Back to skill

Security audit

Multi Platform Publisher Claw

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a publishing prototype that overstates real posting capability and can report fake publication success, so users should review it carefully before use.

Treat this as an unfinished prototype, not a real publisher. Do not rely on its success messages or mock links, do not provide production account credentials until real platform adapters and confirmation controls exist, and run it only in a private working directory if testing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
scripts/publish-content.py:55
Finding

Fabricated Publication Success and Mock Result URLs

Content
View full analysis

Vulnerability Details

File Location: scripts/publish-content.py, lines 55-65
Vulnerability Type: Deceptive success reporting
Risk Level: Medium

python
# Simulated publication result; replace with a real API call in production.
result = {
    "platform": platform,
    "status": "success",
    "url": f"https://{platform}.example.com/video/mock_id",
    "error": None,
    "schedule_time": schedule_time,
}
print(f"[{platform}] Publication successful: {result['url']}")
return result

Technical Analysis

The publication function unconditionally constructs a result with a success status and a mock example.com URL. It performs no platform API request, browser automation, upload, authentication, remote-response validation, or scheduling operation.

Consequently, any valid local invocation reports successful publication regardless of whether content reached a platform. The retry wrapper cannot detect this condition because the function always returns success without attempting an external operation. A supplied schedule is merely copied into the result and does not create or execute a scheduled job.

This behavior contradicts the documented workflow, which represents the script as publishing content and returning actual platform statuses and content links.

Attack Path

  1. A user or automated agent invokes the script with an existing video path and one or more supported platforms.
  2. The script accepts the input and calls publish_to_platform.
  3. No remote publication or scheduling operation occurs.
  4. The function unconditionally returns status: success and a mock URL.
  5. The retry wrapper accepts the fabricated success result immediately.
  6. The script presents the mock result in its publication summary and stores it in a local record.
  7. The user may rely on the false report and incorrectly conclude that the content was published or scheduled.

Impact Assessment

This i ...[truncated 416 chars]

Remediation
View remediation

Remediation Suggestions

  • Return an explicit failed or not_implemented result until genuine platform integrations are available.
  • Implement a separate authenticated adapter for each supported platform.
  • Treat publication as successful only after validating the platform's authoritative response, content identifier, and canonical URL.
  • Validate scheduling timestamps and submit them to an actual durable scheduling mechanism.
  • Distinguish success, pending, scheduled, failed, and not_implemented states.
  • Add integration tests that verify a success response cannot be produced without a confirmed remote operation.
  • Clearly label any development simulation mode and require an explicit flag to enable it.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/publish-content.py:140
Finding

Predictable Record File Creation Permits Symlink Overwrite and Metadata Exposure

Content
View full analysis

Vulnerability Details

File Location: scripts/publish-content.py, lines 140-148
Vulnerability Type: Insecure local file creation
Risk Level: Low

python
record = {
    "timestamp": datetime.now().isoformat(),
    "title": args.title,
    "video": args.video,
    "results": results,
}
record_path = f"publish-record-{datetime.now().strftime('%Y%m%d-%H%M%S')}.json"
with open(record_path, "w", encoding="utf-8") as f:
    json.dump(record, f, ensure_ascii=False, indent=2)
print(f"\nPublication record saved: {record_path}")

Technical Analysis

Publication records are written to the process's current working directory under a filename derived from the current time with one-second precision. The filename is predictable, and two executions in the same second can select the same destination.

The use of open(record_path, "w") follows symbolic links and truncates an existing destination. The code does not use exclusive creation, reject symbolic links, select a private storage directory, or explicitly enforce restrictive file permissions.

In an attacker-writable or shared working directory, a local attacker can predict the filename and create a symbolic link before the script opens it. If the process has permission to write to the linked destination, that file can be truncated and replaced with the JSON publication record. The resulting record may also expose titles, local video paths, timestamps, platforms, and result data according to the directory and process permission settings.

Attack Path

  1. A local attacker identifies that the script will run from a shared or attacker-writable directory.
  2. The attacker predicts the timestamp-based record filename for the expected execution second.
  3. The attacker creates a symbolic link with that filename pointing to another file writable by the victim process.
  4. The victim runs the publishing script.
  5. Python opens the predictable path in trunc ...[truncated 772 chars]
Remediation
View remediation

Remediation Suggestions

  • Store records in a dedicated application directory owned by the executing user and inaccessible to other users.
  • Create the directory with restrictive permissions such as 0700.
  • Create record files atomically with exclusive creation and permissions such as 0600.
  • On supported systems, use os.open with O_CREAT | O_EXCL | O_WRONLY | O_NOFOLLOW, then wrap the descriptor with os.fdopen.
  • Use a collision-resistant filename generated with a secure random value or UUID rather than second-resolution timestamps alone.
  • Refuse to write when the destination already exists or is a symbolic link.
  • Avoid executing the script with elevated privileges.
  • Minimize stored metadata and consider omitting or redacting absolute local video paths.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

该代码与“多平台内容发布”主题相关,确实包含平台选择、基础内容适配、批量处理、定时参数传递、重试和结果记录等支持性功能,因此不是完全无关。但声明描述的是一个较完整的自动分发与SEO优化专家,而实际代码只是一个未接入真实平台的命令行原型。它只做了非常基础的标题/描述长度裁剪和模拟发布,缺少声明中的关键核心能力:真实同步发布、SEO关键词优化、最佳时间计算、状态监控,以及图文支持。因此描述明显高于代码实际行为,属于实质性不匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad terms like '发布内容', 'SEO优化', and '跨平台', which can cause the skill to activate in contexts where the user did not intend automated distribution. Because this skill can lead to publishing content to external accounts, accidental activation could result in unauthorized posting, reputational harm, or leakage of sensitive content.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a publishing script that implies network access to external platforms and relies on local configuration such as a .env file, but it declares no explicit tool scope or permission boundaries. In an agent environment, missing capability restrictions increases the chance of unintended file access or external actions being performed without clear authorization or review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language instructions and invocation guidance are entirely in Chinese, which implicitly enforces a specific language without stating that this skill is Chinese-only or offering alternatives. Under the policy, locale or language constraints should be justified or presented as an opt-in choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill lacks a clear warning that it can perform automated actions against external social-media accounts and distribute content publicly. Without prominent disclosure and confirmation, users may not understand that invoking the skill could cause irreversible posting, account actions, or exposure of sensitive or unreviewed material.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill is written in simplified Chinese and targets Chinese platforms such as 抖音、小红书、B站, and 微博, with no indication that the language or locale is optional or intentionally restricted for a documented regional use case. Under the policy, a skill that effectively requires a specific language or locale without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring, usage examples, argument help text, and runtime messages are all written in Chinese, which effectively forces a specific language for users. The policy allows locale constraints only when the tool offers opt-in or clearly documents a justified region-specific limitation, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all guidance in Chinese and does not indicate that the skill is intentionally limited to Chinese-speaking users or provide any user opt-in for language/locale. Under the stated policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains natural-language guidance only in Chinese and does not indicate that users may choose another language or locale. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy concern unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.