Back to skill

Security audit

Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated image/video generation purpose, but it relies on an unpinned global CLI that handles credentials and local files, and uploads may expose local files publicly.

Install only if you trust the current and future @xianchou/cli npm package. Prefer a pinned reviewed version, do not install or run it with elevated privileges, use a limited project access key, avoid passing sensitive local media because uploads can become public, and review dry-run output before using --write on Markdown files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Globally Installed npm Dependency Cannot Be Independently Verified

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9 and 22
Vulnerability Type: Unpinned third-party package installed globally
Risk Level: Medium

Vulnerable Code Snippet

yaml
metadata: {"openclaw":{"requires":{"bins":["xianchou"],"env":["XIANCHOU_ACCESS_KEY","XIANCHOU_PROJECT_ID","XIANCHOU_API_URL","XIANCHOU_CONFIG_DIR"]},"primaryEnv":"XIANCHOU_ACCESS_KEY","credentials":{"storage":"~/.xianchou/config.json","configDirEnv":"XIANCHOU_CONFIG_DIR","description":"xianchou auth login 写入的访问凭据,JSON 格式,存储 accessKey、projectId 和 apiUrl。"},"install":[{"id":"npm","kind":"node","package":"@xianchou/cli","bins":["xianchou"],"label":"Install Xianchou CLI (npm)"}],"category":"AIGC","tags":["xianchou","markdown","image-generation","video-generation","cli","ai-tools"]}}
bash
npm install -g @xianchou/cli

The same unpinned installation command also appears in README.md:35 and references/cli-command-guide.md:7.

Technical Analysis

The Skill requires installing the mutable npm package @xianchou/cli globally without specifying an exact version, package integrity hash, lockfile, or other immutable artifact identifier. The repository contains documentation only and does not include the CLI implementation, so the executable behavior cannot be independently audited from the reviewed project.

This is security-sensitive because the installed CLI is expected to:

  • Receive and store an access key and project identifier.
  • Read local Markdown, image, video, and audio files.
  • Upload selected local files to a remote service.
  • Make authenticated network requests.
  • Download generated assets.
  • Modify Markdown or MDX files when --write is used.

Global npm installation may also execute package lifecycle scripts with the privileges of the user performing the installation. Because no version is pinned, a future or compromised package release could differ materially from the package behavior intended when the Skill was reviewed.

This findin ...[truncated 1871 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin @xianchou/cli to an exact, reviewed version in both Skill metadata and every installation example, rather than resolving the latest release.
  2. Provide a trusted package integrity hash or an equivalent immutable artifact attestation and verify it before installation.
  3. Publish the corresponding CLI source code and build instructions alongside the Skill so reviewers can inspect the executable implementation.
  4. Use lockfiles and reproducible builds for the CLI and all transitive dependencies.
  5. Prefer a project-local, sandboxed installation over global installation. Run the CLI with the minimum filesystem and network permissions required.
  6. Disable npm lifecycle scripts during installation where compatible, for example through an approved installation process using --ignore-scripts.
  7. Sign releases and publish provenance or software-bill-of-materials information so consumers can verify package origin and dependency contents.
  8. Document the exact files, environment variables, and network destinations the CLI accesses.
  9. Store access keys with restrictive filesystem permissions and avoid exposing them to unrelated subprocesses.
  10. Keep installation instructions synchronized across SKILL.md, README.md, and references/cli-command-guide.md so users are not directed back to an unpinned command.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs use of commands that modify Markdown content and frontmatter, including a --write workflow, but does not warn users that files may be changed in place or overwritten. In an agent skill context, this increases the risk of unintended destructive edits because an autonomous agent may execute the documented workflow without prompting for confirmation, backup, or dry-run review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that uploaded local files are sent to platform storage and a publicly accessible URL is returned, but it does not prominently warn users that uploads become public. In an AI-agent/CLI context, this increases the risk that agents or users will upload sensitive local images, videos, audio, or document-derived assets under the assumption they remain private, causing unintended data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly states that uploaded local files become publicly accessible via a returned URL, but it does not prominently warn users about the privacy and data-exposure consequences. In a CLI meant for agents and automated workflows, this is dangerous because sensitive local media could be uploaded and exposed without the operator fully realizing the visibility scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide says local file paths supplied to generation commands are automatically detected, uploaded, and replaced with platform URLs, but it does not present this as a prominent security/privacy warning. That creates a meaningful risk of unintended exfiltration of local content, especially when an AI agent may pass local paths automatically during routine document or media workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is entirely written in Chinese starting from the title, with no indication that language selection is optional or that the skill is region-specific. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/common-pitfalls.md (reported line 8)May include surrounding context.

错误:

bash
curl https://api.xianchou.com/run

正确:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language instructions and descriptions in this README are entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience for a documented reason. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The --write flag causes in-place modification of the user's Markdown file, but the guide does not prominently warn that local files will be changed. This is a lower-severity integrity issue rather than a remote compromise, but in agent-driven editing flows it can still cause unintended content changes or overwrite user work if the effect is not clearly emphasized.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown describes behavior that generates files, downloads images, and inserts content into Markdown documents. While it mentions the actions factually, it does not include a clear warning that running with --write will modify user content and create local assets, which is relevant to user data and filesystem integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.