Back to skill

Security audit

文献检索与下载全流程

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its research-download purpose, but it asks for powerful browser, posting, file-write, subprocess, and recurring cron authority without enough user control or containment.

Review before installing. Use only a dedicated temporary browser profile, avoid wildcard CDP origins, confirm every Ablesci post and cron task before creation, pin or verify dependency skills, and keep download/progress paths scoped to a non-sensitive folder.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:183
Finding

Wildcard CDP Origin Configuration Exposes Authenticated Browser Sessions

Content
View full analysis
` 提取 2. **Cookie**:通过 `Network.getAllCookies` 获取所有 ablesci.com 域名下的 cookie ``` ### Technical Analysis The documented browser launch commands enable the Chrome DevTools Protocol on TCP port 9334 while setting `--remote-allow-origins=*`. The wildcard disables origin-based restrictions for connections to the debugging interface. This is especially dangerous because the same instructions direct the agent to connect to a browser in which the user is already authenticated and to invoke `Network.getAllCookies`. An entity capable of reaching the debugging endpoint may be able to attach to browser targets, inspect pages, execute JavaScript in page contexts, retrieve browser data, and perform actions using authenticated sessions. The instructions do not require an isolated browser profile, authenticate access to CDP, enforce a loopback-only binding, or restrict which local processes and origins can connect. The wildcard origin configuration therefore increases the attack surface of a highly privileged browser-control interface. ### Attack Path 1. The user launches Edge or Chrome with remote debugging enabled on port 9334 and `--remote-allow-origins=*`. 2. The user signs in to Ablesci or has other authenticated sessions available in that browser profile. 3. A malicious local process, malicious browser-accessible origin, or network actor ...[truncated 1265 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:77
Finding

Unpinned Third-Party Skills Are Installed and Their Code Is Executed

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description contains very broad trigger phrases such as generic requests to 'find literature' or 'download this paper', which are common in normal conversation and can cause the skill to activate unintentionally. Because the skill has powerful permissions including browser control, filesystem write, cron, and subprocess, accidental invocation could trigger downloads, scheduled tasks, or external posting workflows without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill lacks clear boundaries between harmless literature lookup and privileged follow-on actions, so an ambiguous request may trigger a workflow that performs downloads, writes progress files, and establishes cron jobs. Because this skill bundles search, browser control, and persistent automation together, vague activation conditions materially increase the risk of unintended side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill lacks clear boundaries between harmless literature lookup and privileged follow-on actions, so an ambiguous request may trigger a workflow that performs downloads, writes progress files, and establishes cron jobs. Because this skill bundles search, browser control, and persistent automation together, vague activation conditions materially increase the risk of unintended side effects.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
## Step 1:文献检索

**必须先读取 academic-literature-search 技能**,路径通过以下方式定位:
1. 优先查找当前 workspace 下的 `skills/academic-literature-search/SKILL.md`
2. 其次查找 `~/.qclaw/skills/academic-literature-search/SKILL.md`
3. 若均不存在,提示用户先安装 academic-literature-search skill

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
## Step 1:文献检索

**必须先读取 academic-literature-search 技能**,路径通过以下方式定位:
1. 优先查找当前 workspace 下的 `skills/academic-literature-search/SKILL.md`
2. 其次查找 `~/.qclaw/skills/academic-literature-search/SKILL.md`
3. 若均不存在,提示用户先安装 academic-literature-search skill

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

渠道 1:Unpaywall(最快)

text
GET https://api.unpaywall.org/v2/{DOI}?email={LIT_UNPAYWALL_EMAIL}
  • 响应中取 best_oa_location.landing_page 或 best_oa_location.url_for_pdf
  • 注意:Unpaywall 有频率限制,每小时 ≤ 5000 请求

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

渠道 3:Semantic Scholar PDF

text
GET https://api.semanticscholar.org/graph/v1/paper/{DOI}/PDF
(需设置 API Key:SEMANTIC_SCHOLAR_API_KEY)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

渠道 4:Crossref PDF 链接

text
GET https://api.crossref.org/works/{DOI}
(从响应中取 `link` 字段)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to automatically download files, rename them, write to local paths, update tracking files, and create recurring cron-based monitoring without an explicit warning or fresh consent at the point of action. In context, this is especially risky because it combines filesystem-write, browser-cdp, and cron permissions, enabling persistent background activity and repeated writes to the host environment.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
## Step 5:建立 Cron 监控任务

### 读取 qclaw-cron-skill 获取正确的 cron 配置语法
路径:`~/Library/Application Support/QClaw/openclaw/config/skills/qclaw-cron-skill/SKILL.md`

### 监控任务配置

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest advertises multi-channel downloading, help posting, cron monitoring, notifications, and progress tracking, but does not disclose user-facing warnings about persistence, outbound communication, or local system changes. In context, this is dangerous because the skill can write files, schedule recurring jobs, and potentially transmit research topics or identifiers to third-party services, creating privacy, resource, and consent risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

整个技能说明、示例提示语和通知模板均固定为中文,没有提供用户语言偏好选择或说明该技能仅面向特定中文环境。按自然语言策略,这可能构成未经用户选择的语言/地区约束。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file presents the skill name and categories in Chinese while the main operational description is written in English, but it does not state which language the skill will use with end users or offer a language preference. This can create an implicit language policy mismatch for users who expect behavior aligned with the localized metadata.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.