Back to skill

Security audit

Mzu 每日简报

Security checks for vulnerabilities and agentic risk

Overview

This news-briefing skill is mostly purpose-aligned, but it asks users to handle live Twitter/X session cookies and an API key in plaintext files without enough safety guidance.

Review this skill before installing. Use a dedicated or low-risk Twitter/X account if you choose the cookie-based backend, protect any credential files with owner-only permissions, avoid committing or syncing them, and rotate the cookies or API key if exposed. Prefer a scoped API key or safer auth flow where possible, and consider pinning dependency versions before following the install commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:118
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:118, README.md:126; duplicated in README_ZH.md:118,127 and SKILL.md:32,68
Vulnerability Type: Unpinned packages installed directly from public registries
Risk Level: Medium

Vulnerable Code

bash
pip install agent-reach
bash
npm install -g @steipete/bird

Technical Analysis

The installation instructions retrieve the latest available releases from public Python and npm registries without specifying reviewed versions, cryptographic hashes, lockfiles, or integrity metadata. Consequently, the code installed by a user can change after the Skill itself has been audited.

The npm dependency is installed globally, increasing the potential effect of a compromised package. npm installation can invoke package lifecycle scripts, while Python packages can execute build-related code during installation. A compromised publisher account, malicious future release, dependency takeover, or compromised transitive dependency could therefore result in arbitrary code execution during installation.

No evidence establishes that either named package is currently malicious. The vulnerability is the unsafe and non-reproducible dependency acquisition process.

Attack Path

  1. An attacker compromises a dependency publisher, package release process, or relevant transitive dependency.
  2. The attacker publishes a malicious release under the package name referenced by the documentation.
  3. A user follows the documented commands without selecting a reviewed version.
  4. The package manager resolves and downloads the attacker-controlled release.
  5. Malicious installation, build, or lifecycle code executes with the privileges of the user running the package manager.
  6. For the globally installed npm package, the malicious package may also place commands in globally accessible executable locations.

Impact Assessment

Successful exploitation could execut ...[truncated 422 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every direct dependency to a specifically reviewed version.
  • For Python, provide a locked requirements file with cryptographic hashes and require hash verification, for example through pip install --require-hashes.
  • For npm, provide a lockfile and use a reproducible installation mechanism such as npm ci.
  • Document the expected package publisher, version, and integrity digest.
  • Review and lock transitive dependencies rather than relying only on direct version constraints.
  • Avoid global npm installation where possible. Install the CLI in a dedicated project directory or isolated environment.
  • Disable package lifecycle scripts during installation when they are unnecessary, and review any scripts that must remain enabled.
  • Establish a dependency update process in which new versions are reviewed before documentation pins are changed.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:81
Finding

Sensitive Authentication Credentials Stored in Unprotected Plaintext Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:81-82,99,110,116; related instructions in README.md:129,139 and README_ZH.md:134-135,146-150,157
Vulnerability Type: Plaintext storage and loading of reusable session credentials and API keys
Risk Level: Medium

Vulnerable Code

bash
echo "AUTH_TOKEN=your_auth_token_value" > ~/.agent-reach-twitter.env
echo "CT0=your_ct0_value" >> ~/.agent-reach-twitter.env
bash
export $(cat ~/.agent-reach-twitter.env | xargs)
bash
echo "YOUR_GROK_API_KEY" > ~/.grok-api-key
bash
curl https://api.x.ai/v1/models \
  -H "Authorization: Bearer $(cat ~/.grok-api-key)"

The placeholders above correspond to the credential values users are instructed to place in the files.

Technical Analysis

The Skill directs users to save Twitter/X session credentials and a Grok API key in plaintext files under the user's home directory. It does not establish restrictive permissions before creating the files, apply chmod 600, require an owner-only umask, or use an operating-system credential store.

File permissions created by shell redirection depend on the user's current umask. In an environment with permissive defaults, other local accounts or processes may be able to read the credentials. Plaintext files may also be collected by home-directory backup, synchronization, indexing, diagnostic, or malware processes.

The Twitter values are reusable authenticated-session material rather than low-sensitivity configuration. Exposure may permit access to the associated Twitter/X session subject to the platform's controls. Exposure of the Grok API key may permit unauthorized API requests, quota consumption, and charges within the key's permissions.

The export $(cat ... | xargs) pattern additionally parses the credential file as shell-generated arguments. Although the documented file is user-created rather than remotely supplied, this i ...[truncated 1770 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer an operating-system credential manager or dedicated secret-management service instead of plaintext files.

  • If file storage is unavoidable, create the files with owner-only permissions:

    bash
    umask 077
    printf '%s\n' "AUTH_TOKEN=..." "CT0=..." > ~/.agent-reach-twitter.env
    chmod 600 ~/.agent-reach-twitter.env
    
    umask 077
    printf '%s\n' "..." > ~/.grok-api-key
    chmod 600 ~/.grok-api-key
    
  • Verify ownership and permissions before reading either credential file, and reject files writable by other users.

  • Avoid passing secrets as visible command-line arguments because process listings, shell history, or diagnostic tooling may expose them.

  • Replace export $(cat file | xargs) with a parser that validates an explicit allowlist of variable names and treats values as data rather than shell syntax.

  • Exclude credential files from backup, synchronization, indexing, and source-control systems.

  • Document immediate revocation and rotation procedures for both Twitter/X session values and Grok API keys.

  • Use narrowly scoped keys, quotas, expiration, and billing alerts where supported.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README states '中文为主' as a built-in behavior, and the workflow later repeats output in Chinese as the default. This imposes a language preference without indicating that users may choose another language, which conflicts with the policy against forcing a locale or language absent opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow step '输出(中文为主)' directs the skill to produce output primarily in Chinese. Because no opt-in or alternative language path is provided, this is a natural-language policy issue rather than a technical one.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to export and store Twitter/X session credentials (auth_token, ct0) and a Grok API key in local files without clear warnings about their sensitivity, scope, or secure storage practices. These secrets could be exposed through shell history, weak file permissions, backups, or accidental sharing, enabling account or API misuse.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 147)May include surrounding context.

bash
# 每天 08:00 早间简报
openclaw cron add "0 8 * * *" "请按 skills/mzu-news-briefing/SKILL.md 生成今日简报" --announce

# 每天 22:00 晚间简报
openclaw cron add "0 22 * * *" "请按 skills/mzu-news-briefing/SKILL.md 生成今日简报" --announce

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 150)May include surrounding context.

bash
# 每天 08:00 早间简报
openclaw cron add "0 8 * * *" "请按 skills/mzu-news-briefing/SKILL.md 生成今日简报" --announce

# 每天 22:00 晚间简报
openclaw cron add "0 22 * * *" "请按 skills/mzu-news-briefing/SKILL.md 生成今日简报" --announce

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README_ZH.md (reported line 165)May include surrounding context.

bash
# 每天 08:00 早间简报
openclaw cron add "0 8 * * *" "请按 skills/mzu-news-briefing/SKILL.md 生成今日简报" --announce

# 每天 22:00 晚间简报
openclaw cron add "0 22 * * *" "请按 skills/mzu-news-briefing/SKILL.md 生成今日简报" --announce

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README_ZH.md (reported line 168)May include surrounding context.

bash
# 每天 08:00 早间简报
openclaw cron add "0 8 * * *" "请按 skills/mzu-news-briefing/SKILL.md 生成今日简报" --announce

# 每天 22:00 晚间简报
openclaw cron add "0 22 * * *" "请按 skills/mzu-news-briefing/SKILL.md 生成今日简报" --announce

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to extract Twitter/X session cookies (auth_token and ct0) from the browser and store them in a local env file, but it does not warn that these values are highly sensitive session credentials equivalent to account access. If the file is exposed through weak permissions, backups, shell history, or accidental commits, an attacker could hijack the user's X account or abuse it through the configured tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions tell users to save a Grok API key directly into a local file without any warning about secret sensitivity, file permissions, or accidental disclosure risks. Exposed API keys can be abused for unauthorized API usage, quota exhaustion, billing impact, or access to associated account resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to extract live Twitter/X session cookies and store them in a local env file, but does not warn that these cookies are equivalent to account credentials and may grant account access if exposed. This increases the risk of credential theft, accidental leakage through shell history/files, or account abuse, especially because the workflow normalizes manual handling of sensitive session tokens.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

验证连接

bash
curl https://api.x.ai/v1/models \
  -H "Authorization: Bearer $(cat ~/.grok-api-key)"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The '输出语言' section specifies '中文为主' as the required output language, which imposes a language preference at the skill level. The policy allows locale or language constraints only when users are given a choice or the constraint is clearly justified as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill tells users to save a Grok API key into a plaintext file and use it directly in a shell command without guidance on securing the file or preventing accidental disclosure. While API keys are expected for this type of integration, missing handling guidance raises the chance of leakage via filesystem exposure, backups, shared machines, or command-history-related mistakes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

At L383 the workflow says the merged final briefing must contain 10-15 items, but at L499 the notes section says the total must be 15-20 items. This is an active contradiction in the skill's own instructions about what output it is supposed to produce, creating intent ambiguity for an agent following the document.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.