Back to skill

Security audit

Price Monitor Skill

Security checks for vulnerabilities and agentic risk

Overview

This Lite price-monitoring skill includes undisclosed Pro-like monitoring, notification, and login helper files that do not match its documented purpose.

Review this skill before installing. The advertised Lite entry point is narrow, but the package contains extra executable code for JD monitoring, external notifications, and ClawHub login logging. Install only if you trust the publisher, understand those extra files, and are comfortable auditing or removing the undocumented components.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
do_login.sh:3
Finding

Authentication output written to an insecure predictable temporary file

Content
View full analysis
"$LOG_FILE" clawhub login >> "$LOG_FILE" 2>&1 ``` ### Technical Analysis The undocumented login helper redirects all standard output and error output from `clawhub login` to the fixed path `/tmp/clawhub_login.log`. It does not establish a restrictive `umask`, explicitly set file permissions, create the file atomically, or verify that the destination is not a symbolic link. With a common `umask` of `022`, a newly created log may be readable by other local users. Authentication output could contain temporary login URLs, authorization codes, account identifiers, or diagnostic information. Because the filename is predictable, unsafe symbolic-link handling may also allow redirection to another file where operating-system protections and local permissions permit it. Invoking ClawHub authentication is not required for the documented manual price-comparison functionality and therefore exceeds the Skill's minimum necessary operational scope. ### Attack Path 1. A victim installs the Skill and manually invokes `do_login.sh`. 2. The script creates or truncates the predictable `/tmp/clawhub_login.log` path. 3. The `clawhub login` process writes all authentication and diagnostic output to that file. 4. Under permissive file-creation settings, another local user reads authentication-related output from the log. 5. Alternatively, where symbolic-link and filesystem permissions allow it, an attacker pre-creates the path as a symbolic link, causing the victim's shell redirection to truncate or append to an unintended target. 6. The file remains in `/tmp` after the login process exits, extending the disclosure window. ### Impact Assessment This issue may expose authentication metadata or temporary log ...[truncated 326 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/price_monitor.py:134
Finding

Undocumented transmission of monitoring data to configurable notification endpoints

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a Lite version limited to Taobao/Pinduoduo basic search, but the detected behavior reportedly includes JD support, message-push integrations, and automated cross-platform alerting not disclosed in the manifest. Undeclared outbound notification and expanded platform coverage increase the attack surface and may enable silent data transmission or user tracking beyond what a user would reasonably expect from the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a Lite version limited to Taobao/Pinduoduo basic search, but the detected behavior reportedly includes JD support, message-push integrations, and automated cross-platform alerting not disclosed in the manifest. Undeclared outbound notification and expanded platform coverage increase the attack surface and may enable silent data transmission or user tracking beyond what a user would reasonably expect from the description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill declares no explicit tool scope even though detected capabilities include file read and network access. Missing permission boundaries can allow a seemingly simple price-monitoring skill to access local files or make external requests without user visibility, which increases the risk of data exposure or capability abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description, trigger phrase, and usage example require Chinese-language interaction, but the file does not state that the skill is region- or language-specific or offer users an opt-in choice of language. This can violate language/locale policy when a skill implicitly forces a specific language for activation and use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs a background-style authentication flow and writes login output to /tmp, which does not align with a lightweight price-monitoring skill that should not require separate account login behavior. This mismatch increases the risk that the skill is collecting or using credentials for an unrelated external service, and the log file may capture sensitive authentication details in a world-accessible temporary location.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The command authenticates to an external service even though the declared scope is basic multi-platform price search, making the capability unjustified and suspicious in context. Unnecessary authentication expands the attack surface, may grant the skill persistent access to third-party resources, and could expose credentials or session material through command output logging.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The implementation exceeds the declared lite-edition scope by including JD monitoring despite metadata stating only Taobao/Pinduoduo support. Capability mismatches are dangerous because users and reviewers may grant permissions or trust based on the manifest while the code performs broader network activity than disclosed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends outbound notifications to Feishu and Telegram, but the skill description only advertises basic price search. Undisclosed exfiltration paths are security-relevant because monitored keywords and price reports can leave the local environment and be transmitted to third-party services without clear user expectation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Price reports include searched keywords and platform results, and these are transmitted to configured Feishu/Telegram endpoints without any in-script disclosure or consent flow. In this skill context, search terms may reveal business interests, purchase plans, or sensitive product monitoring targets, so silent third-party transmission increases privacy and data-leak risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The code performs external transmission to the Telegram API containing the generated monitoring report. In context this appears to be intended notification functionality, but it is still security-relevant because it sends potentially sensitive monitored keywords and pricing data to a third party and was not clearly disclosed by the manifest.

Content

Scanner excerpt · scripts/price_monitor.py (reported line 154)May include surrounding context.

python
if token and chat_id:
        try:
            text = urllib.parse.quote(message[:4000])
            url = f"https://api.telegram.org/bot{token}/sendMessage?chat_id={chat_id}&text={text}"
            urllib.request.urlopen(url, timeout=5)
        except:
            pass

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module description and all user-facing output strings are in Chinese, and the skill does not offer any language selection or explain that it is intentionally limited to Chinese-speaking users. This creates a natural-language locale policy issue because the skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The comment/title uses Chinese ('配置') in a way that suggests the skill or its configuration may be localized to a specific language without any visible user choice or justification in this file. Per policy, forcing a specific language or locale without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language interface elements and module description are entirely in Chinese, and the file does not indicate that language choice is optional or that the tool is intentionally restricted to a Chinese-speaking context. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The inline module documentation explicitly says the script supports three platforms including 京东/JD. This conflicts with the manifest description of the lite edition as supporting only Taobao and Pinduoduo, creating an intent/documentation mismatch for the skill's scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code sends the user's keyword to external e-commerce sites by embedding it in request URLs and performing HTTP requests. There is no confirmation prompt, disclosure message, or comment/docstring warning that user input will be transmitted to third-party services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.