T09 · Insecure Skill Coding Practices
- Location
index.js:53- Finding
Path Traversal Allows Files to Be Written Outside the Intended Output Directory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Xiaohongshu content generator, but it needs review because unsafe input handling can write files outside the chosen output folder and inject active HTML into browser-rendered output.
Review before installing. Use only trusted topic values, choose an isolated output directory, and avoid running it in a workspace with sensitive writable files until path containment, filename slugging, HTML escaping, dependency pinning, and browser rendering restrictions are fixed.
index.js:53Path Traversal Allows Files to Be Written Outside the Intended Output Directory
index.js:275Unescaped Topic Input Enables HTML and Script Injection in Rendered Content
temp-convert.js:31Standalone Puppeteer Converter Disables Chromium Sandbox Protections
Referenced artifact was not completely inspected
import { generateXiaohongshuArticle } from './index.js';
The file title and all usage examples are written as a Chinese-only Xiaohongshu content generation workflow, with no indication that users can choose another language or locale. This is a natural-language policy concern because the examples implicitly constrain output language and platform style without documenting opt-in or a justified region-specific limitation.
SQP-3 applies to all file types and covers language or locale policy violations. The README consistently assumes Chinese with no mention of alternative language support or that the skill is intended only for Chinese-speaking users, which can amount to forcing a specific language without user opt-in.
The skill instructs the agent to collect hot-topic data from third-party platforms like 脉脉、微博、知乎 without clearly disclosing that external browsing or content sourcing will occur. In a skill with browser, shell, and filesystem access, this can lead to unexpected outbound access, opaque data provenance, and potential ingestion of untrusted or copyrighted content into generated outputs.
The file description and generated output are explicitly hardcoded for 小红书-style Chinese content, and the HTML also fixes the locale to zh-CN. There is no user opt-in, language selection, or documented region-specific justification, which violates the language/locale policy requirement.
The manifest description states the skill generates '小红书风格' content and is written entirely as a Chinese-language capability, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill implicitly constrains output language without explicit opt-in or documented regional limitation.
The natural-language metadata is entirely Chinese and positions the skill around a Chinese-platform workflow, but it does not explicitly state that the skill is Chinese-only or offer any user language/locale choice. Under the policy, forcing a specific language or locale without opt-in can be a violation unless clearly justified and documented.
The trigger "图文生成" is generic and not clearly limited to Xiaohongshu-specific usage. In a manifest file, such a broad activation phrase can match ordinary user requests and cause unintended invocation of this specific skill.
The manifest grants shell access to a content-generation skill even though the declared functionality only describes generating Xiaohongshu-style copy, HTML, and images. Unnecessary shell capability expands the attack surface significantly: if downstream code uses user-controlled inputs with shell commands, it could enable command execution or filesystem abuse.
This JavaScript file includes natural-language comments and runtime console output in Chinese, such as the configuration and status messages. The policy requires flagging language or locale constraints when the skill forces a specific language without offering user choice or documenting a justified locale restriction.
The example command writes HTML, markdown, and image files to a local output directory, but the surrounding documentation does not explicitly warn users that running the skill will create files on disk. For markdown guidance, data-affecting behavior should be disclosed clearly so users understand the side effects before running the command.
This is a markdown file, so SQP-2 applies to missing user-facing warnings about behaviors affecting user data or system state. The README documents output paths and generated files, but it does not explicitly warn that execution will create directories and overwrite or populate files under the chosen output path.
The trigger field lists short phrases like “小红书生成” and “图文生成”, which can overlap with generic content-generation requests and do not specify boundaries for when this skill should or should not activate. The file also does not provide negative examples or narrower context limits to reduce unintended invocation.
Using a caret version for puppeteer allows installation of newer minor/patch releases without explicit review, which can introduce unexpected vulnerable or breaking dependency changes into the skill. In an automation package that renders/generated HTML and may launch a browser, dependency drift increases supply-chain risk even if the manifest itself does not prove exploitability.
"author": "OpenClaw",
"license": "MIT",
"dependencies": {
"puppeteer": "^21.0.0"
},
"peerDependencies": {
"html-pages-to-images": "file:../html-pages-to-images"
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
No suspicious patterns detected.