Back to skill

Security audit

极空间迅雷下载

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its documented command can run unsafe shell input while creating real downloads in a logged-in account.

Review before installing. Only use this with magnet links you trust, because the current instructions can pass the link through a shell command unsafely. The skill should validate magnet URLs, avoid shell interpolation, and ask for confirmation before creating the download task.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:21
Finding

Shell Command Injection Through Unsafely Interpolated Magnet URL

Content
View full analysis
" ``` ### Technical Analysis The skill instructs the agent to replace `` with a user-provided magnet URI and then execute the resulting command through a shell. The value is embedded directly inside a double-quoted shell argument without shell-safe encoding. Double quotes do not provide adequate protection when untrusted data is inserted through textual replacement. A malicious value can include a double quote to terminate the intended argument, followed by shell syntax such as command substitution, backticks, separators, or redirections. The shell may then interpret that syntax as commands rather than treating the entire value as browser input. Requiring the value to begin with `magnet` is insufficient because an attacker can place malicious shell syntax after a valid-looking prefix. The vulnerability is reached specifically when the agent performs the documented placeholder substitution and executes the generated shell command. ### Attack Path 1. An attacker supplies a crafted value that begins with a plausible `magnet:` prefix but also contains a quote and shell syntax. 2. The agent follows the skill instructions and replaces `` verbatim with the supplied value. 3. The replacement closes the double-quoted argument in the generated shell command. 4. The shell interprets the remaining attacker-controlled characters as shell syntax. 5. The injected command executes with the operating-system privileges of the account running the agent or `openclaw`. 6. The original command may then continue, fail, or be syntactically repaired by additional attacker-controlled characters, potentially conceal ...[truncated 749 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to drive a logged-in browser session to create a new 迅雷 download task on the user's 极空间 account, which causes real side effects on the user's account and storage. While this appears to be the intended function of the skill rather than overtly malicious behavior, it lacks explicit safety checks, confirmation, and warnings about account, bandwidth, and storage impact before triggering the action.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.