Back to skill

Security audit

Health Report

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real health-reporting tool, but it handles sensitive health data with unsafe automation and outbound-sharing patterns that need review before installation.

Install only after reviewing or fixing the daily shell wrapper. Keep webhooks disabled unless needed, restrict them to trusted official provider URLs, protect config/.env and MEMORY_DIR permissions, and run any cron job under a dedicated non-root account. Expect personal health details and generated reports to leave the machine if webhook or public report URL settings are enabled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/daily_health_report_pro.sh:46
Finding

Arbitrary Python Code Execution Through Unquoted Heredoc Interpolation

Content
View full analysis
&1) echo "$result" >> "$LOG_FILE" # Extract the text report and PDF URL text_report=$(echo "$result" | sed -n '/=== TEXT_REPORT_START ===/,/=== TEXT_REPORT_END ===/p' | sed '1d;$d') pdf_url=$(echo "$result" | grep "=== PDF_URL ===" -A 1 | tail -1) if [ -z "$text_report" ] || [ -z "$pdf_url" ]; then echo "❌ 报告生成失败" >> "$LOG_FILE" exit 1 fi # Use Python to send to three channels python3 << PYTHON_SCRIPT import urllib.request import json import sys import os text_report = '''${text_report}''' pdf_url = '${pdf_url}' current_date = '${CURRENT_DATE}' ``` ### Technical Analysis The script captures report content derived from a local health-record Markdown file and directly interpolates that content into executable Python source inside an unquoted shell heredoc. The `text_report` variable is inserted between Python triple quotes without escaping Python delimiters, backslashes, or newline-sensitive syntax. An attacker-controlled value containing `'''` can close the intended string literal and append arbitrary Python statements. The resulting heredoc is then executed by `python3`. The report generator includes parsed food descriptions and other health-record-derived values in the generated text report. Therefore, an attacker who can influence the daily Markdown record can potentially propagate a malicious string into `text_report`. The `pdf_url` variable is similarly inserted into a single-quoted Python string without escaping, providing another possible injection surface if its source becomes attacker-controlled. ### Attack Path 1. An attacker gains the ability to modify or in ...[truncated 1708 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/daily_health_report_pro.sh:78
Finding

Unrestricted Webhook Destinations Permit SSRF and Recurring Health-Data Disclosure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (47)

Tainted flow: 'req' from os.environ.get (line 451, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/health_report_pro.py (reported line 452)May include surrounding context.

python
"max_results": max_results
            }).encode('utf-8')
            req = urllib.request.Request(url, data=data, headers={'Content-Type': 'application/json'})
            resp = urllib.request.urlopen(req, timeout=60)
            result = json.loads(resp.read().decode('utf-8'))
            return result.get('results', [])
        except Exception as e:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 361)May include surrounding context.

md
# 专业版每日健康报告脚本
# 功能:读取健康记录文件,生成综合评分报告并发送到多通道
# 执行频率:每天 22:00
# 配置:从 config/ 目录的 .env 文件读取

# 获取脚本所在目录(scripts/)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 314)May include surrounding context.

md
# 专业版每日健康报告脚本
# 功能:读取健康记录文件,生成综合评分报告并发送到多通道
# 执行频率:每天 22:00
# 配置:从 config/ 目录的 .env 文件读取

# 获取脚本所在目录(scripts/)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/daily_health_report_pro.sh (reported line 5)May include surrounding context.

sh
# 专业版每日健康报告脚本
# 功能:读取健康记录文件,生成综合评分报告并发送到多通道
# 执行频率:每天 22:00
# 配置:从 config/ 目录的 .env 文件读取

# 获取脚本所在目录(scripts/)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/daily_health_report_pro.sh (reported line 20)May include surrounding context.

sh
# 专业版每日健康报告脚本
# 功能:读取健康记录文件,生成综合评分报告并发送到多通道
# 执行频率:每天 22:00
# 配置:从 config/ 目录的 .env 文件读取

# 获取脚本所在目录(scripts/)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/daily_health_report_pro.sh (reported line 26)May include surrounding context.

sh
# 专业版每日健康报告脚本
# 功能:读取健康记录文件,生成综合评分报告并发送到多通道
# 执行频率:每天 22:00
# 配置:从 config/ 目录的 .env 文件读取

# 获取脚本所在目录(scripts/)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/health_report_pro.py (reported line 35)May include surrounding context.

python
# 专业版每日健康报告脚本
# 功能:读取健康记录文件,生成综合评分报告并发送到多通道
# 执行频率:每天 22:00
# 配置:从 config/ 目录的 .env 文件读取

# 获取脚本所在目录(scripts/)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_config.py (reported line 235)May include surrounding context.

python
# 专业版每日健康报告脚本
# 功能:读取健康记录文件,生成综合评分报告并发送到多通道
# 执行频率:每天 22:00
# 配置:从 config/ 目录的 .env 文件读取

# 获取脚本所在目录(scripts/)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_config.py (reported line 239)May include surrounding context.

python
# 专业版每日健康报告脚本
# 功能:读取健康记录文件,生成综合评分报告并发送到多通道
# 执行频率:每天 22:00
# 配置:从 config/ 目录的 .env 文件读取

# 获取脚本所在目录(scripts/)
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Using source on a .env file executes the file as shell code rather than parsing it as data. If an attacker can modify config/.env, they gain arbitrary code execution in the context of this script, which is especially risky because the default paths suggest a privileged/root-oriented environment and the script handles sensitive report data and outbound credentials.

Content

Scanner excerpt · scripts/daily_health_report_pro.sh (reported line 21)May include surrounding context.

sh
mkdir -p "${LOGS_DIR}"

# 加载环境变量(从 config/目录的 .env 文件)
if [ -f "${CONFIG_DIR}/.env" ]; then
    set -a
    source "${CONFIG_DIR}/.env"
    set +a

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/daily_health_report_pro.sh (reported line 23)May include surrounding context.

sh
# 加载环境变量(从 config/目录的 .env 文件)
if [ -f "${CONFIG_DIR}/.env" ]; then
    set -a
    source "${CONFIG_DIR}/.env"
    set +a
else
    echo "警告:未找到 .env 配置文件,使用默认值"

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

A health report generator should not need to invoke a separate agent binary with rich patient data to perform its core function. In this skill context, the capability expansion is especially dangerous because the transmitted content includes medical-condition and symptom information, increasing privacy and data-governance impact.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

Passing {**os.environ, ...} to the spawned agent exposes the entire parent process environment, potentially including API keys, webhook secrets, tokens, and deployment-specific credentials, to another executable. In combination with an agent binary that may load plugins or make network calls, this greatly increases the blast radius of any compromise or unintended behavior.

Content

Scanner excerpt · scripts/health_report_pro.py (reported line 386)May include surrounding context.

python
result = subprocess.run(
                ['openclaw', 'agent', '--local', '--to', '+860000000000', '--message', prompt],
                capture_output=True, text=True, timeout=90,
                env={**os.environ, 'SYSTEM_PROMPT': '你是一位专业的私人营养师,专门服务胆结石患者。'}
            )
            if result.returncode == 0 and result.stdout.strip():
                output = result.stdout.strip()

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

This second subprocess repeats the same full-environment inheritance problem while processing sensitive health-planning data. Any secret present in the runtime environment becomes available to the child process, creating unnecessary credential exposure for a feature that is not core to local report generation.

Content

Scanner excerpt · scripts/health_report_pro.py (reported line 535)May include surrounding context.

python
result = subprocess.run(
                ['openclaw', 'agent', '--local', '--to', '+860000000000', '--message', prompt],
                capture_output=True, text=True, timeout=90,
                env={**os.environ, 'SYSTEM_PROMPT': '你是一位专业的私人营养师。输出纯 JSON,不要其他文字。'}
            )
            if result.returncode == 0 and result.stdout.strip():
                output = result.stdout.strip()

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_config.py (reported line 240)May include surrounding context.

python
print("如果不需要推送,可以跳过此步骤。")
print()
print("编辑 .env 文件:")
print(f"  nano {CONFIG_DIR / '.env'}")
print()
print("=" * 60)
print("🎉 恭喜!配置全部完成!")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill description, setup flow, dialogue examples, configuration examples, and operational instructions are written to assume Chinese-language use, including fixed Chinese prompts such as the initialization questionnaire and bot interaction examples. There is no indication that users may choose another language or locale, which matches the policy category for language/locale constraints without opt-in.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The README instructs users to install a persistent cron job that automatically runs the reporting script every day. In this skill’s context, persistence increases risk because it repeatedly reads local health data and can automatically send reports to external services, so any misconfiguration or later compromise continues without fresh user action.

Content

Scanner excerpt · README.md (reported line 315)May include surrounding context.

bash
# 编辑 Crontab
crontab -e

# 添加每日 22:00 推送
0 22 * * * bash /root/.openclaw/workspace/skills/health_report/scripts/daily_health_report_pro.sh

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The README explicitly instructs users to configure webhook endpoints and demonstrates outbound POST requests to third-party services. In the context of this skill, that matters because the skill processes sensitive health records from MEMORY_DIR and then transmits generated reports externally, creating a real data-exfiltration path if the webhook target is misconfigured, compromised, or untrusted.

Content

Scanner excerpt · README.md (reported line 342)May include surrounding context.

bash
# 测试 Webhook
curl -X POST "https://oapi.dingtalk.com/robot/send?access_token=YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"msgtype":"text","text":{"content":"测试"}}'

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises only limited capabilities in metadata, but the content clearly describes broader behaviors including reading environment secrets, generating files/PDFs, making outbound webhook requests, and invoking installation/shell-related actions. This scope mismatch weakens least-privilege controls and can cause an agent platform or reviewer to underestimate what the skill can access or exfiltrate, especially given the health-data context and external push channels.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file title and operational examples indicate the skill interaction is defined in Chinese, and no opt-in or alternative language behavior is offered. Under the policy, forcing a specific language without user choice is a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation rules allow broad natural-language phrases such as 'I want to configure a health report' or partial personal disclosures to trigger configuration behavior without strong exclusion conditions or confirmation gates. In a conversational agent, this can cause unintended collection, persistence, or transmission of sensitive health information when the user did not mean to initiate the skill fully.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest advertises optional delivery of generated health reports through DingTalk, Feishu, and Telegram webhooks/bot tokens, which implies transmission of potentially sensitive health information to third-party services. There is no user-facing notice, consent language, data minimization statement, or retention/privacy guidance in the metadata, so users may unknowingly exfiltrate personal health data outside the local environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring is entirely in Chinese and describes the database in Chinese-only terms, which suggests a fixed language/locale assumption in the skill content. There is no nearby indication that users may choose another language or that the skill is intentionally limited to a China-specific audience for compliance or regional reasons.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends health-report content to DingTalk, Feishu, and Telegram webhooks, which is an external transmission of potentially sensitive personal health data. Even if this is intended functionality, there is no consent gate, minimization, destination allowlisting, or masking in this script, so misconfiguration or unauthorized webhook values could leak private data to third parties.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The Telegram API call transmits the generated report to an external service, which can expose sensitive health information outside the local system boundary. In the context of a health-reporting skill, this is more dangerous because the content likely contains personal or sensitive wellness data and the script does not enforce strong safeguards around destination trust or data classification.

Content

Scanner excerpt · scripts/daily_health_report_pro.sh (reported line 125)May include surrounding context.

sh
'text': message_text,
            'parse_mode': 'Markdown'
        }).encode('utf-8')
        req = urllib.request.Request(f'https://api.telegram.org/bot{TG_BOT_TOKEN}/sendMessage', data=data, headers={'Content-Type': 'application/json'})
        resp = urllib.request.urlopen(req, timeout=10)
        result = json.load(resp)
        return '✅' if result.get('ok') else '❌'

Static analysis

No suspicious patterns detected.