T05 · Unauthorized Access and Privilege Escalation
- Location
security_news_aggregator.py:446- Finding
Undocumented Automatic Archival of Remote Notion Records
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This security-news skill mostly matches its stated purpose, but it can automatically change Notion records and publish AI-generated content with unclear safeguards.
Review before installing. Use a dedicated Notion database and a least-privilege Notion integration, disable or patch the automatic 90-day archival, keep Tistory disabled unless you intend browser-session publishing, pin dependencies, and require review before publishing AI-generated summaries from crawled content.
security_news_aggregator.py:446Undocumented Automatic Archival of Remote Notion Records
security_news_aggregator.py:366Indirect Prompt Injection Through Crawled News Content
modules/crawlers/skshieldus.py:30TLS Certificate Verification Disabled in Multiple Crawlers
requirements.txt:2Unpinned Runtime Dependencies Create Supply-Chain Risk
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
### Tistory API (선택)
1. https://www.tistory.com/guide/api/register 접속
2. 앱 등록
3. Access Token 발급
## 라이선스
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv
# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv
# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv
# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path
Automatically loading the first .env found while walking up parent directories can cause the application to trust configuration and secrets from an unintended location. In a shared filesystem, mispackaged deployment, or attacker-influenced directory structure, this could inject malicious API keys, webhook URLs, or service endpoints and redirect sensitive operations.
current_path = Path(__file__).resolve()
search_paths = [current_path] # 현재 디렉토리
for _ in range(4): # 최대 4단계 상위 경로 검색
env_file = current_path / '.env'
if env_file.exists():
load_dotenv(env_file)
break
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
\`\`\`markdown
\`\`\`bash
# 패치 적용
sudo apt update && sudo apt upgrade
\`\`\`
\`\`\`
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)
from modules.crawlers.krcert import KRCERTCrawler
The code publishes crawled and LLM-generated content to Notion, an external service, without any available context establishing that publication is within the skill's authorized scope. In a security review context, undeclared exfiltration or outbound publication is dangerous because it can transfer sensitive, copyrighted, or manipulated content to third-party systems.
The trigger phrases include very broad terms like 'security news' and '뉴스 수집', which can overlap with ordinary user requests and cause the skill to activate unexpectedly. Because this skill performs external collection, summarization, and possible publication, accidental invocation can lead to unintended network activity and data handling beyond the user's intent.
The skill description explains functionality but does not clearly warn users that collected content is sent to Gemini and may be stored or published to Notion and Tistory. This creates a transparency and consent problem: users may invoke the skill without realizing data will leave the local environment and potentially be posted externally.
No suspicious patterns detected.