Back to skill

Security audit

tencent-cloud-article-publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it handles live Tencent Cloud session cookies and can publish publicly under the user's account without enough scoping or confirmation safeguards.

Install only if you are comfortable giving the skill a live Tencent Cloud browser session Cookie and allowing it to publish articles under that account. Avoid passing cookies on the command line; prefer a secure prompt or secret store, revoke or refresh any cookie already used this way, and require a manual review/confirmation before each publish.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
publish_tencent.py:73
Finding

Authentication Cookie Exposed Through Process Arguments and Shell History

Content
View full analysis
<正文> [cookie]") sys.exit(1) title = sys.argv[1] content = sys.argv[2] cookie = sys.argv[3] if len(sys.argv) > 3 else None ``` `README.md:26-36`: ```bash python3 publish_tencent.py "文章标题" "文章正文(支持Markdown)" "你的Cookie" ``` ```bash python3 publish_tencent.py \ "OpenClaw + Qwen3-TTS 自动化简报系统实战" \ "本文介绍如何用 **OpenClaw** 和 Qwen3-TTS 构建每日自动化简报系统..." \ "skey=xxx; qcloud_uid=xxx; qcommunity_session=xxx; ..." ``` `install.sh:15`: ```bash echo ' python3 ~/.openclaw/workspace/publish_tencent.py "标题" "正文" "Cookie"' ``` ### Technical Analysis The script accepts the complete Tencent Cloud authentication Cookie through `sys.argv`. Command-line arguments are not an appropriate transport for session credentials because they may be exposed through: - Process inspection facilities while the command is running. - Shell command history after execution. - Terminal session recording. - Automation, monitoring, or endpoint telemetry that captures process command lines. - Diagnostic logs that record invoked commands. The Cookie includes authenticated session fields such as `skey` and `qcommunity_session`. Consequently, disclosure may permit session reuse until the Cookie expires or is revoked. This behavior also conflicts with the statement in `SKILL.md` that the Cookie is retained only in memory and discarded after use. Although the script does not explicitly write the Cookie to a file, the documented command-line workflow can cause it to be persisted by the shell or surrounding system. ### Attack Path 1. A user follows the documented c ...[truncated 1357 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:21
Finding

Unpinned and Unverified Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill asks users to provide live authentication cookies via private message and then uses them directly for authenticated API calls, without strong warning about account takeover risk, replay risk, or secret handling limitations. Session cookies are bearer credentials; anyone who obtains them may be able to act as the user on the target service until expiry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README instructs users to extract and pass live authentication cookies directly to the tool, but does not warn that these cookies are sensitive bearer credentials that can enable account actions if exposed. Because the skill publishes directly to a remote platform without a browser boundary, mishandling these values could let logs, shell history, prompts, or other tooling capture credentials and permit unauthorized posting or account compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation phrase "帮我发到腾讯云" is broad enough to plausibly match ordinary user intent and trigger publication behavior without sufficient specificity or confirmation. In a skill that can post content using supplied authentication cookies, accidental activation could cause unintended outbound actions and disclosure or misuse of authenticated publishing capability.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill performs network publication to an external API but does not declare an explicit tool scope or permissions boundary. That creates a transparency and governance gap: users and host systems may not realize the skill can exfiltrate provided content and authentication material to a remote service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill sends article content and authentication cookies to an external endpoint, which is expected for publishing but still constitutes sensitive external transmission. In this context it is more dangerous because the transmitted headers include reusable session credentials and the action causes an irreversible external side effect: publishing under the user's account.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
"closeTextLink": 0
    }
    
    resp = requests.post(url, headers=headers, json=payload, timeout=15)
    result = resp.json()
    
    if "articleId" in result:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase “帮我发布文章到腾讯云” is broad enough that normal conversational text could invoke a high-impact action skill. Because this skill can transmit user content and authentication cookies to publish externally, accidental activation could lead to unintended posting or credential handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments and echoed usage messages are presented in Chinese, which imposes a specific language on users of the skill. The file does not provide an opt-in, alternative language, or justification that the skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 5)May include surrounding context.

sh
# 安装脚本:将 skill 复制到 OpenClaw skills 目录

SKILL_DIR="$HOME/.openclaw/skills/tencent-cloud-publish"
mkdir -p "$SKILL_DIR"

cp "$(dirname "$0")/SKILL.md" "$SKILL_DIR/"
cp "$(dirname "$0")/publish_tencent.py" "$HOME/.openclaw/workspace/"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 5)May include surrounding context.

sh
# 安装脚本:将 skill 复制到 OpenClaw skills 目录

SKILL_DIR="$HOME/.openclaw/skills/tencent-cloud-publish"
mkdir -p "$SKILL_DIR"

cp "$(dirname "$0")/SKILL.md" "$SKILL_DIR/"
cp "$(dirname "$0")/publish_tencent.py" "$HOME/.openclaw/workspace/"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The docstrings and all user-facing CLI messages are written only in Chinese, including usage and error output. This imposes a specific language on users without any opt-in, fallback, or justification that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The script transmits user-supplied article content and raw authentication cookies to an external third-party endpoint, which is inherently sensitive because cookies are bearer credentials and the publication action is state-changing. In the context of an agent skill, this is more dangerous because a user may provide high-value session cookies and the skill can immediately act on their behalf without browser confirmation or scoped OAuth-style authorization.

Content

Scanner excerpt · publish_tencent.py (reported line 59)May include surrounding context.

python
print(f"发布标题: {title}")
    print(f"内容长度: {len(content_md)} 字符")
    
    resp = requests.post(url, headers=headers, json=payload, timeout=15)
    result = resp.json()
    
    if "articleId" in result:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The README presents the skill description and invocation guidance entirely in Chinese, including the example trigger phrase, without indicating whether other languages are supported or whether Chinese is required for a justified regional purpose. This can violate a language-choice policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

整个技能说明及示例均默认以中文呈现和操作,但没有说明这是仅面向中文用户的限定场景,也未提供语言/locale 选择。按照语言/locale 政策,若技能强制特定语言而无用户选择或合理限定,可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This shell script creates a skill directory under the user's home folder and copies files into both the skills and workspace directories. Although it prints completion messages afterward, there is no advance disclosure, confirmation, or explicit warning in the script itself before performing these filesystem writes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.