Back to skill

Security audit

QWeather China

Security checks for vulnerabilities and agentic risk

Overview

This weather skill is mostly purpose-aligned, but it needs review because it handles signing keys and has configuration paths and network-host handling that could expose credentials if misconfigured.

Review or patch this skill before installing in a sensitive environment. Use a dedicated QWeather private key only, remove the stale .openclaw key path from openclaw_config.yaml, validate QWEATHER_API_HOST against approved qweatherapi.com hosts before sending JWTs, avoid printing credential-related environment values in errors, and install dependencies from a pinned lock file or isolated virtual environment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
qweather.py:67
Finding

Unrestricted API Host Can Receive Signed Bearer Tokens

Content
View full analysis
Dict: """发送API请求""" # 生成JWT token token = self._generate_jwt() # 构建URL url = f"https://{self.api_host}{endpoint}" # 设置headers headers = { "Authorization": f"Bearer {token}" } # 发送请求 response = self.session.get(url, headers=headers, params=params, timeout=10) response.raise_for_status() return response.json() ``` ### Technical Analysis The `QWEATHER_API_HOST` environment variable is used directly to construct the destination URL. The application does not verify that the resolved hostname is an approved QWeather domain. Every request generates a JWT signed with the configured private key and sends it in the `Authorization` header. An attacker who can modify the process environment or otherwise control the configuration can set `QWEATHER_API_HOST` to an attacker-controlled HTTPS host. The application would then send a valid, signed bearer token to that host. This runtime behavior does not enforce the `*.qweatherapi.com` endpoint restriction declared in the Skill metadata. Prefix-based or substring-based validation would not be sufficient because domains such as `qweatherapi.com.attacker.example` could bypass weak checks. Redirect handling is a ...[truncated 1289 chars]
Remediation
View remediation
str: if not host or any(char in host for char in "/:@?#"): raise ValueError("Invalid QWeather API host") normalized = host.rstrip(".").lower() approved_suffix = ".qweatherapi.com" if not normalized.endswith(approved_suffix): raise ValueError("API host must be a qweatherapi.com subdomain") return normalized ``` 4. Reject URL schemes, embedded credentials, ports unless explicitly required, IP literals, control characters, and path components in the host setting. 5. Disable redirects for credential-bearing requests: ```python response = self.session.get( url, headers=headers, params=params, timeout=10, allow_redirects=False, ) ``` 6. If redirects are operationally required, validate every redirect destination before forwarding the authorization header. 7. Prefer a fixed endpoint or a deployment-level allowlist instead of allowing arbitrary environment-controlled destinations. 8. Add tests covering malicious domains, including `qweatherapi.com.attacker.example`, `attacker-qweatherapi.com`, IP addresses, and credential-bearing URLs. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
openclaw_config.yaml:27
Finding

Stale Configuration References an OpenClaw Agent Private Key

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
install.sh:47
Finding

Runtime Installation Uses Unpinned Dependencies and Malformed Shell Constraints

Content
View full analysis
=2.0.0, cryptography>=3.0, requests>=2.25" pip3 install pyjwt>=2.0.0 cryptography>=3.0 requests>=2.25 --quiet ``` The same unsafe installation form also appears in the Skill manifest: ```yaml steps: - name: "Install Python dependencies" description: "安装必要的Python包" command: "pip3 install pyjwt>=2.0.0 cryptography>=3.0 requests>=2.25" ``` ### Technical Analysis The installation process resolves mutable packages from the active pip package index without exact version pins or cryptographic hashes. Consequently, package code installed in the future may differ from what was reviewed during this audit. In `install.sh`, the requirement expressions are not quoted. In a shell, the `>` characters are redirection operators rather than ordinary argument characters. The command may therefore be parsed as installation of unversioned package names while creating or truncating files such as `=2.0.0`, `=3.0`, and `=2.25`. The intended minimum-version restrictions are not reliably passed to pip. Even if the requirement expressions were quoted, lower-bound-only constraints would still permit arbitrary future versions. Package installation can execute package build logic with the privileges of the user running the installer. ### Attack Path 1. A user or automated Skill installer executes `install.sh`. 2. The shell interprets the unquoted `>` characters as output redirections. 3. Pip receives package names without the intended constraints and resolves current releases from its configured package index. 4. Pip downloads and installs package artifacts that were not pinned to the versions reviewed with the Skill. 5. Maliciously modif ...[truncated 969 chars]
Remediation
View remediation
\ --hash=sha256: cryptography== \ --hash=sha256: requests== \ --hash=sha256: ``` 2. Install dependencies using hash verification: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. If inline constraints must temporarily remain, quote every requirement so the shell does not interpret `>`: ```bash python3 -m pip install \ 'pyjwt>=2.0.0' \ 'cryptography>=3.0' \ 'requests>=2.25' ``` 4. Exact pins should still replace lower-bound-only constraints for production installation. 5. Install into a dedicated virtual environment rather than modifying the global Python environment. 6. Configure an explicitly trusted package index and disable unexpected additional indexes to reduce dependency-confusion exposure. 7. Keep the dependency installation command in one reviewed script or lock file instead of duplicating it in `install.sh` and `skill.yaml`. 8. Run automated vulnerability and provenance checks against every locked dependency update. 9. Avoid suppressing pip output with `--quiet` during security-sensitive installation, or preserve detailed installation logs for review. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (102)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

One aspect of this finding is security-relevant: the documentation instructs returning explicit configuration troubleshooting details for authentication failures, and the static note suggests environment-variable values may be echoed. Reflecting secret-bearing configuration values or precise auth material paths during errors can leak sensitive information to users, logs, or other tools.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 46)May include surrounding context.

  1. 配置私钥文件:
    bash
    # 创建配置目录
    mkdir -p ~/.config/qweather
    
    # 复制私钥到独立位置(推荐)
    cp /path/to/your/qweather-private.pem ~/.config/qweather/private.pem
    

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 46)May include surrounding context.

  1. 配置私钥文件:
    bash
    # 创建配置目录
    mkdir -p ~/.config/qweather
    
    # 复制私钥到独立位置(推荐)
    cp /path/to/your/qweather-private.pem ~/.config/qweather/private.pem
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 50)May include surrounding context.

复制私钥到独立位置(推荐)

cp /path/to/your/qweather-private.pem ~/.config/qweather/private.pem chmod 600 ~/.config/qweather/private.pem

text
4. 测试安装:
```bash

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

复制私钥到独立位置(推荐)

cp /path/to/your/qweather-private.pem ~/.config/qweather/private.pem chmod 600 ~/.config/qweather/private.pem

text
4. 测试安装:
```bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The release notes explicitly advertise reading the user's remembered city from MEMORY.md and using it automatically, but do not mention user consent, visibility, retention, or how location memory is managed. Location data is sensitive personal data, and silently consuming remembered location can create a privacy issue or unintended disclosure, especially in a conversational agent context where users may not expect persistent memory to influence responses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The release notes explicitly describe '中文语法优化' and the examples and behavior are presented as Chinese-only, with no indication that users can choose another language or locale. That can constitute a language/locale policy issue when the skill appears to force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description states the skill is ‘专为中国用户优化’ and later emphasizes ‘中文天气描述,符合中国用户习惯,’ which indicates a fixed locale/language behavior. The file does not mention any user opt-in or alternative language option, so this appears to impose a specific language/locale by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.