Back to skill

Security audit

pushplus

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed PushPlus notification helper, but its shell-based request examples create a real risk that crafted message text could execute local commands.

Review before installing. Use the manual install path or a pinned installer, and do not let an agent paste arbitrary user text directly into the shown shell templates. Only send messages you have reviewed, avoid secrets or personal data in notifications, and grant AccessKey credentials only when you intentionally want the agent to manage PushPlus account settings such as friends, blacklists, bot bindings, or forwarding rules.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:29
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md:29
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

bash
npx clawhub@latest install pushplus-notification

Technical Analysis

The documented installation command instructs users to download and execute the mutable latest version of the clawhub package. No exact version, lockfile, checksum, signature, or other integrity constraint is specified.

Because the version associated with latest can change after this Skill has been reviewed, the code ultimately executed by users is outside the reviewed artifact. The command may also invoke package CLI or lifecycle code with the permissions of the user running npx.

This creates a supply-chain trust boundary in which compromise of the package, its publishing account, the package registry, or a future release could result in execution of code that was not present during this audit.

Attack Path

  1. An attacker compromises the upstream package, its maintainer account, or the release process.
  2. The attacker publishes a malicious release and assigns it the latest distribution tag.
  3. A user follows the installation instructions and runs npx clawhub@latest install pushplus-notification.
  4. npx downloads the current mutable package release.
  5. The package's CLI or lifecycle behavior executes locally with the invoking user's privileges.
  6. The malicious package can access files, environment variables, credentials, and network resources available to that user.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user performing the installation. The accessible scope may include the user's home directory, project files, environment variables, agent credentials, SSH configuration, and any services reachable from the host.

The reviewed project does not itself contain evidence that the cu ...[truncated 117 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version.
  2. Publish and verify the expected package provenance, checksum, or signature.
  3. Prefer an installation mechanism backed by a lockfile and integrity metadata.
  4. Review the pinned package's lifecycle scripts and transitive dependencies before recommending execution.
  5. Document a manual installation path that copies the audited Skill files without executing third-party package code.
  6. Update pinned versions only after reviewing the new release.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:62
Finding

Potential Shell Command Injection Through Unsafe JSON Construction Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:62-64, with incomplete escaping guidance at SKILL.md:329
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable Code

bash
curl -s -X POST "https://www.pushplus.plus/send" \
  -H "Content-Type: application/json" \
  -d '{"token":"TOKEN","title":"标题","content":"内容","template":"html","channel":"wechat"}'

The related escaping guidance at SKILL.md:329 states:

text
- content 中双引号转义为 `\"`,换行用 `\n`(markdown 亦然)

Technical Analysis

The Skill instructs an agent to construct JSON inside a single-quoted shell argument. Notification titles and content are expected to originate from user requests and are therefore potentially untrusted.

The documented escaping guidance only addresses JSON double quotes and newline characters. It does not address single quotes, which delimit the shell argument. If an implementation directly substitutes user-controlled content into this template, an embedded single quote can terminate the argument. Shell operators placed after that quote can then be interpreted as commands rather than message data.

JSON escaping alone is not a safe substitute for shell escaping. Correctly handling every combination of JSON and shell metacharacters is error-prone, and direct interpolation into shell source should be avoided entirely.

Attack Path

  1. An attacker supplies notification content containing a single quote followed by shell syntax.
  2. An agent follows the documented template and directly substitutes that content into the single-quoted -d argument.
  3. The embedded single quote closes the intended shell string.
  4. Subsequent shell metacharacters are parsed by the shell.
  5. The injected command executes with the privileges and environment of the agent process.
  6. Depending on agent permissions, the attacker may read or alter project files, access credentials, execute programs, or initiate a ...[truncated 784 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prohibit direct interpolation of titles, message content, tokens, channel values, and other dynamic fields into shell command text.

  2. Construct the request body with a proper JSON serializer. For example:

    bash
    payload="$(jq -n \
      --arg token "$PUSHPLUS_TOKEN" \
      --arg title "$title" \
      --arg content "$content" \
      --arg template "$template" \
      --arg channel "$channel" \
      '{token:$token,title:$title,content:$content,template:$template,channel:$channel}')"
    
    curl --fail-with-body --silent --show-error \
      -X POST "https://www.pushplus.plus/send" \
      -H "Content-Type: application/json" \
      --data-binary "$payload"
    
  3. If the zero-dependency requirement must be retained, use a language runtime with a standard JSON encoder or write serialized JSON to a securely created temporary file and send it with --data-binary @file.

  4. Do not use eval, dynamically generated shell scripts, or nested command substitution to construct requests.

  5. Add explicit security guidance covering single quotes, command substitutions, shell operators, backticks, and multiline input.

  6. Add tests using adversarial content containing quotes, semicolons, command substitutions, newlines, backslashes, and Unicode characters.

  7. Continue requiring user confirmation before transmission, but treat that as a separate safety control rather than an injection defense.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (21)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill is explicitly designed to send notifications through the PushPlus HTTP API, meaning it transmits user-provided content and authentication tokens to an external service. External transmission is expected for this skill, but it remains security-relevant because the broad supported channels and management APIs increase the consequences of sending sensitive content or using over-privileged credentials.

Content

Scanner excerpt · README.md (reported line 8)May include surrounding context.

md
An [OpenClaw](https://clawhub.ai) agent skill that enables AI agents to send push notifications via [PushPlus](https://www.pushplus.plus) HTTP API (消息接口 V1.18) to WeChat, WeChat ClawBot, 新消息ClawBot, QQ bot, email, webhook, SMS, App, and more — with progressive disclosure of Open API (V1.19) for result lookup, account management, friend/topic-user blacklists, ClawBot / 新消息ClawBot / QQ bot binding, and message forward rules.

**Zero dependencies** — works with any agent that has Shell/curl access. No MCP server or extra packages required.

## Features

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

md
Copy the `SKILL.md` file to your skills directory:

- **Personal**: `~/.cursor/skills/pushplus-notification/SKILL.md`
- **Project**: `.cursor/skills/pushplus-notification/SKILL.md`

## Usage

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

md
Copy the `SKILL.md` file to your skills directory:

- **Personal**: `~/.cursor/skills/pushplus-notification/SKILL.md`
- **Project**: `.cursor/skills/pushplus-notification/SKILL.md`

## Usage

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states the agent will 'automatically use this skill when you ask it to send notifications' and lists broad natural-language triggers. In a skill that can transmit arbitrary content to external destinations, vague trigger boundaries increase the chance of unintended activation and exfiltration of sensitive data through notification requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README demonstrates direct curl calls to an external API with a bearer-like token and arbitrary message content, but it does not prominently warn users that prompts, logs, secrets, or other sensitive data may be transmitted off-platform. In this context, omission of that warning materially increases the risk of accidental data disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description contains broad activation phrases like generic requests to send notifications, alerts, reminders, or messages across many channels. This can cause the agent to invoke the skill for loosely related user requests, increasing the chance of unintended external transmission of user-provided or sensitive data to a third-party service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

发送消息(/send)

bash
curl -s -X POST "https://www.pushplus.plus/send" \
  -H "Content-Type: application/json" \
  -d '{"token":"TOKEN","title":"标题","content":"内容","template":"html","channel":"wechat"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

最简 POST

bash
curl -s -X POST "https://www.pushplus.plus/send" \
  -H "Content-Type: application/json" \
  -d '{"token":"YOUR_TOKEN","title":"标题","content":"消息内容"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
# pushplus 开放接口参考

文档版本:**V1.19**([官方文档](https://www.pushplus.plus/doc/guide/openApi.html))  
在线调试:https://api.pushplus.plus/doc-6905395

本文件供智能体在需要查询发送结果、管理群组/好友/黑名单/渠道/ClawBot/新消息ClawBot/QQ 机器人、配置设置/消息规则等场景时按需阅读。日常发消息请优先使用 [SKILL.md](SKILL.md) 中的 `/send` 与 `/batchSend`(用户 token,无需 AccessKey)。

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference.md (reported line 4)May include surrounding context.

md
# pushplus 开放接口参考

文档版本:**V1.19**([官方文档](https://www.pushplus.plus/doc/guide/openApi.html))  
在线调试:https://api.pushplus.plus/doc-6905395

本文件供智能体在需要查询发送结果、管理群组/好友/黑名单/渠道/ClawBot/新消息ClawBot/QQ 机器人、配置设置/消息规则等场景时按需阅读。日常发消息请优先使用 [SKILL.md](SKILL.md) 中的 `/send` 与 `/batchSend`(用户 token,无需 AccessKey)。

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference.md (reported line 29)May include surrounding context.

获取 AccessKey

bash
curl -s -X POST "https://www.pushplus.plus/api/common/openApi/getAccessKey" \
  -H "Content-Type: application/json" \
  -d '{"token":"USER_TOKEN","secretKey":"SECRET_KEY"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference.md (reported line 162)May include surrounding context.

bash
# 拉黑(topicRelationId = 订阅人列表 id)
curl -s -X POST "https://www.pushplus.plus/api/open/topicUser/addBlacklist?topicRelationId=1" \
  -H "access-key: ACCESS_KEY"

# 黑名单列表

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference.md (reported line 245)May include surrounding context.

bash
# 1. 绑定(apiKey 来自手机 5G 消息「新消息ClawBot」应用号)
curl -s -X POST "https://www.pushplus.plus/api/open/cmcc/bind" \
  -H "Content-Type: application/json" \
  -H "access-key: ACCESS_KEY" \
  -d '{"apiKey":"ak_xxxxxxxxxxxxxxxx"}'

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference.md (reported line 270)May include surrounding context.

md
| 获取绑定链接 | GET | `/getBindLink` | query: `refresh`(可选,true 使旧绑定码失效并重新生成) |
| 查询绑定状态 | GET | `/botInfo` | 无参数 |
| 解绑 | GET | `/unbind` | 无参数(不可逆,需确认) |
| 已加入的 QQ 群列表 | GET | `/groupList` | 无参数 |
| 群配置列表 | POST | `/list` | 分页 `current`, `pageSize` |
| 新增群配置 | POST | `/add` | `qqName`, `qqCode`, `qqGroupId` 必填 |
| 修改群配置 | POST | `/edit` | `id`, `qqName`, `qqGroupId`(`qqCode` 不可改) |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference.md (reported line 280)May include surrounding context.

md
| 获取绑定链接 | GET | `/getBindLink` | query: `refresh`(可选,true 使旧绑定码失效并重新生成) |
| 查询绑定状态 | GET | `/botInfo` | 无参数 |
| 解绑 | GET | `/unbind` | 无参数(不可逆,需确认) |
| 已加入的 QQ 群列表 | GET | `/groupList` | 无参数 |
| 群配置列表 | POST | `/list` | 分页 `current`, `pageSize` |
| 新增群配置 | POST | `/add` | `qqName`, `qqCode`, `qqGroupId` 必填 |
| 修改群配置 | POST | `/edit` | `id`, `qqName`, `qqGroupId`(`qqCode` 不可改) |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference.md (reported line 295)May include surrounding context.

md
| 获取绑定链接 | GET | `/getBindLink` | query: `refresh`(可选,true 使旧绑定码失效并重新生成) |
| 查询绑定状态 | GET | `/botInfo` | 无参数 |
| 解绑 | GET | `/unbind` | 无参数(不可逆,需确认) |
| 已加入的 QQ 群列表 | GET | `/groupList` | 无参数 |
| 群配置列表 | POST | `/list` | 分页 `current`, `pageSize` |
| 新增群配置 | POST | `/add` | `qqName`, `qqCode`, `qqGroupId` 必填 |
| 修改群配置 | POST | `/edit` | `id`, `qqName`, `qqGroupId`(`qqCode` 不可改) |

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference.md (reported line 303)May include surrounding context.

md
| 获取绑定链接 | GET | `/getBindLink` | query: `refresh`(可选,true 使旧绑定码失效并重新生成) |
| 查询绑定状态 | GET | `/botInfo` | 无参数 |
| 解绑 | GET | `/unbind` | 无参数(不可逆,需确认) |
| 已加入的 QQ 群列表 | GET | `/groupList` | 无参数 |
| 群配置列表 | POST | `/list` | 分页 `current`, `pageSize` |
| 新增群配置 | POST | `/add` | `qqName`, `qqCode`, `qqGroupId` 必填 |
| 修改群配置 | POST | `/edit` | `id`, `qqName`, `qqGroupId`(`qqCode` 不可改) |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference.md (reported line 288)May include surrounding context.

bash
# 1. 取绑定链接,把 url 生成二维码给用户扫,或让用户私聊发送 bindCode
curl -s "https://www.pushplus.plus/api/open/qqBot/getBindLink" \
  -H "access-key: ACCESS_KEY"

# 2. 轮询绑定状态,isBind=1 即可用 channel=qq 发消息

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference.md (reported line 350)May include surrounding context.

bash
# 拉黑(friendId = 好友列表 friendId)
curl -s -X POST "https://www.pushplus.plus/api/open/friend/addBlacklist?friendId=1" \
  -H "access-key: ACCESS_KEY"

# 黑名单列表

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · reference.md (reported line 441)May include surrounding context.

bash
# 开启总开关(未命中仍按默认推送)
curl -s "https://www.pushplus.plus/api/open/forwardRule/setting?mode=1" \
  -H "access-key: ACCESS_KEY"

# 新增规则

Static analysis

No suspicious patterns detected.