Back to skill

Security audit

115 Publish

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its 115 cloud-storage management purpose, but it handles account cookies and state-changing file actions with security and consent gaps that warrant manual review before installation.

Install only after reviewing or patching the credential and confirmation issues. Treat this skill as having broad access to your 115 account: it stores reusable session cookies locally, can browse file metadata, create remote download tasks, move files, and includes delete/clear operations. Use it only in an environment where the local account and workspace are trusted, and require explicit confirmations for downloads, organization, deletion, and recycle-bin clearing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
lib/auth-web.js:15
Finding

TLS Certificate Verification Disabled for Authentication Requests

Content
View full analysis

Vulnerability Details

File Location: lib/auth-web.js:15-27
Vulnerability Type: Improper certificate validation
Risk Level: High

js
this.httpClient = axios.create({
  baseURL: 'https://115.com',
  timeout: 10000,
  headers: {
    'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36',
    'Accept': 'application/json, text/plain, */*',
    'Accept-Language': 'zh-CN,zh;q=0.9,en;q=0.8',
    'Referer': 'https://115.com/'
  },
  httpsAgent: new https.Agent({
    rejectUnauthorized: false
  })
});

Technical Analysis

The authentication client explicitly sets rejectUnauthorized to false. This causes Node.js to accept expired, self-signed, incorrectly named, or attacker-generated certificates instead of validating the server certificate against trusted certificate authorities.

This client is used to generate login QR codes and poll login status. Consequently, the disabled validation affects an authentication-sensitive communication channel. HTTPS encryption alone does not provide server authenticity when certificate validation is disabled.

Attack Path

  1. An attacker obtains a network interception position, such as control of a malicious Wi-Fi access point, compromised proxy, DNS response, or upstream network device.
  2. The attacker redirects traffic intended for https://115.com to an attacker-controlled HTTPS server.
  3. The attacker presents an untrusted or self-signed certificate.
  4. The application accepts the certificate because rejectUnauthorized is disabled.
  5. The attacker supplies forged QR-code or login-status responses, observes authentication state, or captures authentication artifacts transmitted through this client.

Impact Assessment

Successful exploitation compromises the confidentiality and integrity of the web authentication flow. An attacker may manipulate the QR code presente ...[truncated 231 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the custom HTTPS agent and use Node.js certificate validation defaults.
  • Never set rejectUnauthorized: false in production or authentication code.
  • If a private trust chain is genuinely required, configure a narrowly scoped trusted CA bundle rather than disabling verification.
  • Consider certificate or public-key pinning only if the service has an appropriate certificate-rotation strategy.
  • Add an automated test confirming that connections with self-signed, expired, or hostname-mismatched certificates fail.
  • Ensure fallback authentication implementations follow the same certificate-validation policy.

T09 · Insecure Skill Coding Practices

Error
Location
lib/client/http-client.js:147
Finding

115 Session Cookies Can Be Forwarded to Arbitrary Origins

Content
View full analysis

Vulnerability Details

File Location: lib/client/http-client.js:147-178
Vulnerability Type: Credential disclosure through unrestricted outbound requests
Risk Level: Critical

js
async request(endpoint, options = {}) {
  const {
    method = 'GET',
    params = {},
    data = {},
    headers = {},
    useSign = false,
    retryCount = 0
  } = options;

  let release = null;

  try {
    // Rate limiting
    await this.checkRateLimit();

    // Acquire a concurrency slot
    release = await this.acquireSlot();

    // Build the complete URL
    const url = endpoint.startsWith('http') ? endpoint : `${this.apiBase}${endpoint}`;

    // Prepare request headers
    const requestHeaders = {
      ...this.defaultHeaders,
      ...headers,
      'Cookie': this.getCookieHeader()
    };

The cookie header is generated as follows:

js
getCookieHeader() {
  if (!this.cookie) return '';
  return `UID=${this.cookie.uid || ''}; CID=${this.cookie.cid || ''}; SE=${this.cookie.se || ''}`;
}

Technical Analysis

request() treats any endpoint beginning with http as a complete URL. It does not verify the URL scheme, hostname, port, or effective destination. The method then unconditionally attaches the authenticated 115 cookie to the request.

As a result, a caller able to influence endpoint can direct an authenticated request to an attacker-controlled server. The public batch() method also forwards each supplied req.endpoint to request(), increasing the number of reachable call paths. The condition additionally accepts malformed or unexpected strings beginning with http, rather than parsing and validating a URL.

Redirect handling also requires attention: even after validating the initial URL, credentials must not be forwarded if a redirect changes the origin.

Attack Path

  1. An attacker reaches a code path or integration that permits control of the ` ...[truncated 959 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not accept absolute URLs in the general authenticated API client. Require relative API paths beginning with /.
  • Parse destinations with the standard URL class and enforce an exact allowlist of HTTPS hostnames.
  • Reject user-info components, unexpected ports, non-HTTPS schemes, IP-literal hosts, and ambiguous hostname encodings.
  • Add the cookie only after the effective destination has passed validation.
  • Disable cross-origin redirects for credential-bearing requests, or manually validate every redirect target and remove credentials whenever the origin changes.
  • Separate clients by service origin if multiple official 115 domains are required. Give each client only the credentials needed for that origin.
  • Restrict visibility of the low-level request() interface and validate endpoints supplied to batch().
  • Add tests proving that requests to arbitrary URLs and cross-origin redirects cannot receive the 115 cookie.

T09 · Insecure Skill Coding Practices

Error
Location
lib/storage/cookie-store.js:43
Finding

Cookie Encryption Key Is Derived from Predictable Host Metadata

Content
View full analysis

Vulnerability Details

File Location: lib/storage/cookie-store.js:43-60
Vulnerability Type: Predictable key derivation for stored credentials
Risk Level: High

js
getMachineId() {
  const os = require('os');
  const crypto = require('crypto');
  const machineInfo = `${os.hostname()}-${os.platform()}-${os.arch()}`;
  return crypto.createHash('sha256').update(machineInfo).digest('hex');
}

/**
 * Encrypt Cookie data
 * @param {Object} cookie - Cookie object
 * @returns {string} Encrypted JSON string
 */
encrypt(cookie) {
  const password = this.getMachineId();
  const salt = this.generateSalt();
  const key = this.deriveKey(password, salt);

The resulting credential data is persisted at a predictable location:

js
this.storagePath = path.join(
  process.env.HOME || process.env.USERPROFILE,
  '.openclaw/115-cookie.json'
);

Technical Analysis

The encryption password is derived solely from the hostname, operating system platform, and processor architecture. These values are not cryptographic secrets and are commonly available to local users, process telemetry, container metadata, backups, system inventories, or anyone with contextual knowledge of the host.

Hashing predictable metadata does not add entropy. PBKDF2 and the random salt increase the cost of testing a candidate, but they do not prevent recovery when the exact input values are known or can be guessed from a small search space. AES-256-GCM is used correctly for authenticated encryption, but its security still depends on the secrecy of the key.

Attack Path

  1. An attacker obtains ~/.openclaw/115-cookie.json, for example through a backup leak, filesystem read access, archive exposure, or copied user profile.
  2. The attacker obtains or guesses the host's name, platform, and architecture.
  3. The attacker reproduces the SHA-256 value generated by getMachineId().
  4. The attacker reads the salt and I ...[truncated 624 chars]
Remediation
View remediation

Remediation Suggestions

  • Generate a cryptographically random encryption key instead of deriving it from host metadata.
  • Store the key in an operating-system credential facility such as Keychain, Credential Manager, Secret Service, or an appropriately configured secrets manager.
  • Alternatively, derive the key from a user-held passphrase with a memory-hard KDF such as Argon2id or scrypt, using a unique random salt.
  • Retain the existing 0600 file permission as defense in depth, but do not rely on it as the encryption secret.
  • Avoid returning the credential file path to untrusted callers unless operationally necessary.
  • Provide a secure key-rotation and cookie-revocation mechanism.
  • Migrate existing cookie files by decrypting them once under the old scheme and immediately re-encrypting them under a random protected key.
  • Clear persisted sessions and require reauthentication if migration integrity cannot be established.

T09 · Insecure Skill Coding Practices

Error
Location
lib/auth-puppeteer.js:26
Finding

Chromium Sandbox Disabled During Remote Login Page Processing

Content
View full analysis

Vulnerability Details

File Location: lib/auth-puppeteer.js:26-34
Vulnerability Type: Unsafe browser isolation configuration
Risk Level: High

js
this.browser = await puppeteer.launch({
  headless: 'new',
  args: [
    '--no-sandbox',
    '--disable-setuid-sandbox',
    '--disable-dev-shm-usage',
    '--disable-gpu'
  ]
});

The unsandboxed browser subsequently processes a remote page:

js
await this.page.goto('https://115.com/', {
  waitUntil: 'networkidle2',
  timeout: 30000
});

Technical Analysis

The --no-sandbox and --disable-setuid-sandbox flags disable Chromium's primary process-isolation boundary. Chromium renders complex, remotely supplied HTML, JavaScript, images, fonts, and other content that may exercise browser vulnerabilities.

A renderer exploit is normally constrained by browser sandboxing. With the sandbox disabled, successful exploitation has a substantially more direct path to the operating-system privileges of the Node.js process. HTTPS reduces content-tampering opportunities but does not protect against a compromised upstream site, malicious third-party resources, or an unknown browser vulnerability in legitimate content.

Attack Path

  1. The Puppeteer authentication implementation is invoked.
  2. Chromium starts without its sandbox and loads the remote 115 login page and associated resources.
  3. A compromised page, malicious third-party resource, or browser exploit targets the installed Chromium version.
  4. The exploit gains code execution in a browser process.
  5. Because the sandbox is disabled, the attacker can access host resources with the privileges of the Skill process rather than remaining confined to a restricted renderer environment.
  6. The attacker may read local data available to that account, including the persisted cookie file, or modify files and execute further actions permitted to the process.

Impact Assessment

T ...[truncated 341 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove --no-sandbox and --disable-setuid-sandbox.
  • Run Chromium as a dedicated, non-root operating-system user with the normal Chromium sandbox enabled.
  • If deployment constraints prevent use of the browser sandbox, isolate the browser in a hardened, disposable container or virtual machine with a read-only filesystem, no host mounts, minimal Linux capabilities, resource limits, and narrowly restricted network access.
  • Keep Puppeteer and its bundled Chromium version promptly patched.
  • Restrict navigation and subresource origins to the minimum required official domains.
  • Prefer the direct API-based QR authentication implementation when it can be operated with proper TLS validation and without a general-purpose browser.
  • Add a deployment check that refuses to start browser authentication as root or when sandbox support is unavailable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (65)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The HTTPS client is explicitly configured with rejectUnauthorized: false, which disables TLS certificate validation for requests involved in QR login and status polling. This allows man-in-the-middle interception or tampering with login responses and potentially theft or injection of authentication cookies, which is especially dangerous in an auth module handling session establishment.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The clearRecycleBin method invokes /files/clear_recycle, which appears to permanently empty deleted items. The function contains no confirmation prompt, visible warning, or explicit disclosure to the user before executing this irreversible cleanup operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The offline download description explains that magnet/HTTP tasks can be added, but it does not clearly disclose that submitted URLs or magnet links will be transmitted to the remote 115 service for processing. This omission can mislead users about where sensitive or identifying download targets are sent, creating privacy and consent risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrase "下载 xxx" is broad enough to match ordinary user requests that may not be intended to invoke this skill's offline-download behavior. In a storage-management skill that can create remote download tasks, ambiguous activation increases the risk of unintended network actions against the user's account or third-party content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The smart organization feature says it will automatically classify and organize files, but it does not prominently warn that files may be moved, renamed, or reclassified in bulk. In a cloud-storage context, insufficient warning about automated state-changing behavior raises the chance of accidental disruption, misplaced files, or loss of expected directory structure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrase "整理文件" is a common natural-language request and does not clearly signal that the skill may automatically reorganize cloud files. Because the documented behavior includes auto-classification and moving files, an overly generic trigger can cause unintended bulk file changes in the user's storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill immediately submits a magnet link to the offline download service as soon as a matching string is detected in the user's message. This causes a state-changing action with network and storage side effects without an explicit confirmation step, increasing the risk of accidental downloads, abusive triggering through ambiguous prompts, or downloading infringing/malicious content under the user's account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

When the message contains terms like “自动” or “智能”, the skill directly invokes automatic organization and moves files into a target folder. This is a destructive or at least state-altering file operation performed without a dry run, preview, or confirmation, which can lead to unintended file movement, workflow disruption, or difficult-to-reverse organization changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code saves login cookies obtained from a QR-based browser session to persistent storage via cookieStore.save(status.cookie) without any visible consent, disclosure, or safeguards in this file. Authentication cookies are bearer credentials, so unauthorized access to the storage layer or accidental reuse can let an attacker hijack the user's 115 session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

On successful login, the code saves authentication cookies via this.cookieStore.save(status.cookie), which is a sensitive write of credential material. Although the code has internal comments, there is no user-facing prompt, log, or explicit disclosure in this file that login cookies will be stored locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code persists long-lived authentication cookies (UID/CID/SE) to storage for 90 days, which creates a credential-at-rest risk if the host, logs, backups, or storage backend are compromised. In a chat-based QR login flow, this is especially sensitive because the user may not realize their session tokens are being retained and reused beyond the immediate login session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code reads sensitive cookie fields, especially SE, to generate request signatures and assemble authenticated Cookie headers. While this is functionally necessary for the client, the file lacks any warning or disclosure that credential-like values are being consumed and used for authenticated API operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code constructs a Cookie header from UID/CID/SE values and sends it over network requests via axios. Although the code comments describe request signing and error handling, there is no user-facing warning, confirmation, or explicit disclosure in this file that authentication data will be transmitted to a remote API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module stores raw userInput and assistantOutput in history records without any minimization, redaction, retention control, or consent mechanism. In a context/history component, these fields can easily contain secrets, personal data, prompts, tokens, or proprietary content, creating privacy and data-exposure risk if history is later viewed, exported, logged, or leaked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The export function enables bulk extraction of stored interaction history with no apparent guardrails, confirmation, sensitivity filtering, or warning. Because this manager stores raw interaction data, bulk export materially increases the blast radius of any misuse or accidental sharing of sensitive conversation contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language comments and user-facing error/recovery messages are entirely in Chinese, including imperative user instructions such as replying with specific Chinese phrases. The policy scope allows flagging language/locale constraints when the skill forces a specific language without offering a user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The batchDelete method issues a deletion request to /rb/delete, which is a destructive operation affecting user data. While the file has a brief doc comment naming the operation, this code path contains no confirmation prompt, visible user-facing disclosure, or warning about the irreversible impact before executing the delete.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code performs file-list enumeration and search operations against a user's cloud storage without any built-in disclosure, consent gate, or policy check in this module. In an agent/skill context, these APIs expose sensitive metadata such as filenames, directory structure, and recent activity, which can enable privacy violations or downstream exfiltration if higher layers call them silently.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The deleteFiles method performs a destructive remote delete operation by POSTing file IDs to /files/delete. Although the method has an internal doc comment, there is no confirmation prompt, logging/print disclosure, or stronger warning around the destructive action itself in this code path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The download function writes remote content directly to a caller-supplied savePath with no validation, sandboxing, or confirmation. If untrusted input can influence savePath, this can overwrite arbitrary files accessible to the process, causing data loss or unsafe file placement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file exposes destructive operations (deleteTask, batchDeleteTasks, and clearCompleted) that immediately delete tasks once called, with no built-in confirmation, dry-run mode, or safeguard against accidental invocation. In an agent skill context, where higher-level prompts or tool chains may trigger these methods based on ambiguous user input, this increases the risk of unintended data/task loss even if the code is not malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file contains natural-language comments, returned labels, and parameter documentation entirely in Chinese, including category names and size/time labels that appear intended for user-visible output. Because the skill does not offer language selection or explain that it is intentionally Chinese-only, it conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This method automatically creates folders and moves files unless dryRun is set, which changes user data organization in a nontrivial way. Although comments describe the behavior for developers, there is no user-facing confirmation, logging, or warning in this file before the write-like operations occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This routine creates directories and moves files into them automatically when dryRun is false, affecting user file layout. The code lacks any confirmation prompt, print/log message, or other user-facing disclosure in this file about these modifications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

All natural-language help text, shortcut keywords, and command descriptions in this file are hardcoded in Chinese, and the parser's documented natural-language interface appears to assume Chinese input. There is no indication of user opt-in, locale selection, or justification for enforcing a single language.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
lib/storage/cookie-store.js:58

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
lib/auth-web.js:25