Back to skill

Security audit

Ioc Patrol Report

Security checks for vulnerabilities and agentic risk

Overview

The skill is a report generator, but it ships a plaintext remote PostgreSQL admin-style credential and uses it by default, so it needs review before installation.

Do not install or run this version until the publisher removes the packaged database password, rotates the exposed credential, replaces the postgres account with a least-privilege reporting role, makes environment or secret-manager credentials actually take precedence, and clearly labels live versus mock data in generated reports. If this package was already installed, treat the database credential as compromised and audit related database access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
config.yaml:2
Finding

Hardcoded Credential for a Remote PostgreSQL Superuser Account

Content
View full analysis
^bZsPIX}A&" options: "-c search_path=ioc" ``` The credential is consumed directly by the application in `scripts/generate_report.py:49-59`: ```python db_config = { "host": config["database"]["host"], "port": config["database"]["port"], "dbname": config["database"]["name"], "user": config["database"]["user"], "password": config["database"]["password"], } # If options are configured, add them. if "options" in config["database"]: db_config["options"] = config["database"]["options"] return psycopg2.connect(**db_config) ``` ### Technical Analysis The distributed configuration contains a usable-looking password together with a publicly addressable database hostname, nonstandard PostgreSQL port, database name, and username. Anyone who can read or download the Skill package can recover all information required to attempt authentication. The configured username is `postgres`, which conventionally identifies PostgreSQL's administrative superuser. The report generator only needs to execute aggregate `SELECT` queries, so using an administrative account substantially exceeds the minimum privileges required by the declared reporting functionality. The credential must be treated as compromised even if the database is currently protected by network filtering or the password is no longer valid. Copies may remain in package caches, repository history, audit logs, and downloaded Skill archives. ### Attack Path 1. An attacker downloads or otherwise obtains the Skill package. 2. The attacker opens `config.yaml` and extracts the host, port, database name, username, and password. 3. The attacker attempts a PostgreSQL connection to `hi ...[truncated 1249 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_report.py:17
Finding

Declared Environment-Variable Secret Handling Is Bypassed When Configuration Exists

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
pyproject.toml:8
Finding

Non-Reproducible Dependency Installation Using Open-Ended Version Constraints

Content
View full analysis
=2.9.0", "pyyaml>=6.0", ] ``` The README also recommends unconstrained installation at `README.md:17-23`: ```bash # Clone into the OpenClaw skills directory. git clone ~/.openclaw/skills/ioc-patrol-report cd ~/.openclaw/skills/ioc-patrol-report # Install dependencies. pip install psycopg2-binary pyyaml # Or use uv. uv sync ``` The package metadata repeats lower-bound-only constraints in `package.json:34-38`: ```json "dependencies": { "python": ">=3.10", "psycopg2-binary": ">=2.9.0", "pyyaml": ">=6.0" } ``` ### Technical Analysis The project specifies only minimum dependency versions and does not include a reviewed lockfile or package hashes. Separate installations can therefore resolve to different future releases. This prevents reproducible builds and expands supply-chain exposure to any later compatible package version selected by the resolver. The package names observed during the audit are legitimate and no malicious dependency was identified. The vulnerability is the absence of version and integrity controls, not evidence that the current dependencies are malicious. ### Attack Path 1. An operator follows the documented `pip install` or `uv sync` process. 2. The resolver retrieves the latest versions satisfying the open-ended constraints. 3. A future compromised, malicious, or unexpectedly incompatible release remains eligible for installation. 4. The dependency is installed into the Skill's Python environment. 5. Malicious code in a compromised distribution could execute during installation or when imported by the report generator. This path requires compromise or malicious publication of an eligible dependency release or package-index delivery path. ### I ...[truncated 362 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code broadly aligns with the general idea of generating IOC operations reports for daily/weekly use and supports PostgreSQL connectivity. However, there are material mismatches. The description explicitly claims Markdown/HTML output, but the implementation only saves Markdown files and has no HTML generation. The script also advertises analysis of device status, alarm records, energy data, and work order progress, yet the real-data path does not query alarm data at all and instead queries hard-coded patrol, energy, and personnel tables; configured table mappings are effectively unused. Additionally, the weekly report is just a stub message rather than a substantive generated report. These are significant enough that the declared description does not accurately represent the implemented behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

定时任务:

bash
# crontab -e
0 8 * * * cd /root/clawd/skills/ioc-patrol-report && uv run scripts/generate_report.py --type daily

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The package description is entirely in Chinese and describes the report-generation behavior without offering any language or locale choice. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is entirely presented in Chinese, including the title and report metadata, and attributes generation to an assistant without any indication that language selection is optional. Under the language/locale policy, forcing a specific language without user opt-in or documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code reads database host, user, and password values from environment variables and later uses them to establish a real database connection. Although there is internal error logging, there is no user-facing warning in the script's usage text or comments that the skill may access live database data and credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a report generator that analyzes 设备状态、报警记录、能耗数据、工单进度. In the real-data path, the code queries t_patrol_task, t_energy_hourly_consumption, and t_personnel_room_access, then derives both device and work-order statistics from patrol-task status rows, with no actual alarm query at all. This is a semantic mismatch between the advertised reporting scope and the implemented data collection behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The function performs multiple queries against live operational tables, including patrol, energy, and personnel access data. The script prints progress and error messages, but it does not clearly warn beforehand that executing it will access production-like database records unless mock mode is used.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The footer always claims the report data came from the IOC real-time database, even when the script fell back to mock data after a connection or query failure. In an operations context, this can cause staff to make decisions based on fabricated or stale information while believing it is authoritative, creating an integrity and operational-risk issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and nearly all trigger phrases are Chinese-only, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking region. This creates a natural-language policy concern because the skill appears to impose a language/locale without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad operational terms such as '巡检报告', '运维报告', '设备巡检', and '智能运维', which can match ordinary user requests outside a narrowly intended scope. This increases the chance of accidental or overly broad invocation, causing the skill to activate in contexts involving sensitive operational reporting or database-backed workflows without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This is a markdown file, so missing-warning checks apply to the skill description. The usage and file structure indicate the skill reads from a database and writes generated reports to a reports directory, but the README does not warn users that running it will access operational data and create output files on disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language invocation example is only provided in Chinese and the document consistently presents the skill as Chinese-language, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The visible natural-language description and headings are presented entirely in Chinese, which can amount to forcing a specific language without explicit user opt-in. There is no statement that the skill is China-region specific or that alternative language support is unavailable by design.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file instructs users to configure a live database connection and specifies an output directory for generated reports, which means the skill will read potentially sensitive operational data and create files on disk. The documentation describes setup and usage but does not include any explicit user warning about data sensitivity, privacy, or file creation behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown template is entirely written in Chinese, including the report title and section headings, which implies the generated report will be produced in a fixed language. The file does not mention any user opt-in, language selection, or explicit region-specific requirement that would justify the locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The config sets timezone: Asia/Shanghai, which imposes a specific locale setting. Under the policy rule for natural-language locale constraints, this can be a violation when no user opt-in or documented justification is present in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is written only in Chinese ("IOC 智能巡检报告生成器"), which indicates a language-specific presentation without any documented user choice or opt-in. Under the policy criteria, language constraints should either offer a choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The manifest allows any PyYAML version at or above 6.0, so the actual installed version is not strictly controlled and vulnerability status cannot be verified from the file alone. In a reporting tool that may parse configuration or report templates, use of a vulnerable YAML library could enable unsafe parsing or deserialization issues if untrusted YAML is ever processed.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pytest has 2 known advisory(ies) (CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, and there is no indication that the user can choose another language or that the report is intentionally limited to a Chinese-speaking context. Under the policy rule for language or locale constraints, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written fully in Chinese, including the title, section headings, labels, and assistant attribution, with no indication that the user opted into this locale or that the report is limited to a Chinese-specific environment. The policy for natural-language violations applies to all file types and flags forced language/locale behavior when no opt-in or documented justification is present.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The report title and body are entirely in Chinese, and the file provides no indication that Chinese output is optional or that the skill is explicitly limited to a Chinese-language or China-region context. Under the language/locale policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.