Back to skill

Security audit

ClawCall · AI 外呼、智能外呼与电话机器人

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it says, but it needs review because its authenticated API calls can follow redirects while carrying the phone-service API key.

Review this before installing if the API key has paid calling privileges or transcript access. Only use trusted Stepone endpoints, avoid custom API bases unless you control them, require per-call confirmation, and rotate the API key if you suspect authenticated requests were redirected unexpectedly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/stepone_client.py:176
Finding

API Key May Be Disclosed Through Cross-Origin HTTP Redirects

Content
View full analysis

Vulnerability Details

File Location: scripts/stepone_client.py, lines 176-181; related credential attachment at lines 164-165 and request construction at lines 197-200 and 382-389
Vulnerability Type: Cross-origin credential disclosure through unrestricted redirect handling
Risk Level: Medium

Vulnerable Code

python
def open_request(req: urllib.request.Request, timeout: float):
    scheme = urllib.parse.urlsplit(req.full_url).scheme
    if scheme not in {"https", "http"}:
        raise ClientError("request URL must use HTTP or HTTPS")
    # The URL scheme is allowlisted immediately above.
    return urllib.request.urlopen(req, timeout=timeout)  # nosec B310

Authentication is attached before this function is called:

python
if authenticated:
    headers["X-API-Key"] = api_key()

Technical Analysis

The client validates only the initial API URL. It then invokes urllib.request.urlopen, whose default opener automatically follows HTTP redirects. The destination of each redirect is not revalidated against the original scheme and origin.

Because X-API-Key is supplied as a normal request header, redirect processing may preserve it when constructing the redirected request. A redirect from the validated API endpoint to another origin can consequently disclose the Stepone AI API key. The same transport is used by ordinary authenticated API operations and transcript streaming.

The sensitive network transmission detected by the pre-scan is otherwise necessary for the declared telephone functionality: phone numbers, call instructions, call identifiers, and transcripts are sent to or retrieved from the documented Stepone AI API. The issue is that the credential can potentially travel beyond that intended endpoint.

Attack Path

  1. An authenticated command such as call, callinfo, balance, or stream is invoked.
  2. The client creates a request containing the user's `X-API-Key ...[truncated 1271 chars]
Remediation
View remediation

Remediation Suggestions

  • Disable automatic redirect handling for authenticated requests and reject redirect responses by default.
  • If redirects are operationally required, implement a custom HTTPRedirectHandler that validates every destination before following it.
  • Permit redirects only when the destination has the same normalized scheme, hostname, and effective port as the original API endpoint.
  • Reject HTTPS-to-HTTP downgrades under all production configurations.
  • Remove X-API-Key, Authorization, cookies, idempotency keys, and other sensitive headers before any cross-origin redirect.
  • Apply identical redirect controls to both standard JSON requests and SSE transcript streaming.
  • Add automated tests covering same-origin redirects, cross-origin redirects, HTTPS downgrades, and custom API-base configurations.
  • Rotate the API key if logs or runtime evidence indicate that an authenticated request previously followed an untrusted redirect.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on telephony and AI call-robot features. The actual code chunk merely launches another Python script in streaming mode and does not itself demonstrate any phone-related behavior or the stated communications features. While the missing Python file could theoretically implement them, based on the supplied code chunk alone, the observed behavior is a generic stream client launcher, which is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill can access environment secrets and perform network-backed actions, including placing real phone calls, but it does not declare an explicit tool/permission scope. That weakens least-privilege controls and makes it easier for an agent platform to invoke sensitive capabilities without clear policy gating or user-visible restrictions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad everyday requests like 'help me make a call' or 'call a merchant,' which can cause the skill to activate in many normal conversations. Because this skill can initiate real-world telephony actions with cost, privacy, and harassment implications, overbroad activation increases the risk of unintended or premature call workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage conditions mix broad user phrases with open-ended criteria such as '明确要求拨打中国大陆手机号码' and other flexible routing rules, which can create ambiguity about when the skill should take control. In a telephony skill, ambiguous activation is risky because it can lead to collecting numbers, preparing call content, or steering toward real-world contact when the user may have intended something else.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code embeds mandatory Chinese-language safety instructions and later emits Chinese-only user-facing status/output strings. The file does not offer a language/locale option or explain why Chinese-only output is required, which conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Several stream-mode messages such as parse errors, call completion, timeout notices, and speaker labels are displayed only in Chinese. Because the script does not let the user choose output language or document a justified locale restriction, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.