Back to skill

Security audit

A2a Gateway

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an agent-collaboration gateway, but it includes under-scoped persistent cron execution and a spawn-file behavior that users should review before installing.

Review this skill before installing if you do not want it to create recurring cron jobs or local collaboration logs. Do not run scripts/setup-cron.sh unless you trust the referenced health.py in your ~/.qclaw workspace and are comfortable with twice-daily execution under your user account. Avoid logging secrets in task descriptions, results, errors, or pending spawn files.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
scripts/setup-cron.sh:5
Finding

Persistent Scheduled Execution of an External Mutable Script

Content
View full analysis
> $LOG_DIR/health-check.log 2>&1" EXISTING=$(crontab -l 2>/dev/null | grep -F "scripts/health.py check") if [ -n "$EXISTING" ]; then read -p " 是否要替换它?(y/n): " -n 1 -r echo if [[ $REPLY =~ ^[Yy]$ ]]; then crontab -l 2>/dev/null | grep -v "scripts/health.py check" | crontab - else exit 0 fi fi (crontab -l 2>/dev/null; echo "$CRON_LINE") | crontab - crontab -l | grep -v "^#" cd "$WORKSPACE" && python3 scripts/health.py check ``` ### Technical Analysis The installer changes the invoking user's crontab and schedules the following command to run every 12 hours: ```bash cd "$HOME/.qclaw/workspace-a2a-gateway" && python3 scripts/health.py check ``` This is a cross-session persistence mechanism because the scheduled command survives termination of the installation process and continues executing under the user's account. Periodic health checks are related to the Skill's documented functionality, and the installer is interactive rather than automatically invoked by another reviewed file. Nevertheless, modifying the user's persistent scheduler is more invasive than performing an on-demand health check and should be treated as a separate, explicit opt-in operation. The risk is increased because `scripts/health.py` is not present in the audited project. The cron job therefore points to a separately provisioned, mutable Python file whose implementation and integrity cannot be verified from this package. Any party or compromised component capable of modifying that file after cron installation ...[truncated 2258 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (20)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly describes persistent storage of registry, task, audit, and health data under a local workspace, but provides no warning, retention policy, access-control guidance, or minimization guidance for potentially sensitive collaboration metadata. In an agent bus context, these logs can reveal user intents, inter-agent routing, errors, and operational relationships, which increases the chance of privacy leakage or unintended disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language documentation entirely in Chinese, including the title, usage sections, and output description, with no indication that the skill is region-specific or that users may choose another language. The policy requires flagging language or locale constraints when a skill forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

All visible runtime prompts and warnings printed to the user are hard-coded in Chinese, and the script does not provide any mechanism to select another language. For a general-purpose CLI tool, this is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's control flow contradicts its documented behavior: it writes pending spawn parameters in both the --spawn and non---spawn paths. In this skill context, writing audit/pending_spawn.json is itself a side effect that can trigger downstream automation if another component watches that file, causing unintended session creation or task execution despite the operator believing spawn was disabled.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

This script inspects and manages the user’s crontab to establish a recurring health-check job, which is a persistence mechanism by definition. In a trusted admin/setup context this may be legitimate, but if the skill is run unexpectedly or the referenced workspace contents are later modified, it creates ongoing code execution every 12 hours.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 46)May include surrounding context.

sh
# 5. 检查是否 already 存在
echo "5️⃣  检查是否已存在相同的定时任务..."
EXISTING=$(crontab -l 2>/dev/null | grep -F "scripts/health.py check")
if [ -n "$EXISTING" ]; then
    echo "   ⚠️  发现已存在的定时任务:"
    echo "   $EXISTING"

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

This line removes matching cron entries and rewrites the user’s crontab, reinforcing the script’s ability to persist scheduled execution. The danger is not the grep itself, but that the script programmatically controls recurring tasks, which can be abused to maintain execution or overwrite legitimate cron state if invoked in the wrong context.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 55)May include surrounding context.

sh
echo
    if [[ $REPLY =~ ^[Yy]$ ]]; then
        # 删除旧的任务
        crontab -l 2>/dev/null | grep -v "scripts/health.py check" | crontab -
        echo "   ✅ 旧任务已删除"
    else
        echo "   ❌ 取消配置"

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

Appending a new cron entry creates durable periodic execution, which is a recognized persistence technique. In this specific skill the task is a health check, but the security risk comes from establishing unattended execution tied to files under a user-writable workspace, so later tampering with scripts in that path would be executed automatically.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 66)May include surrounding context.

sh
# 6. 添加到 crontab
echo "6️⃣  添加到 crontab..."
(crontab -l 2>/dev/null; echo "$CRON_LINE") | crontab -
echo "   ✅ 定时任务已添加"
echo ""

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 72)May include surrounding context.

sh
# 7. 显示当前 crontab
echo "7️⃣  当前的定时任务:"
crontab -l | grep -v "^#"
echo ""

# 8. 测试运行

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 100)May include surrounding context.

sh
# 7. 显示当前 crontab
echo "7️⃣  当前的定时任务:"
crontab -l | grep -v "^#"
echo ""

# 8. 测试运行

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The create_task flow records user-provided description and context into an event and persists it via append(event). This is a data-affecting write operation involving potentially sensitive content, but the file provides no confirmation prompt, user-facing warning, or explicit disclosure about that persistence behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The complete_task function places result into the event payload and appends it to persistent task history. Results may contain sensitive or personal data, yet this file contains no user disclosure or warning that completion outputs are retained in the event log.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language description and operational guidance are entirely in Chinese and do not indicate that users may interact in other languages or opt into this locale. Under the language/locale policy, fixed-language behavior should either provide user choice or clearly justify the locale constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring says 'Minimum 3 tasks required for meaningful score,' implying the function itself enforces or reflects that threshold. In reality, reliability_score returns successes / total for any total > 0, and the 3-task threshold is only applied later in _recommend_status, so the documentation misstates what this function does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The _persist function creates directories and writes aggregated agent performance data to registry/performance.json, but there is no confirmation prompt, user-facing log/print, or explicit warning in this file about the write occurring. Because this is a file-modifying operation in a general performance utility, users invoking record_outcome may not realize persistent state is being updated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring, usage examples, and later user-facing messages are written entirely in Chinese, which imposes a specific language on operators. The file does not offer an alternate language or state that the skill is intended only for a Chinese-speaking or region-specific context, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The route() docstring states that adaptive mode blends keyword matching with dynamic performance data, but main() only parses --top-k and --min-score and always calls route() without adaptive=True. This creates an intent/documentation mismatch for the user-facing behavior of this file: the documented adaptive capability is not actually reachable via the documented CLI entrypoint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing natural-language examples that exclusively use Chinese keywords ("周报", "报修") as the demonstrated invocation inputs. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment says terminal states have no further transitions, but the code defines COMPLETED -> COMPENSATED in the transition table and omits COMPLETED from TERMINAL_STATES. This is an intent/documentation mismatch about lifecycle semantics, even though it is not a direct security issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing comments, prompts, and status messages are written in Chinese throughout, including the confirmation prompt and completion instructions. This imposes a specific language on users without opt-in, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The fail_task function persists the provided error string into the event log. Error messages can contain sensitive operational details, but the file does not include a user-facing disclosure that such failure data will be stored.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.