Back to skill

Security audit

NowPlaying XHS

Security checks for vulnerabilities and agentic risk

Overview

This movie-recommendation skill mostly matches its stated purpose, but it asks the agent to install global browser tooling and run a lingering local web server from a shared temp folder, so it needs review before installation.

Review before installing. Use the skill only in a restricted environment, avoid running the global agent-browser install from the skill, and do not use the chart screenshot workflow unless it is changed to serve only a private temporary directory bound to localhost with guaranteed cleanup. Expect movie, city, location, and preference queries to be sent to external search or movie-data providers.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:177
Finding

Unpinned Global Third-Party Package Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:531
Finding

Shared Temporary Directory Exposed Through a Persistent Network Server

Content
View full analysis
..." # 2. Start HTTP server (background) exec command="cd /tmp && nohup python3 -m http.server 8888 > /tmp/http.log 2>&1 &" background=true # 3. Wait for server to start exec command="sleep 2" # 4. Open browser and wait for chart rendering browser action=open url="http://localhost:8888/nowplaying-charts.html" # Wait 3 seconds to ensure Chart.js has loaded browser action=snapshot targetId="xxx" delayMs=3000 # 5. Screenshot (full page) browser action=screenshot targetId="xxx" fullPage=true type="png" # 6. Read and send screenshot (Feishu) # Screenshot path: /home/admin/.openclaw/media/browser/{uuid}.jpg # Use the message tool with the buffer parameter ``` #### Notes 1. **Wait time**: Wait at least 2-3 seconds for Chart.js to load and render. 2. **Full-page screenshot**: Ensure all charts are captured. 3. **Image format**: Browser screenshots are saved as JPG by default, using `/home/admin/.openclaw/media/browser/{uuid}.jpg`. 4. **Cleanup**: The HTTP server may be stopped after completion (optional). ``` ### Technical Analysis The command changes the working directory to the shared `/tmp` directory and starts Python's basic HTTP server with that directory as its document root: ```bash cd /tmp && nohup python3 -m http.server 8888 ... ``` By default, `python3 -m http.server 8888` listens on all available network interfaces rather than only the loopback interface. It can provide directory listings and serve readable files beneath its document root. Because the document root is the entire s ...[truncated 2556 chars]
Remediation
View remediation
/dev/null || true rm -rf "$WORK_DIR" } trap cleanup EXIT INT TERM ``` 6. Do not use `nohup` for a short-lived rendering server unless lifecycle management is guaranteed. 7. Create output files atomically with restrictive permissions and avoid following symbolic links. 8. Prefer direct local-file rendering or a browser API that can load generated HTML without starting a network listener. 9. If an HTTP server is unavoidable, disable directory listing and restrict requests to the single expected chart file. 10. Remove generated HTML, logs, screenshots, and temporary directories immediately after the image has been delivered. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is movie recommendation, but the skill also instructs local file creation, browser/server orchestration, and ancillary data collection not reflected in the description. This mismatch undermines informed consent and review, because operators may approve a low-risk content skill that actually performs higher-risk actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description says the skill provides '附近影院排片' (nearby cinema showtimes), which implies location-aware theater or schedule retrieval. In code, the implemented behavior is limited to fetching Rotten Tomatoes movie listings and Variety box-office data; there is no location input, theater lookup, or showtime retrieval anywhere in the file.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CONFIG.md (reported line 72)May include surrounding context.

bash
# 测试博查 API
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"猫眼电影 上海 今日排片"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CONFIG.md (reported line 72)May include surrounding context.

bash
# 测试博查 API
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"猫眼电影 上海 今日排片"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · CONFIG.md (reported line 95)May include surrounding context.

bash
# 测试博查 API
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"猫眼电影 上海 今日排片"}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manual trigger phrases are broad conversational requests such as asking what movies are good to watch, which can overlap with normal user speech and cause the skill to activate unintentionally. In an agent environment, this increases the chance of unexpected external fetching, scheduled recommendations, or context switching without clear user intent, even though the skill itself appears low-risk in function.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill requests or demonstrates network access and local file writing but does not declare an explicit tool/permission scope. That makes the effective capability set ambiguous and increases the chance that an agent executes higher-risk actions than reviewers or users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and the entire instruction set are written as a China-specific movie recommendation workflow, but there is no natural-language statement offering output language choice or clarifying that the skill is intentionally limited to Chinese-speaking users. Under the locale policy, forcing a specific language without opt-in can be a policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation examples include broad natural phrases like “帮我选一部电影” and “今天想去看电影,” which are common conversational requests and not narrowly scoped skill invocations. The description also says the skill triggers on '等问题', without negative examples or boundary conditions, making activation scope ambiguous.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded external domain reference reinforces that the skill is designed to exfiltrate query content to a nonlocal service. While not malicious on its face, repeated direct endpoint usage without declared scope or privacy controls increases data-handling risk.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

bash
# 1. 实时排片(优先使用博查 API)
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The hardcoded external domain reference reinforces that the skill is designed to exfiltrate query content to a nonlocal service. While not malicious on its face, repeated direct endpoint usage without declared scope or privacy controls increases data-handling risk.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

bash
# 1. 实时排片(优先使用博查 API)
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This additional external endpoint use expands the same privacy and governance concern to box-office lookups. The risk is moderate because it broadens outbound data paths and normalizes direct API calls from a content-oriented skill.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
-d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'

# 2. 票房数据(博查 API)
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"猫眼专业版 实时票房 [日期]"}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs package installation and browser dependency setup for a task that should only require fetching and formatting movie data. Allowing installation commands expands the attack surface dramatically by enabling arbitrary code acquisition and system modification in the runtime environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The repeated direct bocha.cn reference at this location confirms third-party transmission as an operational dependency. In combination with broad triggers and execution instructions, the skill context makes this more dangerous because more conversations may cause unreviewed outbound requests.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

方案 B:博查 API 搜索(实时性较好)

bash
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The repeated direct bocha.cn reference at this location confirms third-party transmission as an operational dependency. In combination with broad triggers and execution instructions, the skill context makes this more dangerous because more conversations may cause unreviewed outbound requests.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

方案 B:博查 API 搜索(实时性较好)

bash
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs starting a local HTTP server and issuing shell commands solely to render charts. Even if framed as visualization, spawning services and executing shell commands is outside the minimally necessary scope for recommendation output and can be abused for persistence, data exposure, or arbitrary local content serving.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes background execution, sleep-based process coordination, screenshots, and message sending for chart generation. This combination materially exceeds a simple data-retrieval skill and creates a reusable execution pattern for running and hiding auxiliary processes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Using nohup and background execution creates persistence beyond the immediate action, leaving a local HTTP server running after the task. Persistent processes increase the risk of unintended exposure of temporary files, port conflicts, and a foothold for later misuse within the session.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

md
write path=/tmp/nowplaying-chart.html content="<html>..."

# 2. 启动 HTTP 服务器(后台)
exec command="cd /tmp && nohup python3 -m http.server 8888 > /tmp/http.log 2>&1 &" background=true

# 3. 等待服务器启动
exec command="sleep 2"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The repeated server/shell orchestration for radar-chart generation confirms that broad execution capability is embedded as a standard part of the skill. Repetition increases risk because it normalizes privileged operations and provides multiple opportunities for misuse or later prompt-injection-driven expansion.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This is a second persistence pattern for the radar-chart workflow, again leaving a background HTTP server active. Repeated persistence instructions show that lingering processes are part of the intended design rather than an accidental artifact, which materially elevates operational risk.

Content

Scanner excerpt · SKILL.md (reported line 536)May include surrounding context.

md
write path=/tmp/nowplaying-charts.html content="<html>..."

# 2. 启动 HTTP 服务器(后台)
exec command="cd /tmp && nohup python3 -m http.server 8888 > /tmp/http.log 2>&1 &" background=true

# 3. 等待服务器启动
exec command="sleep 2"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest advertises '多维度评分' (multi-dimensional ratings), suggesting multiple rating sources or rating facets. The code only parses one numeric percentage from Rotten Tomatoes and does not aggregate or present additional rating dimensions such as audience score, critic count, IMDb, Metacritic, or other factors.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The stated purpose is current theatrical recommendations, ratings, and nearby cinema schedules. Fetching and summarizing Variety box-office news is a distinct media-news capability that is not necessary to provide now-playing recommendations or theater listings, making it an unjustified expansion of scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is entirely presented in Chinese and does not indicate that users may choose another language or locale. Under the language/locale policy, a fixed language should be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.