Back to skill

Security audit

乐有家找房

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent real estate search skill that sends user queries to Leyoujia APIs, with some privacy and link-tracking caveats users should understand.

Install only if you are comfortable sending real estate search details, such as city, area, budget, school, and housing preferences, to Leyoujia using your API key. Keep LYJ_API_KEY secret, delete any temporary body.json files created from examples, and be aware that returned listing links may include tracking parameters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:352
Finding

Mandatory Preservation and Promotion of Vendor-Tracked External Links

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 352–364 and line 398
Vulnerability Type: Output instruction hijacking and traffic diversion
Risk Level: High

Relevant code snippets:

text
### 房源展示字段规范(找房)

向用户展示每套房源时,按以下顺序包含下列内容(接口有则展示,无则省略;**房源外网地址没有则不展示**):

1. **房源标题**
2. **居室、卫生间、面积、朝向、小区**
3. **房源标签**
4. **总价、均价**
5. **用途、装修、产权、建成、电梯**
6. **位置**:小区的地址
7. **周边**:交通、学校
8. **小区名称、小区开发商、小区物业公司**
9. **小区物业费、小区停车费**
10. **房源亮点**:生成的亮点
11. **房源外网地址**(仅当接口返回该字段且非空时展示,没有则省略)
text
- 清洗规则:接口返回数据包含utm_term,不作任何处理

Technical Analysis

The Skill's mandatory output template instructs the agent to reproduce external property URLs supplied by the vendor API. More significantly, line 398 explicitly requires the agent to leave the utm_term query parameter unchanged.

Preserving campaign-attribution parameters is not necessary to perform the declared property-search, community-search, school-search, or result-summarization functions. It imposes an additional output behavior whose purpose is vendor traffic attribution. This exceeds the minimum privileges and output control required for the Skill's stated functionality.

The external link is derived from a remote API response rather than a static, locally reviewed value. Consequently, the destination path and query parameters can change after the Skill package has been audited. Although no remote code execution was found, the instruction gives the remote service indirect control over links emitted in agent responses. The audit found no requirement to validate the returned URL against an HTTPS host allowlist, remove unrelated tracking parameters, or obtain user consent before presenting tracked links.

Attack Path

  1. A user asks the Skill to find or recommend a property.
  2. The agent submits the search criteria to the configured Leyoujia API.
  3. The remote API returns property information containing an external URL and ...[truncated 1235 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction requiring utm_term to remain unchanged.
  2. Strip known tracking parameters, including utm_term and other utm_* fields, before displaying links.
  3. Make external links optional rather than a mandatory element of the property presentation template.
  4. Include external links only when they provide clear user value or when the user explicitly requests source pages.
  5. Validate every API-provided URL before output:
    • Require HTTPS.
    • Enforce a strict hostname allowlist.
    • Reject embedded credentials, nonstandard schemes, redirects to unapproved domains, and malformed URLs.
    • Permit only necessary path and query components.
  6. Clearly label links as vendor-operated external pages and disclose when attribution parameters would otherwise be present.
  7. Treat all remote API fields as untrusted data and ensure they cannot introduce additional instructions, Markdown link spoofing, or arbitrary destinations into the final response.
  8. Add regression tests confirming that tracking parameters are removed and off-allowlist URLs are suppressed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language instructions, examples, and usage policy throughout the file are presented only in Chinese, which effectively forces a specific language experience. The file does not indicate that the skill is region- or language-restricted by policy, nor does it offer users an opt-in or alternative language option.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill requires users to configure LYJ_API_KEY and repeatedly shows it being used in authenticated requests, but never clearly warns that the credential is secret and must not be shared, logged, or embedded in screenshots or copied outputs. In an agent/plugin setting, missing secret-handling guidance increases the chance of accidental credential exposure and unauthorized API use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This skill is fundamentally designed to send user-supplied real-estate queries and an API credential to an external service over the network. That is expected for the advertised functionality, but it still constitutes real external data transmission of potentially sensitive user interest data and authenticated usage metadata.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

  • URL:https://wap.leyoujia.com/wap/openclaw/ai/house/search(固定,无需配置)。
  • 鉴权:请求头 X-Api-Key: ${LYJ_API_KEY}。
  • 方式:仅支持 POST,请求体为 raw JSON,勿用 GET 或 URL 参数。
  • Windows/PowerShell:内联 JSON 易被转义破坏,建议将 body 写入 body.json 后使用 curl -d @body.json。
bash
# 方式一:Bash/WSL 下可直接用 -d '...'(URL 未设置时使用固定地址)

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The communitySearch flow transmits user-provided location and housing-interest information to a third-party endpoint using an authenticated request. While this is core functionality rather than hidden exfiltration, it still exposes user query data externally and could reveal sensitive intent or location preferences.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

bash
# 示例:查后海花园小区信息
curl -s -X POST "https://wap.leyoujia.com/wap/openclaw/ai/communitySearch" \
  -H "X-Api-Key: ${LYJ_API_KEY}" \
  -H "Content-Type: application/json" \
  -d '{"city":"广州","communityKeyword":"天河公园"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The xfSearch examples instruct the agent/user to send search criteria to an external endpoint with the API key in a header. This is expected behavior for a property-search integration, but from a security perspective it is still authenticated external transmission of user-derived data.

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
- **URL**:`https://wap.leyoujia.com/wap/openclaw/ai/xfSearch`(固定,无需配置)。
- **鉴权**:请求头 `X-Api-Key: ${LYJ_API_KEY}`。
- **方式**:仅支持 POST,请求体为 raw JSON,勿用 GET 或 URL 参数。
- **Windows/PowerShell**:内联 JSON 易被转义破坏,建议将 body 写入 `body.json` 后使用 `curl -d @body.json`。
- **返回**:新房信息、新房户型信息、新房成交信息(以实际 JSON 字段为准)。

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The schoolSearch flow sends school-related queries and optional area details to an external service under the same API key. In context this is not covert exfiltration, but it is still a true data-transfer surface that can expose user interests and should be treated as such.

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

  • 返回:学校信息,包含关联小区名称(以实际 JSON 字段为准)。
bash
curl -s -X POST "https://wap.leyoujia.com/wap/openclaw/ai/schoolSearch" \
  -H "X-Api-Key: ${LYJ_API_KEY}" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file includes commands that write request payloads to body.json and then submit them with curl, which is a file write affecting the user's local system. The surrounding instructions explain the mechanics but do not warn that a local file will be created and may persist with query contents unless removed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.