Back to skill

Security audit

Security News Feed Repo

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its security-news automation purpose, but it can automatically publish and archive Notion/Tistory content while using sensitive credentials and weak transport safeguards.

Review this before installing if it will have write access to real Notion databases or a logged-in Tistory browser profile. Use least-privilege Notion databases, keep Tistory disabled unless needed, avoid broad shared .env files, pin dependencies, remove TLS-verification bypasses, and add a manual review/dry-run step before publishing or archiving content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
security_news_aggregator_simple.py:121
Finding

GLM API Credential Can Be Sent to an Arbitrary Configured Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
modules/crawlers/skshieldus.py:34
Finding

TLS Certificate Verification Is Disabled in Multiple Crawlers

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:2
Finding

Most Third-Party Dependencies Are Unpinned

Content
View full analysis
Remediation
View remediation

other

Warning
Location
security_news_aggregator_simple.py:140
Finding

Untrusted Crawled Content Is Directly Embedded in LLM Instructions and Automatically Published

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (226)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 316)May include surrounding context.

md
### Tistory API (선택)
1. https://www.tistory.com/guide/api/register 접속
2. 앱 등록
3. Access Token 발급

## 라이선스

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The script accesses a local .env file to obtain a Notion API key, which is credential access behavior. In an agent skill context, reading local secrets is high risk because it expands trust boundaries: a seemingly simple utility can harvest privileged tokens and immediately use them against external services.

Content

Scanner excerpt · check_notion.py (reported line 13)May include surrounding context.

python
database_id = "fe8277a4484243db8b3b2f1a15399d40"

# Notion 토큰 로드
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
notion_token = None

with open(env_file, 'r') as f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

md
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv

# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

md
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv

# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv

# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.py (reported line 13)May include surrounding context.

python
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv

# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.py (reported line 17)May include surrounding context.

python
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv

# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The code explicitly targets a local .env secrets file under the user's workspace, which is a credential access pattern. In context, this appears intended to supply API and publishing credentials for the pipeline rather than steal them, but it still meaningfully increases risk because any compromise of this script or its imported modules exposes all loaded secrets.

Content

Scanner excerpt · full_pipeline.py (reported line 17)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

# 크롤러 임포트

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

Referencing and loading a .env file from a user workspace is consistent with credential access behavior because .env files commonly contain API keys, tokens, and service credentials. In the context of an integration test, this is more dangerous because test code often runs in developer environments with broad access and weaker operational controls, so secrets may be consumed unnecessarily and exposed indirectly.

Content

Scanner excerpt · integration_test.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

# 크롤러 임포트

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code archives Notion pages automatically with no confirmation, dry-run, rollback, or safety guard. Because the archival decision is based on a derived top-keyword set rather than explicit user intent, any logic error, partial dataset, or cache inconsistency can remove active pages from normal view and disrupt downstream workflows.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · modules/prompts/blog_generation.py (reported line 193)May include surrounding context.

python
\`\`\`markdown
\`\`\`bash
# 패치 적용
sudo apt update && sudo apt upgrade
\`\`\`
\`\`\`

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

Referencing and loading a workspace .env file constitutes credential/config access because it imports whatever secrets are stored there into the process environment before executing multiple external-facing crawlers. In this context, the danger is elevated because imported crawler modules may consume or leak those variables through logs, subprocesses, HTTP requests, or downstream integrations, even though this script itself does not visibly exfiltrate them.

Content

Scanner excerpt · test_9_crawlers.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

# 작동하는 크롤러 임포트

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · all_crawlers_final.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.py (reported line 21)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · final_8_crawlers.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · final_test.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · rss_quick_test.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · selenium_test.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_13_crawlers.py (reported line 15)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_8_crawlers.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_all_active.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_all_crawlers.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_crawlers.py (reported line 14)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_mermaid.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_notion_publish.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Static analysis

No suspicious patterns detected.