T09 · Insecure Skill Coding Practices
- Location
scripts/upload_to_moltbook.py:12- Finding
Hardcoded Moltbook API Bearer Token
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This security-scanner skill mostly matches its stated purpose, but it ships an under-disclosed authenticated Moltbook posting script with a hardcoded bearer token and makes stronger safety claims than its simple scanner supports.
Review this package before installing. The local scanner may be useful, but do not treat its A-F rating as proof of safety, avoid relying on the unpinned npx install path, and do not run the Moltbook publishing script unless the hardcoded token has been removed and replaced with your own explicitly scoped credential.
scripts/upload_to_moltbook.py:12Hardcoded Moltbook API Bearer Token
scripts/skillshield.py:184Bypassable Text-Matching Scanner Produces Misleading Security Trust Ratings
README.md:26Unpinned npx Installation Executes Mutable Third-Party Supply-Chain Code
The script sends an authenticated HTTP request using a bearer token sourced from the environment or, worse, a built-in fallback secret. While posting to Moltbook is intentional, this still creates a credential-handling and outbound-network risk because the skill is advertised as a security scanner, not as a publisher, and it transmits privileged credentials to an external service.
method='POST'
)
with urllib.request.urlopen(req, timeout=10) as response:
result = json.loads(response.read())
return result
except Exception as e:
A skill advertised as defensive but actually posting to an external API and using API credentials—including a hardcoded fallback key per the finding—is highly suspicious. Combining deceptive positioning with credentialed remote publishing creates a strong risk of covert exfiltration, unauthorized posting, or abuse of user trust under the guise of security tooling.
A skill advertised as defensive but actually posting to an external API and using API credentials—including a hardcoded fallback key per the finding—is highly suspicious. Combining deceptive positioning with credentialed remote publishing creates a strong risk of covert exfiltration, unauthorized posting, or abuse of user trust under the guise of security tooling.
A skill advertised as defensive but actually posting to an external API and using API credentials—including a hardcoded fallback key per the finding—is highly suspicious. Combining deceptive positioning with credentialed remote publishing creates a strong risk of covert exfiltration, unauthorized posting, or abuse of user trust under the guise of security tooling.
A skill advertised as defensive but actually posting to an external API and using API credentials—including a hardcoded fallback key per the finding—is highly suspicious. Combining deceptive positioning with credentialed remote publishing creates a strong risk of covert exfiltration, unauthorized posting, or abuse of user trust under the guise of security tooling.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Sensitive file patterns
SENSITIVE_FILES = [
(r'\.env', '读取 .env 文件', 'high'),
(r'\.bashrc', '读取 .bashrc', 'medium'),
(r'\.zshrc', '读取 .zshrc', 'medium'),
(r'\.ssh[/\\]', '访问 SSH 目录', 'critical'),
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Sensitive file patterns
SENSITIVE_FILES = [
(r'\.env', '读取 .env 文件', 'high'),
(r'\.bashrc', '读取 .bashrc', 'medium'),
(r'\.zshrc', '读取 .zshrc', 'medium'),
(r'\.ssh[/\\]', '访问 SSH 目录', 'critical'),
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
�幕截图', 'high'),
(r'webhook', 'Webhook 调用', 'low'),
(r'socket\.', '网络 socket 操作', 'medium'),
(r'ftplib|smtplib', 'FTP/SMTP 协议', 'medium'),
(r'tempfile\.(mkdtemp|mkstemp)', '创建临时文件', 'low'),
]
# Suspicious domains
SUSPICIOUS_DOMAINS = [
'webhook', 'pastebin', 'requestbin', 'hook',
'ngrok', 'burpcollaborator', 'interactsh'
]
def __init__(self, rules_dir: str = None):
self.rules_dir = rules_dir or os.path.join(os.path.dirname(__file__), '..', 'rules')
self.warnings = []
self.permissions = {
'files': {'read': set(), 'write': set(), 'delete': set()},
'network': {'urls': set(), 'domains': set()},
'system': {'commands': set(), 'imports': set()},
'data': {'env_vars': set(), 'credentials': set()}
}
self.file_hashes = {}
def scan(self, skill_path: str, deep_scan: boo
Authenticated posting to a third-party service is not justified by the stated role of a skill security scanner and expands the attack surface unnecessarily. Any capability to send bearer-authenticated external requests from a trusted scanning environment can be abused for spam, data leakage, or unauthorized account activity.
The code embeds a fallback API key directly in source, enabling anyone with code access to reuse the credential for unauthorized Moltbook actions. Hardcoded secrets are especially dangerous here because the script immediately uses the key for authenticated network operations, turning source disclosure into direct account compromise.
This function performs authenticated publication to an external social platform, which is unrelated to the stated purpose of analyzing skills for security. That mismatch is dangerous because users may grant trust and permissions appropriate for a scanner while the code actually performs external content distribution.
The main execution path is devoted to composing and posting promotional content rather than performing any security analysis. In a skill that claims to protect against malicious behavior, this purpose deviation materially increases risk because it suggests hidden or misleading functionality under a trusted label.
The primary description is written in Chinese only, which imposes a language choice on users without any opt-in or indication that the skill is region-specific. The policy for this audit flags language or locale constraints when the file does not offer a choice or clearly justify the limitation.
The README instructs users to execute npx skills add openclaw/skillshield without pinning a specific version. This makes installation depend on whatever package/version is current at execution time, increasing supply-chain risk if the package is updated maliciously, compromised, or unexpectedly changed. In a security-focused skill, this is more dangerous because users are likely to grant the tool elevated trust.
The skill metadata does not declare any tool scope or permissions even though the documented commands indicate capabilities involving environment access, file reads, network activity, and shell execution. Missing capability declarations weaken reviewability and consent, making it easier for a skill to obtain broader access than users expect.
Broad triggers such as generic security-scan phrases can cause the skill to activate during ordinary conversations, increasing the chance of unintended execution. In a skill that may read files, access env vars, use shell commands, or reach the network, accidental invocation materially increases exposure.
Most of the user-facing documentation is written in Chinese, while the file does not state that the skill is region-specific or provide an opt-in language selection. This creates a locale policy issue because the skill effectively imposes a language preference on users without notice or choice.
The module docstring states it will 'Automatically scan skills on Moltbook and post security reports'. In practice, the monitoring loop only identifies posts mentioning skill-related keywords and prints a suggestion to contact the author, while both scanning-by-URL and comment posting are unimplemented stubs.
The class docstring says it will 'Monitor Moltbook for new skills and scan them', and methods such as 'Download and scan a skill from URL' and 'Post a comment to a Moltbook post' are documented as real behaviors. However, the actual code leaves these operations as TODOs or placeholder output, which contradicts the stated intent of the documentation.
The generated security comment strings are entirely in Chinese, and the file does not indicate that this skill is intended only for a Chinese-speaking or region-specific audience. This can violate language/locale policy expectations because users are not given an opt-in or alternative language.
The monitoring output and command-line help strings include Chinese-only user-facing text, but the script does not offer a language selection mechanism or justify a Chinese-only deployment context. That creates a natural-language policy issue under the locale-choice requirement.
This Python file contains multiple user-facing print strings entirely in Chinese, including error messages and publishing instructions. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the tool is clearly documented as region-specific, which is not indicated here.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# Run self-scan
print("\n🔍 正在执行自检扫描...")
scan_result = subprocess.run(
[sys.executable, str(skill_dir / 'scripts' / 'skillshield.py'),
'scan', str(skill_dir)],
capture_output=True,
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
This Python file contains numerous hard-coded Chinese descriptions, warnings, summaries, CLI help strings, and status messages, making the skill effectively Chinese-only. The file does not offer any language selection, opt-in, or documentation that this is intentionally limited to a Chinese-speaking or region-specific audience.
No suspicious patterns detected.