Back to skill

Security audit

悟空邀请码监控

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent monitoring purpose, but its cron setup can overwrite or inject persistent scheduled tasks.

Review this skill before installing. Do not run its cron setup as root, back up your existing crontab first, and avoid the heartbeat crontab instructions unless they are changed to preserve existing jobs, validate intervals, use private state files, and remove only skill-owned entries.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
HEARTBEAT.md:17
Finding

Heartbeat setup replaces the user's entire crontab

Content
View full analysis
> /tmp/wukong-cron.txt << 'EOF' # Heartbeat check - check notifications every 5 minutes */5 * * * * python3 heartbeat-check.py >> /tmp/wukong-heartbeat.log 2>&1 EOF crontab /tmp/wukong-cron.txt ``` `HEARTBEAT.md:17-29`: ```bash cat > /tmp/wukong-cron.txt << 'EOF' # Wukong invite monitor - base check */5 * * * * cd ~/.openclaw/workspace/skills/wukong-invite-monitor/scripts && python3 monitor_lite.py check >> /tmp/wukong-monitor.log 2>&1 # Heartbeat notification check */5 * * * * cd ~/.openclaw/workspace/skills/wukong-invite-monitor/scripts && python3 heartbeat-check.py >> /tmp/wukong-heartbeat.log 2>&1 EOF # Apply configuration crontab /tmp/wukong-cron.txt ``` ### Technical Analysis The command `crontab FILE` replaces the current user's complete crontab with the contents of the supplied file. It does not append the new entries to existing scheduled tasks. The heartbeat guide creates a file containing only the Wukong tasks and then installs it as the complete crontab. The README uses append redirection, but it still installs the resulting temporary file as the entire crontab and does not first preserve the user's existing entries. Recurring scheduling is relevant to the declared monitoring function and is explicitly optional, so persistence itself is not considered malicious. However, replacing unrelated scheduled tasks exceeds the minimum configuration change required to install this Skill. ### Attack Path 1. A user already has unrelated cron jobs, such as backup, monitoring, certificate-renewal, or maintenance tasks. 2. The user follows the documented heartbeat setup instructions. 3. The instructions create `/tmp/wukong-cron.txt` containing the Wukong entries. 4. `crontab /tmp/wukong-cron.txt` replaces the user's comple ...[truncated 614 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup-cron.sh:2
Finding

Unvalidated cron interval permits persistent cron-entry injection

Content
View full analysis
> /tmp/wukong-monitor.log 2>&1" echo "添加:$CRON" (crontab -l 2>/dev/null | grep -v wukong; echo "# wukong"; echo "$CRON") | crontab - ``` ### Technical Analysis The first command-line argument is inserted directly into a generated crontab line without validating that it is a single integer in a safe range. Shell expansion of a variable does not execute shell metacharacters contained in its value at script-construction time, but embedded newline characters remain significant when the resulting text is installed as a crontab. A crafted argument can therefore terminate the intended schedule line and introduce one or more additional cron records. Those injected records execute persistently under the account that ran `setup-cron.sh`. The generated command also embeds `$(dirname $0)` without safely resolving and quoting the directory. Installation paths containing spaces or cron/shell metacharacters can break the command or alter its interpretation when cron later invokes a shell. Finally, `grep -v wukong` removes every existing crontab line containing the string `wukong`, not only entries owned by this Skill. This can delete unrelated user jobs. ### Attack Path 1. An attacker gains the ability to influence the argument supplied to `setup-cron.sh`, such as through an unsafe wrapper, automated installer, copied command, or another process invoking the script. 2. The attacker supplies a value containing a newline followed by a separate cron expression and command. 3. The value is interpolated into `CRON` without validation. 4. `echo "$CRON"` emits both the intended line and the attacker-supplied line. 5. The pipeline installs the g ...[truncated 798 chars]
Remediation
View remediation
&2 exit 1 ;; esac if [ "$INTERVAL" -lt 1 ] || [ "$INTERVAL" -gt 59 ]; then echo "Interval must be an integer from 1 to 59" >&2 exit 1 fi ``` - Explicitly reject newline and carriage-return characters in every value used to generate crontab content. - Resolve the script directory to an absolute path and quote it safely in the cron command. - Prefer invoking Python and the script through fixed absolute paths. - Use exact begin/end markers and replace only the Skill-owned block instead of filtering every line containing `wukong`. - Preserve the existing crontab and install updates atomically. - Run a syntax validation step before installing the generated crontab. - Document that the schedule is installed only for the current user and should not be installed as root. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check-new-code.py:11
Finding

Predictable shared temporary files permit symlink-based file overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims heartbeat push notification support, but the finding indicates there is no actual push or webhook implementation while the code performs external network access, downloads, and local state writes. This is security-significant because it conceals the real attack surface and operational behavior, especially when paired with undeclared permissions and automated execution via cron.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill claims heartbeat push notification support, but the finding indicates there is no actual push or webhook implementation while the code performs external network access, downloads, and local state writes. This is security-significant because it conceals the real attack surface and operational behavior, especially when paired with undeclared permissions and automated execution via cron.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill claims heartbeat push notification support, but the finding indicates there is no actual push or webhook implementation while the code performs external network access, downloads, and local state writes. This is security-significant because it conceals the real attack surface and operational behavior, especially when paired with undeclared permissions and automated execution via cron.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

bash
# Alibaba Cloud Linux / CentOS
sudo yum install -y tesseract tesseract-langpack-chi_sim

# Ubuntu / Debian
sudo apt install -y tesseract-ocr tesseract-ocr-chi-sim

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

md
sudo yum install -y tesseract tesseract-langpack-chi_sim

# Ubuntu / Debian
sudo apt install -y tesseract-ocr tesseract-ocr-chi-sim

# macOS
brew install tesseract tesseract-lang

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install-dependencies.sh (reported line 56)May include surrounding context.

sh
sudo yum install -y tesseract tesseract-langpack-chi_sim

# Ubuntu / Debian
sudo apt install -y tesseract-ocr tesseract-ocr-chi-sim

# macOS
brew install tesseract tesseract-lang

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install-dependencies.sh (reported line 59)May include surrounding context.

sh
sudo yum install -y tesseract tesseract-langpack-chi_sim

# Ubuntu / Debian
sudo apt install -y tesseract-ocr tesseract-ocr-chi-sim

# macOS
brew install tesseract tesseract-lang

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to create cron-based monitoring and notification tasks, including heartbeat push behavior, but does not clearly disclose that this creates persistent background execution and may send outbound notifications on an ongoing basis. In a skill context, undisclosed persistence and network egress reduce informed consent and can mask unexpected resource use or data transmission.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · HEARTBEAT.md (reported line 121)May include surrounding context.

Q: 如何停止监控?

bash
crontab -e  # 删除包含 wukong 的行

Q: 心跳推送如何工作?

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 118)May include surrounding context.

Q: 如何停止监控?

bash
crontab -e  # 删除包含 wukong 的行

Q: 心跳推送如何工作?

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill manifest does not declare any tool scope or permissions, yet the documented workflow clearly invokes shell scripts, Python programs, cron setup, local file access, and likely network operations. This creates a transparency and least-privilege problem: users or orchestration systems cannot accurately constrain what the skill may do, increasing the risk of unintended file modification, scheduled persistence, or outbound access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the visible user-facing sections of the skill documentation are entirely in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module documentation states '每 2 分钟检查一次日志文件', which describes a recurring monitor. However, the code only defines check_and_notify() and invokes it once under __main__ without any loop, scheduler, or sleep-based repetition. This is an active contradiction between the documented behavior and the implemented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s docstrings and visible output strings are entirely in Chinese, which imposes a specific language on users without offering opt-in or documenting that the skill is intended only for a Chinese-speaking context. This matches the language/locale policy violation category because the skill forces a locale-specific user experience through its natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module description and runtime behavior are oriented to Chinese by default, including the default OCR language chi_sim and Chinese-only CLI output. This can violate language/locale policy when the skill forces a specific language experience without user opt-in or an explicitly documented regional constraint.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/ocr_local.py (reported line 21)May include surrounding context.

python
def get_tesseract_version():
    """获取 Tesseract 版本"""
    try:
        result = subprocess.run(
            ['tesseract', '--version'],
            stdout=subprocess.PIPE,
            stderr=subprocess.PIPE,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/ocr_local.py (reported line 36)May include surrounding context.

python
def check_tesseract_langs():
    """检查已安装的语言包"""
    try:
        result = subprocess.run(
            ['tesseract', '--list-langs'],
            stdout=subprocess.PIPE,
            stderr=subprocess.PIPE,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/ocr_local.py (reported line 65)May include surrounding context.

python
try:
        output_base = image_path + '.ocr'
        
        result = subprocess.run(
            ['tesseract', image_path, output_base, '-l', lang, '--psm', '6'],
            stdout=subprocess.PIPE,
            stderr=subprocess.PIPE,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script prints status and completion messages in Chinese (for example on L3, L5, and L7), which imposes a specific language on users without any opt-in or indication that the skill is region-specific. This matches the policy category for language or locale violations in natural-language content embedded in code.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · HEARTBEAT.md (reported line 36)May include surrounding context.

md
echo "设置 cron 任务:每$INTERVAL 分钟检查"
CRON="*/$INTERVAL * * * * cd $(dirname $0) && python3 monitor_lite.py check >> /tmp/wukong-monitor.log 2>&1"
echo "添加:$CRON"
(crontab -l 2>/dev/null | grep -v wukong; echo "# wukong"; echo "$CRON") | crontab -
echo "✓ 完成"

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 6)May include surrounding context.

sh
echo "设置 cron 任务:每$INTERVAL 分钟检查"
CRON="*/$INTERVAL * * * * cd $(dirname $0) && python3 monitor_lite.py check >> /tmp/wukong-monitor.log 2>&1"
echo "添加:$CRON"
(crontab -l 2>/dev/null | grep -v wukong; echo "# wukong"; echo "$CRON") | crontab -
echo "✓ 完成"

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest says the monitor has 'zero token consumption', but this documentation explicitly states push notifications consume approximately 200 tokens per send and less than 2000 tokens per day. That is an active contradiction between documented intent/scope and the described behavior of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document is entirely written in Chinese, including headings and usage guidance, with no indication that the skill is region-specific or that alternative languages are available. This can violate language/locale policy when users are not given an explicit opt-in or choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation forces a specific language/locale for all user-facing instructions, which can violate language-choice policy when no opt-in or justification is provided. There is no indication that the locale restriction is required for compliance or that alternate language support is unavailable by design.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is entirely in Chinese, which imposes a specific language on users without indicating any locale restriction, user choice, or opt-in. Under the policy, language-only presentation can be a natural-language policy violation when no justified locale constraint is documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.