Back to skill

Security audit

Mac 知识库搭建系统

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly a Mac knowledge-base automation tool, but it asks for broad default execution rights and persistent scheduled jobs that are wider than needed.

Review before installing. Use only on a personal Mac, avoid the global exec/process default change if possible, do not enable cron unless you trust and can protect the workspace scripts, install dependencies separately or from pinned sources, and store or rotate the Feishu webhook as a secret rather than leaving it in a broadly accessible workspace file.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup.sh:80
Finding

Mutable Remote Homebrew Installer Is Downloaded and Executed

Content
View full analysis
/dev/null; then read -p " Homebrew 未安装。安装 Homebrew?[y/N] " -n 1 -r echo if [[ $REPLY =~ ^[Yy]$ ]]; then /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" fi fi ``` ### Technical Analysis The installer downloads a shell script from the mutable `HEAD` reference of the official Homebrew GitHub repository and immediately passes its contents to Bash. Although the source is the official Homebrew repository rather than a personal paste site, the effective payload is not fixed at audit time. No commit identifier, checksum, or cryptographic signature is verified before execution. The user's confirmation authorizes installing Homebrew, but it does not establish the integrity of the particular script returned by the remote server. This behavior is not required for the Skill's core document-analysis functionality. Homebrew can be installed separately as an explicit prerequisite, avoiding remote code execution inside the Skill installer. ### Attack Path 1. An attacker compromises the upstream repository, the referenced branch, a privileged maintainer account, or the content-delivery path. 2. The attacker modifies the script returned by `install/HEAD/install.sh`. 3. A user runs `setup.sh` on a machine without Homebrew and approves the installation prompt. 4. `curl` retrieves the modified payload. 5. Bash immediately executes the attacker-controlled script with the privileges of the installing user. 6. The payload can modify user files, install persistence, access data available to the user, or request elevated privileges through the normal Homebrew installation flow. ### Impact Assessment Successful exploitation provides arbitrary command execution under the installing user ...[truncated 311 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
scripts/setup.sh:171
Finding

Persistent Scheduled Jobs Execute Scripts from a User-Writable Workspace

Content
View full analysis
/dev/null \ || echo " ⚠️ cron 注册失败(可能已存在)" fi # [7/8] cron 任务 2 echo "" echo "[7/8] 注册 cron 任务 2:06:00 飞书摘要推送..." read -p " 注册 06:00 cron(每天自动推送摘要到飞书)?[y/N] " -n 1 -r echo if [[ $REPLY =~ ^[Yy]$ ]]; then openclaw cron add \ --name "06:00发送文档摘要" \ --cron "0 6 * * *" \ --tz "Asia/Shanghai" \ --session isolated \ --timeout-seconds 300 \ --message "请读取 summaries/ 目录当天生成的文件,用 message 工具发送摘要到飞书" \ --announce --channel feishu --to "user:\$FEISHU_USER_ID" 2>/dev/null \ || echo " ⚠️ cron 注册失败(可能已存在)" fi ``` ### Technical Analysis The installer creates two cross-session scheduled tasks. The first task executes `run_analysis.py` and `generate_catalog.py` from `~/.openclaw/workspace/knowledge/.analysis`, a location controlled by the user and potentially writable by other processes operating under the same account. The scheduled behavior is disclosed and confirmation-gated, so it is not hidden persistence. Nevertheless, executing mutable scripts on a recurring schedule creates a persistent execution primitive. Any process that can replace or modify those scripts can cause its code to be run later by OpenClaw. The second scheduled task instructs an Agent to ...[truncated 1232 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/setup.sh:147
Finding

Installer Broadens Default Agent Permissions to Command and Process Execution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:87
Finding

Third-Party Packages Are Installed Without Version or Integrity Pinning

Content
View full analysis
/dev/null; then echo " ✅ $pkg 已安装" else read -p " 安装 $pkg — $desc?[y/N] " -n 1 -r echo if [[ $REPLY =~ ^[Yy]$ ]]; then brew install "$pkg" fi fi } install_brew_package "antiword" ".doc 文件提取" install_brew_package "tesseract" "OCR 引擎" install_brew_package "pandoc" "文档格式转换" install_brew_package "libreoffice" "Office 文档转换" # [3/8] Python 包 echo "" echo "[3/8] 检查 Python 包..." for pkg in pymupdf python-docx openpyxl python-pptx pdfplumber Pillow; do if pip3 show "$pkg" &> /dev/null; then echo " ✅ $pkg 已安装" else read -p " 安装 $pkg?[y/N] " -n 1 -r echo if [[ $REPLY =~ ^[Yy]$ ]]; then pip3 install "$pkg" fi fi done ``` ### Technical Analysis The installer resolves Homebrew formulae and Python packages by name without exact versions, hashes, signatures, or a lockfile. This conflicts with the installer's statement that package versions are fixed. Because dependency resolution happens at installation time, the installed artifacts may differ from those reviewed during the Skill audit. User confirmation authorizes installation but does not verify package identity or integrity. The reviewed package names do not demonstrate dependency confusion or typosquatting by themselves. The confirmed issue is the absence of reproducible, integrity-checked dependency resolution. ### Attack Path 1. A package repository, package release, maintainer account, or dependency is compromised. 2. A malicious or unexpectedly changed package version becomes the version resolved by Homebrew or `pip3`. 3. The user approves installation. 4. The package manager downloads and installs the ...[truncated 462 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:205
Finding

Feishu Webhook Bearer Secret Is Stored Without Enforced Access Restrictions

Content
View full analysis
~/.openclaw/workspace/.feishu/webhook_url echo " ✅ 飞书 webhook URL 已保存" fi fi ``` ### Technical Analysis The webhook URL is a bearer credential: possession of the URL may be sufficient to submit messages to the associated Feishu webhook. The script writes it as plaintext and relies on the caller's current `umask` to determine directory and file permissions. The script does not enforce mode `700` on the secret directory or mode `600` on the secret file. On systems with permissive defaults or shared workspace access, another local user or process may be able to read the credential. The secret is also entered through ordinary `read`, so it may be visibly echoed in the terminal. ### Attack Path 1. The user enters and saves a valid Feishu webhook URL. 2. The file is created with permissions derived from a permissive `umask`, or another process already has access to the workspace. 3. A local attacker or compromised process reads `.feishu/webhook_url`. 4. The attacker uses the recovered URL to submit unauthorized webhook messages. 5. Messages may impersonate the configured integration or be used for spam, phishing, or misinformation. ### Impact Assessment The direct impact is compromise of the configured Feishu webhook identity and destination. An attacker may send unauthorized messages to the associated channel. The finding does not by itself provide access to Feishu user accounts or prove that document contents are transmi ...[truncated 24 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a broad, high-risk system setup and automation skill, including installation, configuration changes, scheduled task registration, webhook pushing, OCR repair, and cleanup operations. This code chunk does only a narrower subset: local file discovery, text extraction, summary file writing, and state persistence for batch analysis. While document analysis is consistent with part of a knowledge-base pipeline, the actual code does not implement most of the prominently declared capabilities. That makes the description materially broader than the behavior of this supplied chunk. This is a mismatch in represented capabilities, though not because the code is more dangerous than declared; rather, the code is substantially narrower than the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code substantially matches the setup-oriented portion of the description: it performs shell execution, file writes, package installation, Ollama model download, OpenClaw config modification, cron registration, and Feishu webhook storage. However, the declared description goes materially beyond what this code chunk does by advertising several operational/maintenance capabilities—OCR repair, extraction quality checks, archive cleanup, migration/packaging, and specific document-processing fallbacks—that are absent from the supplied script. There is also a concrete discrepancy in claiming fixed-version Homebrew installs while the script uses ordinary brew install commands with no version pinning. Since the prompt asks whether the description accurately represents what the supplied code chunk actually does, these extra claimed capabilities make the description not accurate for this chunk, even though there are no obvious dangerous undeclared behaviors beyond what was disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The supplied code only implements a supporting document-processing utility layer for a knowledge-base workflow: text extraction, OCR fallback, office/PDF conversion, gibberish/CMap detection, and JSON state/cache/progress file handling. While this aligns with a narrow subset of the declared description (document parsing and OCR repair), the declared purpose presents the skill as a much broader high-risk system setup and automation tool with installation, configuration, scheduling, and webhook capabilities. None of those major capabilities appear in this code chunk. Because the declared description materially overstates what this chunk actually does, the description does not accurately represent the behavior of the supplied code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

This skill creates persistent workspace directories and deploys analysis scripts into a long-lived user path that is later used by scheduled automation. In the context of a skill that also documents cron-based execution and config modification, such persistence increases the blast radius of any later script tampering or misuse because artifacts remain available for recurring execution.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

Step 4: 创建目录结构

bash
mkdir -p ~/.openclaw/workspace/knowledge/.analysis/summaries/archives
mkdir -p ~/.openclaw/workspace/knowledge/temp_docs
touch ~/.openclaw/workspace/knowledge/文章目录/文章目录.md

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes the cron timezone to Asia/Shanghai without showing any user opt-in or validation against the host environment. In a persistence-capable automation skill, forced timezone assumptions can cause tasks to run at unexpected times, which may trigger unattended file processing or outbound messaging when the user does not expect it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains user-facing natural-language content entirely in Chinese in the module docstring, and later prints user-visible status messages in Chinese as well. The file does not offer a language choice or explain that the skill is intentionally region-specific, which can violate language/locale policy for general-purpose skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring is entirely in Chinese, and the script's user-facing console messages are also hard-coded in Chinese throughout the file. For a general-purpose analysis script, this imposes a specific language/locale without any opt-in, fallback, or documented justification, which matches the natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup.sh (reported line 68)May include surrounding context.

sh
# [1/8] 创建目录
echo ""
echo "[1/8] 创建知识库目录..."
mkdir -p ~/.openclaw/workspace/knowledge/.analysis/summaries/archives
mkdir -p ~/.openclaw/workspace/knowledge/temp_docs
mkdir -p ~/.openclaw/workspace/knowledge/"Macro Financials"
mkdir -p ~/.openclaw/workspace/knowledge/文章目录

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script prompts for a Feishu webhook URL and writes it in plaintext to ~/.openclaw/workspace/.feishu/webhook_url without warning, masking, or permission hardening. Webhook URLs are bearer-style secrets; any local user, backup process, or later tool with filesystem access could read and misuse it to send unauthorized messages or abuse the integration.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This finding is valid because the script persists a sensitive webhook credential inside a long-lived workspace path. In the context of a skill that already enables exec/process permissions and scheduled automation, storing the token persistently increases the blast radius: any later local process, agent task, or user with access to that workspace may retrieve and abuse the webhook.

Content

Scanner excerpt · scripts/setup.sh (reported line 213)May include surrounding context.

sh
if [[ $REPLY =~ ^[Yy]$ ]]; then
    read -p "  请输入飞书 webhook URL: " FEISHU_WEBHOOK_URL
    if [[ -n "$FEISHU_WEBHOOK_URL" ]]; then
        mkdir -p ~/.openclaw/workspace/.feishu
        echo "$FEISHU_WEBHOOK_URL" > ~/.openclaw/workspace/.feishu/webhook_url
        echo "  ✅ 飞书 webhook URL 已保存"
    fi

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This Python file contains natural-language descriptions entirely in Chinese, including the top-level module docstring and multiple user-facing error/status strings elsewhere in the file. Under the policy, forcing a specific language without user opt-in is a locale-policy violation unless the constraint is explicitly justified, which is not documented here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/utils.py (reported line 174)May include surrounding context.

python
def extract_doc_via_antiword(filepath):
    try:
        result = subprocess.run(['antiword', filepath], capture_output=True, timeout=10)
        if result.returncode == 0:
            text = result.stdout.decode('utf-8', errors='replace')
            if len(text) > 100:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/utils.py (reported line 186)May include surrounding context.

python
def _kill_proc_tree(pid):
    try:
        # v1.4.3: 替换 os.system 为 subprocess.run(避免 shell 注入 + 抑制输出)
        subprocess.run(["pkill", "-P", str(pid)],
                       capture_output=True, timeout=5)
    except (subprocess.TimeoutExpired, Exception):
        pass

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/utils.py (reported line 210)May include surrounding context.

python
os.remove(tmp_out)
            except:
                pass
        proc = subprocess.Popen(
            ['soffice', '--headless', '--convert-to', new_ext, '--outdir', tmp_dir, filepath],
            stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/utils.py (reported line 367)May include surrounding context.

python
try:
        shutil.copy2(filepath, tmp_pdf)
        # v2.1 修复:用 --force-ocr 替代 --skip-text,确保 OCRmyPDF 强制 OCR 所有页面
        result = subprocess.run(
            ["ocrmypdf", "-l", "chi_sim+eng", "--force-ocr",
             "--pages", "1-999", tmp_pdf, tmp_out],
            capture_output=True, timeout=600   # v2.1: 超时从 60s 提升到 600s

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/utils.py (reported line 415)May include surrounding context.

python
tmp_dir = tempfile.mkdtemp(prefix="office_ocr_")
    try:
        # 1. soffice 转 PDF
        proc = subprocess.Popen(
            ['soffice', '--headless', '--convert-to', 'pdf', '--outdir', tmp_dir, filepath],
            stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/utils.py (reported line 436)May include surrounding context.

python
# 2. OCRmyPDF --force-ocr
        ocr_pdf = os.path.join(tmp_dir, uuid.uuid4().hex + "_ocr.pdf")
        result = subprocess.run(
            ["ocrmypdf", "-l", "chi_sim+eng", "--force-ocr",
             "--pages", "1-999", converted_pdf, ocr_pdf],
            capture_output=True, timeout=600

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing natural language entirely in Chinese, such as the version descriptions and bullet points. Under the language/locale policy rule, forcing a specific language without opt-in or documented locale justification is a policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description says the automated workflow sends the Feishu summary at 08:00, but later documentation states 06:00 as part of the declared capability range. In the same file, the concrete cron registration example also uses 08:00, so the 06:00 statement contradicts the actual documented behavior and can mislead users about when persistent automation will run.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring and generated output strings indicate the script is designed specifically around Chinese-language labels and catalog headings. Under the language/locale policy, hard-coding a single language without user opt-in or documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code creates the target directory and overwrites 文章目录.md with generated content. Although file generation is part of the script's purpose, this file itself provides no explicit user-facing disclosure via prompt, print, or warning before performing the write, so users may not realize an existing catalog file will be replaced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The cron configuration forces the timezone to Asia/Shanghai in natural-language-visible configuration values. This is a locale policy issue because the user is not offered a choice, and the file does not justify why this specific region setting is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This scheduled task also fixes the timezone to Asia/Shanghai, creating the same locale constraint for all users regardless of their environment. The file does not provide opt-in or a region-specific justification for this setting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.