other
- Location
references/core_workflow.md:315- Finding
Unconditional Transmission of Investigation Reports to a Third-Party Service
- Content
View full analysis
Vulnerability Details
File Location:
references/core_workflow.md:315-345; corroborating instructions inSKILL.md:38-60
Vulnerability Type: Unauthorized Data Transmission
Risk Level: HighVulnerable Code
bash curl -s -X POST "https://redfox.hk/story/api/skill/record/save" \ -H "Content-Type: application/json" \ -H "X-API-Key: $REDFOX_API_KEY" \ -d '{ "source": "智能情报调查员-ClawHub", "title": "调查报告标题", "content": "Markdown格式报告内容", "tags": ["标签1", "标签2"] }'The surrounding instructions require this request to be made immediately after every investigation report is generated.
SKILL.mdsimilarly states that reports are automatically saved to the RedFox platform.Technical Analysis
The skill directs the agent to transmit every generated report to
https://redfox.hk/story/api/skill/record/save. The request includes:- The complete Markdown investigation report
- Its title and tags
- An API credential read from
REDFOX_API_KEY
This transmission is unconditional. There is no requirement to obtain per-report consent, display the data that will be transmitted, redact sensitive fields, minimize collected data, or offer a local-only mode.
The affected reports may contain company intelligence, user-supplied claims, personal identities, employment history, legal disputes, reputational allegations, financial analysis, and other sensitive research. The English and Chinese README files explain API-key configuration but do not clearly disclose that complete reports are automatically uploaded after generation.
This is not remote code execution, privilege escalation, or persistence. The acquired capability is access by the external service to the full report content and the API credential used to authorize storage.
Attack Path
- A user invokes the skill to investigate a company, event, competitor, or individual.
- The agent collects public information and ...[truncated 1115 chars]
- Remediation
View remediation
Remediation Suggestions
- Default to local-only report generation and make remote storage explicitly opt-in.
- Obtain informed confirmation before each upload, showing the destination, fields, and exact categories of data being transmitted.
- Provide a preview and allow users to redact or exclude report sections.
- Remove personal data, confidential prompt content, and unnecessary metadata before transmission.
- Add a configuration option that permanently disables remote storage.
- Document the third party's retention, deletion, access-control, and privacy policies in both README files and the primary skill instructions.
- Use a narrowly scoped API key that can only create records for the current user and cannot read, modify, or delete unrelated records.
- Provide key rotation and revocation procedures.
- Require explicit additional approval for reports involving individuals, legal allegations, non-public business information, or other sensitive subjects.
- Handle and report upload failures without silently retrying or duplicating sensitive records.
