Back to skill

Security audit

热点聚合监控

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent hot-topic report tool, but it can place untrusted internet content into an agent memory folder without clear isolation or sanitization.

Install only if you are comfortable with a Chinese-language monitoring skill that writes reports and keyword data under /root/clawd/memory/hotspots. Keep USE_REAL_API disabled unless you trust the listed sources, and review generated reports before letting an agent treat them as memory or instructions. Narrow triggers and add sanitization/trust-boundary handling before using it for automated monitoring.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
scripts/generate-report.sh:9
Finding

Untrusted Remote Hotspot Content Is Persisted in Agent Memory

Content
View full analysis
/dev/null else curl -s --max-time 10 "$url" -o "$output" 2>/dev/null fi } ``` Remote hotspot titles are extracted without sanitization or trust metadata. For example, the Weibo source is processed as follows: ```bash fetch_weibo() { log_info "获取微博热搜..." local output="$DATA_DIR/weibo_${DATE}_${TIME}.json" if [[ "$USE_REAL_API" == "true" ]]; then # 尝试真实API(需要代理或特殊处理) local url="https://weibo.com/ajax/side/hotSearch" if fetch_url "$url" "$output.tmp"; then # 解析真实数据 if jq -e '.ok' "$output.tmp" > /dev/null 2>&1; then jq '[.data.realtime[] | {rank: .rank, title: .word, heat: .realpos, tag: .icon_desc}] | {platform: "weibo", date: "'$DATE'", time: "'$TIME'", data: .}' "$output.tmp" > "$output" rm -f "$output.tmp" log_info "微博热搜(真实数据)已保存" return fi fi log_warn "真实API获取失败,使用模拟数据" fi ``` The Douyin integration relies on a third-party aggregation service: ```bash fetch_douyin() { log_info "获取抖音热搜..." local output="$DATA_DIR/douyin_${DATE}_${TIME}.json" if [[ "$USE_REAL_API" == "true" ]]; then # 使用第三方聚合API local url="https://api.oioweb.cn/api/toutiao/douyinHot" if fetch_url "$url" "$output.tmp"; then if jq ...[truncated 5479 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior implies outbound requests to multiple third-party APIs and writes reports/data under /root/clawd/memory, yet the manifest does not transparently declare those capabilities. That mismatch can mislead operators about the skill’s real access needs and makes it easier for risky network/file behaviors to bypass scrutiny, especially when automated scheduling and keyword monitoring are involved.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises and instructs shell-based execution and external data fetching, but declares no explicit tool scope or permissions. This creates a trust and review gap: an agent may invoke shell/network/file-write behavior without clear least-privilege constraints, increasing the chance of unintended command execution or data access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list contains very broad phrases such as common terms for 'hot topics' and 'monitoring', which are likely to match ordinary user conversations. Overbroad activation can cause the skill to run unexpectedly, leading to unintentional network calls, file writes, or collection/processing of user-request context without a clear opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill promotes keyword subscription and push-style monitoring but does not warn users about privacy, retention, or notification implications. Subscription features can encode user interests, brands, or sensitive monitoring targets, and automated notifications may disclose that information or create unwanted surveillance-style behavior if not transparently controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description, keywords, and category indicate the skill is explicitly Chinese-language focused, but the manifest does not mention user choice, opt-in, or a clear justification for restricting interaction to that locale. This can violate language/locale policy when a skill implicitly forces a specific language without offering alternatives or documenting the constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains many broad, common phrases such as '热点', '热搜', '舆情', and '内容监控' that can match ordinary user requests outside the intended scope of this skill. This increases the chance of unintended invocation, causing the agent to activate the skill in contexts where the user did not explicitly request it, which can lead to inappropriate data fetching, privacy surprises, or response hijacking by this skill over more suitable ones.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script automatically executes fetch-hotspots.sh all when the data directory is empty, which is a subprocess invocation and likely performs external data retrieval. Although there is a brief log message, it does not disclose the concrete action of launching another script or that it may fetch data from external sources, so users are not clearly warned about this safety-relevant behavior in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script's user-facing comments, log messages, status text, and usage guidance are entirely in Chinese, which imposes a specific language on users without offering opt-in or an alternative locale. The policy explicitly disallows forcing a language or locale unless the skill provides a choice or clearly documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

When USE_REAL_API=true, the script sends outbound requests to a third-party aggregation service (api.oioweb.cn) without any trust validation, privacy notice, or allowlist enforcement. Even though no obvious secrets are included in the URL here, this introduces supply-chain and data-governance risk because execution depends on an unaudited external service whose responses are trusted and written into local data files.

Content

Scanner excerpt · scripts/fetch-hotspots.sh (reported line 181)May include surrounding context.

sh
if [[ "$USE_REAL_API" == "true" ]]; then
        # 使用第三方聚合API
        local url="https://api.oioweb.cn/api/toutiao/douyinHot"
        if fetch_url "$url" "$output.tmp"; then
            if jq -e '.result' "$output.tmp" > /dev/null 2>&1; then
                jq '{platform: "douyin", date: "'$DATE'", time: "'$TIME'", source: "real", data: [.result[] | {rank: .index, title: .name, play_count: .hot, author: "热门创作者"}]} | .data |= .[:10]' "$output.tmp" > "$output"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script's comments and all user-visible status/report text are hard-coded in Chinese, including usage, warnings, headings, and final output. The policy allows locale constraints only when documented and justified or when users can opt in, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script presents its description and user-facing usage text entirely in Chinese, and later user-visible logs and errors are also Chinese-only. Under the policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains very generic phrases such as '热点', '热搜', and 'hotspot', which are likely to overlap with ordinary user requests rather than explicit invocation of this skill. This can cause unintended activation, routing unrelated conversations into the skill, and potentially expose users to unexpected behavior or outputs in contexts where they did not intend to use the aggregator.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The natural-language instructions, headings, and examples are all presented in Chinese, and the README does not offer an alternative language or state that the skill is intentionally limited to Chinese-speaking users or China-specific workflows. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents generating a report and explicitly states the output path under /root/clawd/memory/hotspots, but it does not warn users that the skill stores generated content on local disk. Because report contents and subscribed keywords may reflect user interests or monitored topics, a brief disclosure about local data storage would improve transparency.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest file contains a user-facing description string only in Chinese, which can violate language/locale policy when the skill forces a specific language without user opt-in. There is no indication elsewhere in the file that users can choose another language or that the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

All user-facing comments and runtime messages in the script are written in Chinese, with no indication that another language is available. This can violate a language/locale policy when a skill imposes a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language description is presented entirely in Chinese, and the manifest does not state that the skill is region-specific or that users can choose their preferred language. This can create a language-policy concern if the broader environment expects language choice rather than a forced locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.