T09 · Insecure Skill Coding Practices
- Location
main.py:14- Finding
Hardcoded Default Recipient Can Cause Unauthorized Disclosure of Shipping Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real shipping-price monitor, but it can automatically send sensitive price alerts to external chat systems using a hardcoded default recipient and loosely controlled webhook settings.
Review before installing. Configure an explicit notification recipient and trusted chat channel, avoid relying on the default target, and treat webhook URLs as secrets. Use only official Feishu/WeCom webhook endpoints, restrict who can edit the config files, and run the monitor from a directory writable only by trusted users.
main.py:14Hardcoded Default Recipient Can Cause Unauthorized Disclosure of Shipping Data
services/feishu_bot.py:42Unrestricted Webhook URLs Permit Server-Side Request Forgery and Alert Exfiltration
services/feishu_bot.py:19Ambiguous Messaging Module Import Enables Local Tool Spoofing
This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.
This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.
This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.
This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.
This finding is credible because the skill specifically instructs use of WeCom long connections and arbitrary webhook URLs, yet the stated purpose does not foreground outbound enterprise messaging as a core capability. That gap is especially risky in this context because commercial pricing and route data are sensitive business information and external transmission could expose them to unintended recipients.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
self.rules["rules"] = []
self.rules["rules"].append(rule)
self._save_rules()
return rule_id
def update_rule(self, rule_id: str, updates: dict) -> bool:
for rule in self.get_rules():
The skill advertises capabilities that imply local file access, configuration writes, and outbound notifications, but it does not declare any explicit tool scope or permission boundaries. That creates an authorization and transparency gap: users and the runtime may not clearly understand that the skill can read local directories, write settings, and send data externally.
The skill does not clearly warn users that it will automatically transmit shipping prices and route information to external services via long connection or webhook. In this business context, those data points can reveal commercial terms, lanes, and timing, so silent export meaningfully increases confidentiality risk.
The rule name and description are written only in Chinese, which imposes a specific language on users or operators consuming this configuration. The file does not indicate that Chinese is optional, selectable, or required for a justified region-specific use case.
The module docstring is entirely in Chinese and presents the skill description only in that language, with no indication that users may choose another language or locale. Under the policy criteria, natural-language content that imposes a specific language without opt-in can be a locale-policy violation.
This code uses Chinese-only natural-language documentation and later emits Chinese-only user-facing status and error messages, with no indication that the skill is region-specific or that users can opt into another language. That creates a language/locale policy issue under the rule for natural-language policy violations.
The skill description limits scope to monitoring carrier prices from Excel files and sending alerts on threshold drops. In addition to alert delivery, this code modifies local configuration by storing channel selection and webhook URLs in settings.yaml, which is a broader operational behavior than the manifest states.
A shipping price monitoring skill is expected to send alerts, but this module goes further by accepting and persisting Feishu and WeCom webhook endpoints. Credential/configuration management for third-party messaging systems is a separate capability that is not declared in the manifest's stated scope.
Webhook URLs are effectively bearer secrets because anyone possessing them can often post messages into the associated chat channel. Writing them in plaintext to a local YAML file without user-facing disclosure or stronger secret handling increases the risk of credential leakage through local compromise, backups, logs, or accidental file sharing.
This code presents titles, status output, logs, and command guidance only in Chinese, which imposes a specific language on all users. The policy allows language constraints only when the skill offers a choice or clearly documents a justified locale-specific scope, neither of which appears in this file.
The webhook path performs an outbound HTTP request carrying the provided message body, which may include user or system data. While the function names imply sending, there is no confirmation prompt, visible user-facing log/print, or explanatory comment/docstring warning that content will be transmitted to an external Feishu endpoint.
The manifest describes a skill for monitoring shipping carrier prices from Excel files and sending alerts when thresholds are met, but this file implements a generic Enterprise WeCom bot with OpenClaw and webhook delivery logic. While alerting is related, the code exposes a standalone messaging capability decoupled from shipping-price or Excel-specific logic, which is broader than the manifest-described behavior.
This code sends the provided message content to an external Enterprise WeCom webhook endpoint using an HTTP request, but there is no confirmation prompt, user-facing logging, or explanatory comment/docstring warning that message data will leave the local system. Because the file is a code file, outbound transmission of user or system data should have some visible disclosure unless clearly documented as part of the skill's stated purpose.
The title and core operating instructions are written in Chinese, which effectively imposes a language requirement on users. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.
The _save_rules method performs a file write to config/rules.json, but the code provides no confirmation prompt, user-facing log/print, or explanatory comment/docstring disclosing that persistent configuration changes are being made. This is a safety-relevant file modification operation under the code-file warning criteria.
Module documentation and user-visible status/message strings in this file are exclusively Chinese, which may force a specific language experience without offering a locale choice. The policy allows fixed locale behavior only when explicitly documented and justified, which is not present here.
The send() method transmits formatted alert content and target information to external Feishu or WeCom services through webhook/OpenClaw send methods. In this file, there is no user-facing notice, confirmation, or explanatory comment/docstring disclosing that alert data will be sent to external services.
No suspicious patterns detected.