T09 · Insecure Skill Coding Practices
- Location
scripts/push_notifications.py:10- Finding
Unrestricted Webhook Destination Enables Agent Metadata Disclosure and Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated agent-efficiency purpose, but it can read local agent configuration and send derived recommendations to user-supplied webhooks or scheduled pushes without strong scoping.
Install only if you are comfortable letting it inspect all OpenClaw agent skill configuration. Keep reports local by default, review generated recommendations before applying config changes, and use notification or cron features only with an approved webhook destination and known report contents.
scripts/push_notifications.py:10Unrestricted Webhook Destination Enables Agent Metadata Disclosure and Server-Side Request Forgery
The trigger phrases are broad enough to match ordinary requests like optimizing an agent, improving efficiency, or lowering token cost, which increases the chance the skill activates in contexts the user did not specifically intend. Because the skill can inspect agent configuration, recommend changes, and initiate scheduled or outbound workflows, overbroad activation meaningfully raises the risk of unintended execution.
The skill states that optimization changes require user confirmation, but also documents scheduled execution and automatic pushing of reports and recommendations without a clearly defined confirmation gate for those outbound actions. This creates a real risk of autonomous behavior that can transmit configuration-derived information or operational recommendations externally without an explicit, per-action user consent step.
The skill describes sending efficiency reports and recommendations through external channels such as WeCom or Tencent Docs, but it does not present a clear user-facing warning that internal agent metadata, usage metrics, or optimization details may leave the local environment. That omission can lead to unintentional data disclosure, especially if reports include configuration details or operational patterns derived from ~/.qclaw/openclaw.json.
This markdown file is entirely written in Chinese and does not indicate that language choice is optional or that the locale is required for a region-specific purpose. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
该技能文档通篇以中文呈现,且未说明这是面向特定中文用户群体的区域化文档,也未给出可选择其他语言的方式。按照语言/区域策略,这会构成默认强制特定语言而缺少用户选择的自然语言策略问题。
This code file contains user-facing natural-language text entirely in Chinese, including the module docstring and CLI descriptions. Because the skill does not offer any language/locale choice or explain that it is intentionally China/Chinese-specific, it creates a language policy concern under the locale-choice rule.
The module docstring is written as a directive in Chinese and the file consistently presents user-facing descriptions and console output only in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
}
try:
resp = requests.post(webhook_url, json=message, timeout=10)
if resp.status_code == 200:
print(f"✅ 企微推送成功")
else:
The docstring and user-facing messages describe this path as '推送到腾讯文档(生成可分享的文档)', which implies uploading or creating a shareable Tencent Docs document. In reality, the function only renders Markdown and writes it to a local filesystem path, with no Tencent Docs API interaction.
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
def push_via_tencent_docs(recommendations, output_path):
"""推送到腾讯文档(生成可分享的文档)"""
# 生成 Markdown 报告
report = f"# Agent 效率优化建议\n\n生成时间:{__import__('datetime').datetime.now().strftime('%Y-%m-%d %H:%M:%S')}\n\n"
for rec in recommendations.get("recommendations", []):
agent_name = rec.get("agent_name", "Unknown")
This Python file contains user-facing natural-language descriptions in Chinese, including the module docstring and later CLI/help text, with no indication that language is configurable or user-selected. Under the policy, forcing a specific language without opt-in is a locale/language policy violation.
The script claims to track and trend agent efficiency, but it hard-codes average_efficiency_score to 0 and leaves agent metrics unimplemented. This can mislead operators into trusting fabricated trend data, causing bad operational decisions or masking real regressions, though it does not directly enable code execution or privilege escalation.
该文档从标题到正文均仅使用中文,未说明这是特定地区/语言专用文档,也未提供其他语言或用户选择语言的说明。按照语言/locale 政策,若技能或文档默认强制单一语言而无用户选择,可能构成自然语言层面的策略违规。
This Python file contains natural-language descriptions entirely in Chinese, including the module docstring and later CLI messages/help text. That imposes a specific language/locale on users without any visible opt-in or documented region-specific justification, which matches the language-policy violation criteria.
No suspicious patterns detected.