Back to skill

Security audit

Ocean Chat

Security checks for vulnerabilities and agentic risk

Overview

The skill is a messaging tool, but it also enables persistent remote control of Claude Code and message-triggered local execution without adequate safeguards.

Install only if you intentionally want a remotely reachable automation channel into Claude Code. Avoid `--auto-exec` and arbitrary `--on-message` commands, do not run execution modes under PM2 startup, review any WeChat credential reuse, and keep the data directory permissions tightly restricted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
chat.js:727
Finding

Unauthenticated Remote Messages Execute Claude Code Without Permission Checks

Content
View full analysis
{ const child = spawn('claude', ['-p', prompt, '--dangerously-skip-permissions'], { cwd: projectDir || process.cwd(), stdio: ['ignore', 'pipe', 'pipe'], }); ``` The task is populated directly from a received OceanBus message: ```js if (autoExec) { taskQueue.push({ fromName: fromName || msgFrom, fromOpenid: msg.from_openid, body, }); console.log('[auto-exec] Task queued: ' + taskQueue.length); processQueue(); return; } ``` The monitor command contains the same unsafe execution pattern: ```js if (autoExec && content.trim()) { const prompt = content; const label = fromName; try { const result = await new Promise((resolve, reject) => { const child = spawn('claude', ['-p', prompt, '--dangerously-skip-permissions'], { cwd: projectDir || process.cwd(), stdio: ['ignore', 'pipe', 'pipe'], }); ``` ### Technical Analysis When `--auto-exec` is enabled, the body of every received message is passed directly to Claude Code as its prompt. The command explicitly supplies `--dangerously-skip-permissions`, disabling the normal permission boundary around filesystem access, command execution, network access, and other tools available to Claude Code. No sender allowlist, challenge-response authentication, local confirmation, per-task authorization, prompt isolation, or capability restriction is applied before execution. The listener also automatically creates contacts for previously unknown senders, so roster membership does not constitute an authorization boundary. Although enabling `--auto-exec` requires a local command-line option, the resulting execution ...[truncated 1760 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
chat.js:896
Finding

Shell Command Injection Through Message Template Substitution

Content
View full analysis
s.replace(/"/g, '\\"'); const cmd = onMessage .replace(/\{from\}/g, escaped(hookFrom)) .replace(/\{openid\}/g, escaped(msg.from_openid)) .replace(/\{content\}/g, escaped(body)) .replace(/\{time\}/g, escaped(time)); exec(cmd, (err, stdout, stderr) => { ``` ### Technical Analysis The `--on-message` feature builds a shell command by replacing placeholders with fields derived from received messages and then passes the result to `child_process.exec()`. The only attempted sanitization escapes double quotes. This is not sufficient shell escaping. Depending on the hook template and operating system shell, an attacker may use: - Command substitution such as `$(command)` or backticks. - Shell separators such as semicolons or newlines. - Pipes and redirection. - Environment-variable expansion. - Quote termination using quote types not handled by the replacement. - Platform-specific command operators. Because `exec()` invokes a shell, message content is parsed as shell syntax after substitution. The source documentation advertises hook templates that place `{content}` and `{from}` inside commands, making the vulnerable feature practically reachable. ### Attack Path 1. The operator starts the listener with an advertised hook, for example a command containing `{content}`. 2. An attacker sends an OceanBus message containing shell metacharacters or command-substitution syntax appropriate to the configured template. 3. The listener replaces `{content}` with the attacker-controlled body. 4. Only literal double quotes are escaped; other shell syntax remains active. 5. `exec(cmd)` invokes the platform shell. 6. The injected expression executes with the privileg ...[truncated 885 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
docs/手机遥控ClaudeCode-工程师上手.md:33
Finding

Persistent Unattended Remote-Execution Listener Is Promoted Through PM2

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
chat.js:100
Finding

OceanBus API Credentials Are Stored Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/notify-wechat.js:65
Finding

Automatic WeChat Credential Discovery Permits Token and Message Exfiltration to an Unvalidated Host

Content
View full analysis
f.endsWith('.json')); if (files.length === 0) return null; const first = path.join(accountsDir, files[0]); const data = JSON.parse(fs.readFileSync(first, 'utf-8')); if (!data.token || !data.userId) return null; return { token: data.token, baseUrl: data.baseUrl || 'https://ilinkai.weixin.qq.com', userId: data.userId, source: 'WeChat plugin', }; } catch { return null; } } ``` The discovered token and base URL are then used directly: ```js const url = new URL(baseUrl.replace(/\/+$/, '') + '/ilink/bot/sendmessage'); const req = https.request({ hostname: url.hostname, path: url.pathname, method: 'POST', headers: { 'Content-Type': 'application/json', AuthorizationType: 'ilink_bot_token', Authorization: `Bearer ${token}`, 'Content-Length': String(Buffer.byteLength(body)), 'X-WECHAT-UIN': uin, 'iLink-App-Id': 'bot', 'iLink-App-ClientVersion': '0', }, }, callback); ``` ### Technical Analysis The monitor automatically reads credentials belonging to another OpenClaw plugin. It chooses the first JSON account file without explicit account selection, user approval, ownership validation, or file-permission validation. More importantly, `baseUrl` is accepted from that file without restricting the hostname to the expected WeChat API service. The bearer token is placed in the `Authorization` header, and the request body contains the forwarded OceanBus message. C ...[truncated 1431 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
chat.js:1446
Finding

Generated Setup Flow Installs Unreviewed Latest Dependencies and Uses a Nonstandard Locked Registry

Content
View full analysis
/dev/null; then git pull; else git clone https://github.com/ryanbihai/ocean-chat.git && cd ocean-chat; fi && npm install && npm install oceanbus@latest && node chat.js setup', ``` The package manifest allows compatible future releases: ```json "dependencies": { "oceanbus": "^0.8.0" } ``` The lockfile resolves OceanBus through a different registry from most other dependencies: ```json "node_modules/oceanbus": { "version": "0.8.0", "resolved": "https://registry.npmmirror.com/oceanbus/-/oceanbus-0.8.0.tgz" } ``` ### Technical Analysis The repository includes a lockfile, but the generated installation command subsequently invokes `npm install oceanbus@latest`. That command can replace the reviewed dependency version and update the dependency graph at installation time. The caret range in `package.json` also permits future compatible versions when installation is performed without strict lockfile enforcement. Additionally, the OceanBus package is locked to a nonstandard registry while most dependencies use the official npm registry. The lockfile includes integrity metadata, which provides some protection for that exact artifact, but the `@latest` instruction undermines reproducibility by selecting a future artifact not covered by the reviewed lockfile. OceanBus is security-sensitive because it handles identity registration, API credentials, network communication, contacts, and messages. Installing an unreviewed latest version grants updated dependency code access to those resources. ### Attack Path 1. A user follows the pairing message generated by `cmdPairMe()`. 2. The setup command ...[truncated 1039 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (61)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README presents the skill as messaging/contact/meetup/threading, but the documented workflow explicitly turns inbound chat messages into actions executed by Claude Code on the host computer. This creates a significant scope mismatch: users may install a seemingly low-risk chat skill without realizing it enables remote task execution on their machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README advertises that a WeChat message can cause Claude Code on the computer to receive a task, execute it, and reply automatically, but does not foreground the security implications of granting remote execution capability. Without clear warnings, users may expose powerful local automation to chat-originated input they would otherwise treat as untrusted.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented --on-message option executes a command when a message is received, effectively exposing message-driven command execution. If untrusted or spoofed senders can reach the listener, or if message content is interpolated unsafely into shell commands, this can lead to arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Documenting --on-message "cmd" without a conspicuous warning normalizes binding inbound messages directly to OS command execution. This is highly dangerous because it invites insecure deployments where any reachable message path can become an execution primitive, especially if operators copy-paste examples into production-like environments.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a substantial description-behavior mismatch. The declared description presents a communications/coordination skill: messaging, address book, meetup negotiation, and threading. The code indeed supports those features, so the declared purpose is partially accurate. However, the supplied chunk goes far beyond that role. It can continuously monitor for messages, push them to WeChat, write task queues, execute user-specified shell commands when messages arrive, and in auto-exec mode directly pass inbound message content to the claude CLI with --dangerously-skip-permissions, then send the output back over OceanBus. Those are powerful remote automation and command-execution behaviors not disclosed in the description and materially change the risk profile and practical purpose of the skill. Therefore this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on OceanBus-powered P2P messaging, address book management, meetup negotiation, and conversation threading. The supplied code does not implement those capabilities. Instead, it is a notification integration module for pushing messages to WeChat, including credential discovery from local filesystem data and environment variables. This is a materially different purpose and introduces external service interaction and local file access that are not reflected in the description. While the comments mention OceanBus messages being pushed to WeChat, the actual code chunk is specifically about WeChat notification delivery, not the declared core OceanBus collaboration features.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a multi-feature agent communication skill centered on encrypted A2A messaging, contacts, scheduling, and threaded conversations. The supplied code does none of those things. Instead, it specifically exercises the OceanBus Yellow Pages subsystem: setting identities, registering services, discovering tagged rooms/services, heartbeating, updating listings, and deregistering them. This is a materially different primary purpose and exposes an undeclared capability (service directory/discovery testing) while omitting the declared messaging, address book, meetup, and threading behaviors.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented listen --on-message "cmd" feature enables arbitrary shell command execution on receipt of a message, with attacker-controlled fields like sender, content, and time potentially substituted into the command. In a messaging skill, this creates a direct remote-triggered command-execution surface that could lead to code execution, data loss, or persistence if a crafted message reaches the listener.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Recommending a listener mode that executes arbitrary shell commands on inbound messages without an explicit safety warning normalizes a dangerous remote automation pattern. In practice, a malicious sender could trigger unsafe local actions through the message-processing path, especially if operators copy the example directly into production use.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
}
  DATA_DIR = abs;
}
const CRED_FILE = path.join(DATA_DIR, 'credentials.json');
const CURSOR_FILE = path.join(DATA_DIR, 'cursor.json');
const DATE_LOG_FILE = path.join(DATA_DIR, 'date-log.json');
const LEGACY_CONTACTS_FILE = path.join(DATA_DIR, 'contacts.json');

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · chat.js (reported line 53)May include surrounding context.

js
}
  DATA_DIR = abs;
}
const CRED_FILE = path.join(DATA_DIR, 'credentials.json');
const CURSOR_FILE = path.join(DATA_DIR, 'cursor.json');
const DATE_LOG_FILE = path.join(DATA_DIR, 'date-log.json');
const LEGACY_CONTACTS_FILE = path.join(DATA_DIR, 'contacts.json');

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · chat.js (reported line 1326)May include surrounding context.

js
}
  DATA_DIR = abs;
}
const CRED_FILE = path.join(DATA_DIR, 'credentials.json');
const CURSOR_FILE = path.join(DATA_DIR, 'cursor.json');
const DATE_LOG_FILE = path.join(DATA_DIR, 'date-log.json');
const LEGACY_CONTACTS_FILE = path.join(DATA_DIR, 'contacts.json');

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The listen auto-exec path turns untrusted incoming OceanBus message content directly into Claude prompts and runs them with --dangerously-skip-permissions, then sends the result back to the sender. That gives any reachable remote contact a delegated code-execution channel into the local project/workstation, which is far beyond the advertised messaging purpose and creates a clear remote task execution primitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Remote message content is executed via Claude with no confirmation at the point of use, and the invocation explicitly disables permission safeguards. In context, this messaging skill becomes a remote instruction runner, so an attacker who can message the agent can induce file operations, code changes, or sensitive data exfiltration through the model's local tool access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The on-message hook supports arbitrary shell command execution on receipt of remote messages, with message fields substituted into the command template. Even with minimal quote escaping, this is an unsafe remote-triggered execution mechanism unrelated to core chat functionality and can be abused for local command execution, persistence, or data theft.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The custom hook path constructs shell commands from remote-controlled message fields and executes them without an execution-time warning or approval. Because the source is untrusted network input, this creates a high-risk remote command execution surface and invites command injection or abusive automation.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The monitor feature forwards incoming message content into plain-language WeChat notifications, exposing conversation data to a separate service and device channel. In a messaging skill, this materially weakens confidentiality because encrypted or private A2A content may be replicated outside the original trust boundary.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated connect-cc instructions explicitly tell another agent to trust inbound OceanBus messages and execute tasks from them after establishing the connection. This is a staged delegated-execution setup: first build trust and persistence, then authorize remote task handling, which is highly dangerous in a chat-oriented skill.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The pair-me output asks a user to paste a multi-step bootstrap script into Claude Code, install/upgrade software, start a persistent listener, and then accept future instructions from a remote contact. That is a classic trust-escalation and remote control pattern, enabling the messaging channel to become a vehicle for delegated operations on another agent's environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill expands from messaging into instructing an agent to read the project folder and send back a summary over OceanBus. That is a clear workspace-inspection and exfiltration capability unrelated to the declared skill purpose, creating a direct path for unauthorized disclosure of local project contents.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Reading the project folder and sending a summary through a third-party bridge creates a natural-language exfiltration channel. Because the content is summarized rather than copied verbatim, it may evade simplistic data-loss controls while still leaking sensitive architecture, roadmap, customer, or security information.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The behavior rules require automatic transmission of complete task results back through Bridge, including key findings, modified files, and execution results. This can disclose sensitive project state or user data without a review checkpoint, turning the messaging channel into an exfiltration mechanism.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document explicitly instructs users to run an arbitrary shell command on every incoming message via --on-message, interpolating attacker-controlled fields such as {content} into the command line. This turns a messaging feature into a remote command-execution hook, creating a clear path to command injection, unauthorized task execution, and full compromise of the host running Claude Code.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown promotes unattended remote command execution but does not warn that incoming messages may be malicious, spoofed via compromised contacts, or contain payloads that become shell input. Omitting that warning is dangerous here because the documented example directly couples message receipt to local execution in an engineer's environment, where source code, credentials, and infrastructure access are often present.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions normalize operating Claude Code in an unattended, remotely taskable mode and culminate in an example that feeds inbound message data into a local command. In the context of a developer tool, this is especially dangerous because it encourages users to grant a remote messaging channel influence over coding workflows and local system behavior without robust trust checks or containment.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
chat.js:904