 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use the fully qualified package identity rather than the ambiguous short name.
  2. Pin the dependency to a reviewed version and, where supported, an immutable content digest.
  3. Verify the package publisher, registry signature, and expected checksum before installation.
  4. Document a known-good dependency version and a controlled upgrade-review process.
  5. Grant the dependency only the minimum filesystem, environment-variable, and network access necessary.
  6. Avoid exposing unrelated credentials to the process that loads the dependency.
  7. If the package manager cannot provide immutable pinning and authenticity verification, vendor and review the required implementation or use a trusted lockfile mechanism.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:289
Finding

Unvalidated Remote QR URL Is Written to a Predictable Temporary Path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 289–293
Vulnerability Type: Unrestricted remote resource retrieval and unsafe temporary-file handling
Risk Level: Medium

Vulnerable Code Snippet

python
qr_url = result["qr_code_url"]
# Download QR image:
import urllib.request
qr_path = "/tmp/road_trip_qr.png"
urllib.request.urlretrieve(qr_url, qr_path)

Technical Analysis

The example treats qr_code_url, supplied through an external API client, as trusted and passes it directly to urllib.request.urlretrieve. It does not validate:

  • The URL scheme, such as requiring HTTPS
  • The destination hostname
  • Redirect targets
  • Resolution to loopback, link-local, or private network addresses
  • Response content type
  • Download size
  • Whether the response is actually a valid image

If the API response or external dependency is compromised, the URL can cause the agent to make a request to an attacker-selected endpoint. Depending on network placement, this may include internal services accessible from the agent environment.

The response is also written to the fixed shared path /tmp/road_trip_qr.png. In a hostile multi-user environment, another local process may pre-create that path as a symbolic link. Because urlretrieve opens the destination for writing, this can overwrite or truncate a different file writable by the agent process. Repeated concurrent runs can also overwrite one another's output.

The downloaded data is not executed by this snippet, so this finding is not classified as remote payload retrieval and execution.

Attack Path

Unrestricted URL retrieval

  1. An attacker compromises or controls the dependency/API response used to produce result.
  2. The attacker returns a qr_code_url pointing to an attacker-controlled host or a reachable internal service.
  3. The Skill calls urlretrieve without scheme, host, redirect, or address validation.
  4. The agent makes the request from its own network context and wr ...[truncated 1435 chars]
Remediation
View remediation

Remediation Suggestions

  1. Parse the URL before retrieval and require HTTPS.
  2. Maintain an allowlist of documented Amap QR-code hostnames.
  3. Resolve the hostname and reject loopback, link-local, private, reserved, and otherwise unexpected IP ranges.
  4. Disable redirects or revalidate the scheme, hostname, and resolved address after every redirect.
  5. Set explicit connection and read timeouts.
  6. Enforce a conservative response-size limit while streaming the download.
  7. Require an expected image content type and verify the image signature before use.
  8. Replace the fixed filename with a securely created unique file:
    python
    import tempfile
    
    with tempfile.NamedTemporaryFile(
        prefix="road_trip_qr_",
        suffix=".png",
        delete=False,
    ) as output:
        qr_path = output.name
    
  9. Ensure the temporary file has restrictive permissions and is not opened through a user-controlled symbolic link.
  10. Remove the temporary file when it is no longer needed and avoid exposing an unvalidated URL as the fallback link.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and activation guidance are broad enough to trigger on generic travel-planning requests, potentially causing the agent to invoke this skill in contexts where the user did not ask for China-only Amap routing or QR generation. Over-broad activation increases the chance of unintended tool use, unnecessary dependency checks, and leakage of user travel details into external APIs without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The trigger list contains only positive matches and omits exclusion rules, so the agent may over-apply the skill to ambiguous user requests. In a tool-using environment, this can lead to unnecessary external API calls, accidental collection or transmission of itinerary data, and confusing behavior when a simpler non-tool response would have been appropriate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes an Amap-based road-trip planner that generates routes, QR codes, and itinerary details using Amap APIs and the personal-map dependency. In Step 6.1, the skill additionally directs the agent to verify closures, weather warnings, and attraction availability from official/current sources, which implies broader live-information retrieval capabilities not explicitly declared in the stated scope or dependencies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.