Back to skill

Security audit

Ora海关数据分析专家

Security checks for vulnerabilities and agentic risk

Overview

This customs-data skill has a coherent purpose, but it needs Review because its credential handling can expose or reuse API keys more broadly than necessary.

Install only if you are comfortable sending customs queries and an API credential to h.smtso.com. Use a dedicated low-privilege API key, avoid shared OraAgent.key files, do not allow workflows that print the key with Get-Content, and rotate any key that may already have appeared in logs or transcripts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:29
Finding

Plaintext API Key Exposure Through Mandatory Preflight Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 29-33
Vulnerability Type: Credential exposure through tool output
Risk Level: High

The skill requires the agent to execute the following command before every API request:

powershell
Get-Content "$env:USERPROFILE\.openclaw\workspace\skills\OraAgent.key"

Technical Analysis

Get-Content returns the complete contents of the API-key file rather than only checking whether the file exists and is nonempty. When invoked through an agent execution tool, the plaintext credential can be copied into tool results, model context, conversation transcripts, telemetry, or execution logs.

This behavior is unnecessary because ora-customs-client.js already reads the credential internally. It also conflicts with a later instruction in SKILL.md that describes separately reading the key as deprecated.

Attack Path

  1. A user or workflow initiates a customs-data query.
  2. The mandatory startup instructions cause the agent to execute Get-Content against OraAgent.key.
  3. The command returns the plaintext API key in execution output.
  4. The key enters the agent context, transcript, logs, or connected monitoring systems.
  5. Anyone with access to those records can recover the credential and use it independently against the associated service.

Impact Assessment

Successful exploitation exposes the full API credential. An attacker could make unauthorized API requests within the permissions and quota assigned to the key, consume paid resources, access data available to that credential, or cause the legitimate user to experience service disruption or account-level abuse.

This issue does not directly grant operating-system privileges, but its scope includes every remote API capability authorized by the exposed key.

Remediation
View remediation

Remediation Suggestions

  • Remove the instruction that prints the key with Get-Content.
  • Allow ora-customs-client.js to read the credential internally without returning it to the agent.
  • If a preflight check is required, check only file existence and nonzero size and return a boolean result.
  • Never include credential contents in command output, logs, exceptions, telemetry, or model-visible context.
  • Store the key in a dedicated secret manager where available.
  • Restrict key-file permissions to the account that runs the skill.
  • Revoke and rotate any credential that may already have appeared in execution logs or transcripts.
  • Remove contradictory credential-handling instructions from SKILL.md and define one secure workflow.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
ora-customs-client.js:42
Finding

Cross-Skill Credential Access Through Overbroad Key Discovery

Content
View full analysis

Vulnerability Details

File Location: ora-customs-client.js, lines 42-56
Vulnerability Type: Excessive credential-file access
Risk Level: Medium

javascript
// --- Resolve API Key ---
// Try env var first, then look for OraAgent.key in parent skill dirs
let ORA_API_KEY = process.env.ORA_API_KEY || '';

if (!ORA_API_KEY) {
  const searchPaths = [
    path.join(__dirname, '..', 'OraAgent.key'),
    path.join(process.env.USERPROFILE || '', '.openclaw', 'workspace', 'skills', 'OraAgent.key'),
  ];
  for (const fp of searchPaths) {
    try {
      if (fs.existsSync(fp)) {
        ORA_API_KEY = fs.readFileSync(fp, 'utf8').trim();
        break;
      }
    } catch {}
  }
}

Technical Analysis

The client searches for an API key outside its own project directory. It reads both a parent-directory file and a workspace-wide skill credential file. These locations may be shared by other skills or administrative workflows.

This violates least privilege because the client can consume a credential that was not provisioned specifically for this skill. Once discovered, that credential is transmitted to h.smtso.com as an X-API-Key header.

The empty exception handler also suppresses permission and file-access errors, making unexpected credential discovery behavior difficult to audit.

Attack Path

  1. A credential is placed in the parent skill directory or the workspace-wide skills/OraAgent.key path for another workflow.
  2. The customs client runs without ORA_API_KEY being explicitly set.
  3. The client searches the shared locations and reads the first matching file.
  4. The retrieved credential is attached to a request to h.smtso.com.
  5. A credential outside the intended trust boundary is consequently used and disclosed to the remote service.

Impact Assessment

The behavior enables cross-skill access to credentials readable by the current operating-system account. The ...[truncated 355 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove parent-directory and workspace-wide credential discovery.
  • Prefer a dedicated ORA_API_KEY environment variable supplied through a trusted secret-management mechanism.
  • If file-based storage is necessary, use a uniquely named, skill-specific credential file inside a controlled configuration directory.
  • Resolve the credential path explicitly rather than searching multiple broad locations.
  • Verify file ownership and restrictive permissions before reading a credential.
  • Report sanitized access errors instead of silently suppressing every exception.
  • Document the precise credential boundary and ensure other skills cannot unintentionally share the same key.
  • Rotate any shared credential that may already have been transmitted by this client.

T09 · Insecure Skill Coding Practices

Warning
Location
ora-customs-client.js:24
Finding

Unvalidated API Path Receives Credential-Bearing Requests

Content
View full analysis

Vulnerability Details

File Location: ora-customs-client.js, lines 24-74
Vulnerability Type: Unvalidated request-path construction
Risk Level: Medium

The API path is taken directly from a command-line argument:

javascript
const args = {};
let apiPath = '';
process.argv.slice(2).forEach(arg => {
  const m = arg.match(/^--([^=]+)=?(.*)$/);
  if (m) {
    if (m[1] === 'api') {
      apiPath = m[2];
    } else {
      args[m[1]] = m[2];
    }
  }
});

if (!apiPath) {
  console.error(JSON.stringify({ error: 'Missing --api parameter. Example: --api=queryHsCodeProductSkill' }));
  process.exit(1);
}

It is then concatenated into a credential-bearing request without an allowlist:

javascript
const options = {
  hostname: 'h.smtso.com',
  path: '/skill/botcustoms/' + apiPath,
  method: 'POST',
  headers: {
    'Content-Type': 'application/x-www-form-urlencoded;charset=UTF-8',
    'Content-Length': Buffer.byteLength(postData),
    ...(ORA_API_KEY ? { 'X-API-Key': ORA_API_KEY } : {}),
  },
};

Technical Analysis

Although SKILL.md documents six supported API operations, the executable accepts any nonempty --api value. The value is inserted directly into the HTTPS request path while the API credential is attached to the request.

An attacker who can influence skill arguments can supply unexpected paths, traversal-style path components, query delimiters, or undocumented route names. Interpretation depends on the remote server and intermediaries, but the client itself imposes no restriction ensuring that credential-bearing requests reach only the intended endpoints.

The hostname remains fixed, so this issue is not an arbitrary-host server-side request forgery vulnerability. The risk is unintended route access on the trusted host.

Attack Path

  1. An attacker influences the --api argument supplied to the client.
  2. The client accepts the value beca ...[truncated 888 chars]
Remediation
View remediation

Remediation Suggestions

  • Define an immutable allowlist containing exactly the six documented API operation names.
  • Reject values that are not exact allowlist matches before resolving or attaching the API credential.
  • Reject path separators, dot segments, query delimiters, fragments, control characters, and percent-encoded path manipulation.
  • Construct routes from an internal mapping rather than concatenating user-controlled text.
  • Add tests for traversal-style values, encoded separators, empty values, undocumented operations, and query-string injection.
  • Log rejected operation names in a sanitized form without including credentials or sensitive query values.
  • Consider using distinct credentials or narrower scopes if different API operations require different privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly states that user query parameters and API credentials will be transmitted to an external domain, and it instructs the agent to source the key from environment variables or a local file. This is dangerous because it normalizes secret exfiltration and couples sensitive local credential access with automatic outbound requests to a third-party service.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow tells the agent to persist a user-provided API key into a local file for later reuse. Writing secrets to disk increases exposure to other skills, processes, logs, backups, or accidental disclosure, and creates a persistent credential artifact beyond the user's immediate request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These lines require the agent to always prefix Taiwan, Hong Kong, and Macau with “中国” and forbid alternative standalone forms in all response contexts. This is a natural-language policy constraint that forces a specific geopolitical wording without user opt-in or a clearly documented region-specific compliance justification.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates that every request include an X-API-Key header sourced from local files or environment variables, making secret attachment automatic and unconditional. This increases the chance of unauthorized credential use or exfiltration because the agent is directed to pull local secrets and send them to the external API as part of routine operation, even when the user did not explicitly authorize that retrieval path in the current interaction.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises operational behavior that relies on environment variables and local files to obtain credentials, but it does not declare an explicit tool/permission scope. That creates a mismatch between documented behavior and enforceable boundaries, increasing the risk that an agent with broader-than-expected execution/file access could read secrets or perform actions the user did not clearly authorize.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad and overlap with ordinary business language such as '分析', '趋势', '客户', and '详情', which can cause the skill to activate unexpectedly. In this skill, unintended invocation is more dangerous because activation can lead to external transmission of user queries and locally sourced API credentials to a third-party endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code loads an API key from ORA_API_KEY or from local key files, then automatically includes it as the X-API-Key header in outbound requests. Although comments describe the lookup order, there is no user-facing prompt, confirmation, or warning that credentials will be read and sent to a remote service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.