Back to skill

Security audit

shipping-price-monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real shipping-price monitor, but it can automatically send sensitive price alerts to external chat systems using a hardcoded default recipient and loosely controlled webhook settings.

Review before installing. Configure an explicit notification recipient and trusted chat channel, avoid relying on the default target, and treat webhook URLs as secrets. Use only official Feishu/WeCom webhook endpoints, restrict who can edit the config files, and run the monitor from a directory writable only by trusted users.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
main.py:14
Finding

Hardcoded Default Recipient Can Cause Unauthorized Disclosure of Shipping Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
services/feishu_bot.py:42
Finding

Unrestricted Webhook URLs Permit Server-Side Request Forgery and Alert Exfiltration

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
services/feishu_bot.py:19
Finding

Ambiguous Messaging Module Import Enables Local Tool Spoofing

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · core/analyzer.py (reported line 52)May include surrounding context.

python
self.rules["rules"] = []
        self.rules["rules"].append(rule)
        self._save_rules()
        return rule_id
    
    def update_rule(self, rule_id: str, updates: dict) -> bool:
        for rule in self.get_rules():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises capabilities that imply local file access, configuration writes, and outbound notifications, but it does not declare any explicit tool scope or permission boundaries. That creates an authorization and transparency gap: users and the runtime may not clearly understand that the skill can read local directories, write settings, and send data externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill does not clearly warn users that it will automatically transmit shipping prices and route information to external services via long connection or webhook. In this business context, those data points can reveal commercial terms, lanes, and timing, so silent export meaningfully increases confidentiality risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The rule name and description are written only in Chinese, which imposes a specific language on users or operators consuming this configuration. The file does not indicate that Chinese is optional, selectable, or required for a justified region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The module docstring is entirely in Chinese and presents the skill description only in that language, with no indication that users may choose another language or locale. Under the policy criteria, natural-language content that imposes a specific language without opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code uses Chinese-only natural-language documentation and later emits Chinese-only user-facing status and error messages, with no indication that the skill is region-specific or that users can opt into another language. That creates a language/locale policy issue under the rule for natural-language policy violations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description limits scope to monitoring carrier prices from Excel files and sending alerts on threshold drops. In addition to alert delivery, this code modifies local configuration by storing channel selection and webhook URLs in settings.yaml, which is a broader operational behavior than the manifest states.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

A shipping price monitoring skill is expected to send alerts, but this module goes further by accepting and persisting Feishu and WeCom webhook endpoints. Credential/configuration management for third-party messaging systems is a separate capability that is not declared in the manifest's stated scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Webhook URLs are effectively bearer secrets because anyone possessing them can often post messages into the associated chat channel. Writing them in plaintext to a local YAML file without user-facing disclosure or stronger secret handling increases the risk of credential leakage through local compromise, backups, logs, or accidental file sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code presents titles, status output, logs, and command guidance only in Chinese, which imposes a specific language on all users. The policy allows language constraints only when the skill offers a choice or clearly documents a justified locale-specific scope, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The webhook path performs an outbound HTTP request carrying the provided message body, which may include user or system data. While the function names imply sending, there is no confirmation prompt, visible user-facing log/print, or explanatory comment/docstring warning that content will be transmitted to an external Feishu endpoint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes a skill for monitoring shipping carrier prices from Excel files and sending alerts when thresholds are met, but this file implements a generic Enterprise WeCom bot with OpenClaw and webhook delivery logic. While alerting is related, the code exposes a standalone messaging capability decoupled from shipping-price or Excel-specific logic, which is broader than the manifest-described behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code sends the provided message content to an external Enterprise WeCom webhook endpoint using an HTTP request, but there is no confirmation prompt, user-facing logging, or explanatory comment/docstring warning that message data will leave the local system. Because the file is a code file, outbound transmission of user or system data should have some visible disclosure unless clearly documented as part of the skill's stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and core operating instructions are written in Chinese, which effectively imposes a language requirement on users. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The _save_rules method performs a file write to config/rules.json, but the code provides no confirmation prompt, user-facing log/print, or explanatory comment/docstring disclosing that persistent configuration changes are being made. This is a safety-relevant file modification operation under the code-file warning criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Module documentation and user-visible status/message strings in this file are exclusively Chinese, which may force a specific language experience without offering a locale choice. The policy allows fixed locale behavior only when explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The send() method transmits formatted alert content and target information to external Feishu or WeCom services through webhook/OpenClaw send methods. In this file, there is no user-facing notice, confirmation, or explanatory comment/docstring disclosing that alert data will be sent to external services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.