Back to skill

Security audit

aiclone

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate clone and backup skill, but it can package and overwrite sensitive agent identity, memory, and tool files, so it needs review before installation.

Install only if you intentionally want to clone agent configuration and memory. Use it with trusted packages only, inspect ZIP contents before import, avoid --force, back up the target workspace, test in an isolated workspace first, encrypt any package you transfer, and scan for secrets or private memory before sharing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
scripts/clone_robot.py:266
Finding

Unrestricted Archive Import Allows Agent Instruction and Memory Poisoning

Content
View full analysis

Vulnerability Details

File Location: scripts/clone_robot.py:266-283 and scripts/clone_robot.py:367-406
Vulnerability Type: Unrestricted archive member extraction into an agent workspace
Risk Level: High

Vulnerable Code

python
with zipfile.ZipFile(package_path, 'r') as zipf:
    for name in zipf.namelist():
        # Check path safety
        if not is_path_safe(name):
            print(f"  ❌ Unsafe path: {name}")
            return False

        # Check suspicious files
        if name.endswith(('.exe', '.bat', '.sh', '.cmd')):
            print(f"  ⚠️  Suspicious file: {name}")

        # Check absolute paths
        if os.path.isabs(name):
            print(f"  ❌ Absolute path: {name}")
            return False

    print(f"  ✅ Security check passed")
    return True
python
# List files that will be copied
print(f"\n📋 Files to be imported:")
files_to_import = []
with zipfile.ZipFile(package, 'r') as zipf:
    for name in zipf.namelist():
        if name != "clone_metadata.json":
            print(f"  ✅ {name}")
            files_to_import.append(name)

# Confirmation in non-force mode
if not force:
    print(f"\n⚠️  Warning: Existing files in the target directory will be overwritten!")
    print(f"   Use --force to skip confirmation")

    try:
        response = input("\nConfirm import? (y/N): ").strip().lower()
        if response not in ['y', 'yes']:
            print("❌ Import cancelled")
            return False
    except (EOFError, KeyboardInterrupt):
        print("\n❌ Import cancelled")
        return False

# Extract files
print(f"\n📥 Importing...")
target.mkdir(parents=True, exist_ok=True)

with zipfile.ZipFile(package, 'r') as zipf:
    for name in zipf.namelist():
        if name == "clone_metadata.json":
            continue

        # Validate path again
        if not is_path_safe(name):
            prin
...[truncated 3133 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define an explicit allowlist of permitted archive members, such as the documented core configuration filenames. Reject every unrecognized file rather than importing it.
  2. If optional subdirectories are supported in the future, define narrowly scoped permitted prefixes and acceptable file types for each directory.
  3. Reject executable and active-content extensions. A warning is insufficient.
  4. Require a manifest listing each authorized path, expected size, and cryptographic hash. Reject missing, additional, duplicate, or mismatched members.
  5. Authenticate packages with a trusted digital signature when packages are distributed between users or systems.
  6. Stage imported content in a secure temporary directory and present per-file diffs for instruction-bearing and persistent-state files.
  7. Back up existing files before replacement and perform rollback if any validation or write fails.
  8. Require explicit approval for replacing AGENTS.md, SOUL.md, TOOLS.md, MEMORY.md, and other security-sensitive files, even when --force is used.
  9. Do not describe a package as safe merely because its paths are traversal-safe. Distinguish structural ZIP validation from content trust and package authenticity.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/clone_robot.py:266
Finding

Missing Archive Resource Limits Allow ZIP-Bomb Denial of Service

Content
View full analysis

Vulnerability Details

File Location: scripts/clone_robot.py:266-283 and scripts/clone_robot.py:399-406
Vulnerability Type: Unbounded archive validation and extraction
Risk Level: Medium

Vulnerable Code

python
with zipfile.ZipFile(package_path, 'r') as zipf:
    for name in zipf.namelist():
        # Check path safety
        if not is_path_safe(name):
            print(f"  ❌ Unsafe path: {name}")
            return False

        # Check suspicious files
        if name.endswith(('.exe', '.bat', '.sh', '.cmd')):
            print(f"  ⚠️  Suspicious file: {name}")

        # Check absolute paths
        if os.path.isabs(name):
            print(f"  ❌ Absolute path: {name}")
            return False

    print(f"  ✅ Security check passed")
    return True
python
with zipfile.ZipFile(package, 'r') as zipf:
    for name in zipf.namelist():
        if name == "clone_metadata.json":
            continue

        if not is_path_safe(name):
            print(f"  ⚠️  Skipping unsafe path: {name}")
            continue

        target_file = target / name

        try:
            target_file.resolve().relative_to(target.resolve())
        except ValueError:
            print(f"  ⚠️  Skipping file outside target directory: {name}")
            continue

        zipf.extract(name, target)
        print(f"  ✅ {name}")

Technical Analysis

Validation examines member names but does not inspect or constrain archive resource characteristics. There is no maximum member count, maximum uncompressed size per member, maximum cumulative uncompressed size, compression-ratio threshold, or available-disk-space check.

Python's ZipFile.extract() expands each accepted member to disk without an application-level byte limit. A highly compressible archive can therefore be small during transfer but expand to a very large size during import. An archive with an excessi ...[truncated 1394 chars]

Remediation
View remediation

Remediation Suggestions

  1. Inspect every ZipInfo entry before extraction.
  2. Enforce a strict maximum archive member count.
  3. Enforce maximum compressed and uncompressed sizes for each member.
  4. Calculate the cumulative declared uncompressed size and reject packages exceeding a package-wide limit.
  5. Reject entries with an excessive compression ratio, while safely handling zero-byte compressed sizes.
  6. Compare the permitted expansion size with available disk space and configured filesystem quotas.
  7. Extract through bounded streaming rather than unrestricted ZipFile.extract(), tracking the actual number of bytes written.
  8. Abort and remove all staged files when any limit is exceeded.
  9. Extract into a temporary staging directory and move validated files into the workspace only after the entire package passes validation.
  10. Add automated tests covering highly compressed data, oversized members, excessive entry counts, and archives whose declared sizes differ from actual extracted output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 290)May include surrounding context.

text

**防护效果:**
- ✅ 阻止 `../../../etc/passwd` 等路径遍历攻击
- ✅ 阻止绝对路径 `/etc/passwd` 覆盖系统文件
- ✅ 双重验证(原始 + 规范化)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 312)May include surrounding context.

text

**防护效果:**
- ✅ 阻止 `../../../etc/passwd` 等路径遍历攻击
- ✅ 阻止绝对路径 `/etc/passwd` 覆盖系统文件
- ✅ 双重验证(原始 + 规范化)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 313)May include surrounding context.

text

**防护效果:**
- ✅ 阻止 `../../../etc/passwd` 等路径遍历攻击
- ✅ 阻止绝对路径 `/etc/passwd` 覆盖系统文件
- ✅ 双重验证(原始 + 规范化)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 522)May include surrounding context.

text

**防护效果:**
- ✅ 阻止 `../../../etc/passwd` 等路径遍历攻击
- ✅ 阻止绝对路径 `/etc/passwd` 覆盖系统文件
- ✅ 双重验证(原始 + 规范化)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 228)May include surrounding context.

text

**防护效果:**
- ✅ 阻止 `../../../etc/passwd` 等路径遍历攻击
- ✅ 阻止绝对路径 `/etc/passwd` 覆盖系统文件
- ✅ 双重验证(原始 + 规范化)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 229)May include surrounding context.

text

**防护效果:**
- ✅ 阻止 `../../../etc/passwd` 等路径遍历攻击
- ✅ 阻止绝对路径 `/etc/passwd` 覆盖系统文件
- ✅ 双重验证(原始 + 规范化)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 433)May include surrounding context.

text

**防护效果:**
- ✅ 阻止 `../../../etc/passwd` 等路径遍历攻击
- ✅ 阻止绝对路径 `/etc/passwd` 覆盖系统文件
- ✅ 双重验证(原始 + 规范化)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/best-practices.md (reported line 49)May include surrounding context.

bash
# 创建排除列表
cat > exclude.txt << EOF
*.env
*api_key*
*secret*
*token*

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 130)May include surrounding context.

md
".DS_Store",
    "*.pyc",
    "*.pyo",
    ".env",  # 环境变量文件(可能包含密钥)
    "*.key",  # 密钥文件
    "*.secret",  # 敏感文件
]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 151)May include surrounding context.

md
".DS_Store",
    "*.pyc",
    "*.pyo",
    ".env",  # 环境变量文件(可能包含密钥)
    "*.key",  # 密钥文件
    "*.secret",  # 敏感文件
]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 387)May include surrounding context.

md
".DS_Store",
    "*.pyc",
    "*.pyo",
    ".env",  # 环境变量文件(可能包含密钥)
    "*.key",  # 密钥文件
    "*.secret",  # 敏感文件
]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 581)May include surrounding context.

md
".DS_Store",
    "*.pyc",
    "*.pyo",
    ".env",  # 环境变量文件(可能包含密钥)
    "*.key",  # 密钥文件
    "*.secret",  # 敏感文件
]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
".DS_Store",
    "*.pyc",
    "*.pyo",
    ".env",  # 环境变量文件(可能包含密钥)
    "*.key",  # 密钥文件
    "*.secret",  # 敏感文件
]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 273)May include surrounding context.

md
".DS_Store",
    "*.pyc",
    "*.pyo",
    ".env",  # 环境变量文件(可能包含密钥)
    "*.key",  # 密钥文件
    "*.secret",  # 敏感文件
]

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/clone_robot.py (reported line 45)May include surrounding context.

python
".DS_Store",
    "*.pyc",
    "*.pyo",
    ".env",  # 环境变量文件(可能包含密钥)
    "*.key",  # 密钥文件
    "*.secret",  # 敏感文件
]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents commands that export/import ZIP archives and write files into a target workspace, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization gap: an agent may be induced to perform file-writing operations without a clearly bounded capability contract, increasing the chance of unsafe execution in environments that rely on manifest-declared permissions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and description present the skill entirely in Chinese and explicitly describe it as a general-purpose cloning tool for 'any AI robot', which suggests broad applicability rather than a region-specific tool. Under the policy, forcing a specific language without user opt-in or a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to send the generated clone package via common channels like email, cloud storage, or chat encourages exfiltration of packaged workspace data outside the source environment. Because the package may contain memories, identity definitions, tools, scripts, and other sensitive files, promoting ordinary transfer channels materially raises disclosure risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly treats identity, memory, user profile, tools, agents, and optional workspace directories as clonable artifacts, which may contain sensitive user-provided data, credentials, internal prompts, or operational context. Routine packaging and transfer of these files increases the risk of privacy leakage and unauthorized disclosure, especially because the feature is framed as normal cloning workflow rather than exceptional, consented backup/export.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is written entirely in Chinese, including all user-facing instructions and examples, with no indication that other languages are supported or that Chinese is required for a region-specific purpose. Under the policy, natural-language locale constraints should either be optional for the user or clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented clone flow creates an archive of the entire workspace, and this same file explicitly lists highly sensitive contents such as identity, user profile, memory, documents, scripts, and project assets. Even if the surrounding skill claims security hardening, these instructions normalize bulk export of personal and operational data without an explicit privacy warning, review gate, or mandatory exclusion check, creating a real risk of over-collection and unintended disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The checklist mentions API keys and environment variables must be reconfigured, which implies the clone process interacts with secret-bearing environments, but it does not clearly warn operators to verify that secrets were not included in the archive or shared during transfer. In a cloning/backup skill, omission of secret-handling guidance is dangerous because users may assume the package is safe to distribute and fail to audit for embedded credentials, tokens, or config leaks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description states in Chinese that any AI robot can use this tool, and the file's user-facing text throughout the CLI is presented only in Chinese. This imposes a specific language/locale on users without offering a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

文件标题和整份使用说明均以中文呈现(如“使用说明”),但文档中没有为用户提供语言选择、替代语言版本或对中文限定场景作出说明。根据该规则,若技能强制特定语言而无用户 opt-in,可构成自然语言政策问题。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

L351 指示使用默认脱敏参数 --redact-metadata,但全文命令参考中并不存在该参数;相反,L302 说明默认已脱敏,仅提供 --keep-paths 作为例外选项。结合 L419“所有命令参数一致”的声明,这属于文档意图与文档中实际可执行接口描述相互矛盾。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.