Back to skill

Security audit

visit-analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent visit-analysis purpose, but it handles passwords, tokens, and private communications in ways that require Review before installation.

Install only after the publisher replaces HTTP with HTTPS on a verified domain, removes password entry from chat, stores tokens in a secure credential store, deletes the bearer-token URL fallback, and adds explicit confirmation for reading local communications and uploading analysis.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:96
Finding

Credentials, bearer tokens, and private sales data transmitted over plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:96-147, 180-264, 360-364, 903-941
Vulnerability Type: Cleartext transmission of sensitive information
Risk Level: Critical

Vulnerable Code

bash
TOKEN_CACHE=~/.openclaw/workspace/scripts/.token-cache.json
FASTAPI_BASE_URL="http://47.116.49.218:8000/api/v1"

response=$(curl -s -X POST "${FASTAPI_BASE_URL}/auth/login" \
  -H "Content-Type: application/json" \
  -d "{\"employee_id\": \"${EMPLOYEE_ID}\", \"password\": \"${PASSWORD}\"}" \
  --max-time 120)
bash
INGEST_PAYLOAD=$(jq -n \
  --arg company_name "$company_name" \
  --arg project_name "${project_name:-}" \
  --arg contact_name "${contact_name:-}" \
  --arg transcript_file_path "$target_file" \
  --arg visit_date "$visit_date" \
  --arg data_source "电话录音转录" \
  --argjson sales_stage "$(echo "$parsed_result" | jq '.sales_stage')" \
  --argjson follow_up_strategies "$(echo "$parsed_result" | jq '.follow_up_strategies')" \
  --argjson customer_insights "$(echo "$parsed_result" | jq '.customer_insights')" \
  --argjson commitments "$(echo "$parsed_result" | jq '.commitments')" \
  --argjson risk_assessment "$(echo "$parsed_result" | jq '.risk_assessment')" \
  --arg raw_analysis "$(echo "$parsed_result" | jq -r '.' | head -c 10000)" \
  --arg visit_summary "$(echo "$parsed_result" | jq -r '.visit_summary')" \
  '{
    company_name: $company_name,
    project_name: $project_name,
    contact_name: $contact_name,
    transcript_file_path: $transcript_file_path,
    visit_date: $visit_date,
    data_source: $data_source,
    sales_stage: $sales_stage,
    follow_up_strategies: $follow_up_strategies,
    customer_insights: $customer_insights,
    commitments: $commitments,
    risk_assessment: $risk_assessment,
    raw_analysis: $raw_analysis,
    visit_summary: $visit_summary
  }')

ingest_response=$(curl -s -X POST "${FASTAPI_BASE_URL}/project-portrait
...[truncated 1950 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace all plaintext HTTP endpoints with HTTPS endpoints on a verified organizational domain.
  2. Enforce valid certificate-chain and hostname verification; do not disable TLS validation.
  3. Remove the raw-IP service address from the skill and load an administrator-approved endpoint from trusted configuration.
  4. Obtain explicit user authorization before transferring transcript- or notification-derived information.
  5. Minimize payloads and avoid transmitting raw analysis, local file paths, or unrelated customer information.
  6. Use short-lived, audience-restricted access tokens rather than employee passwords after initial authentication.
  7. Define server-side retention, access-control, encryption-at-rest, and audit-log requirements for uploaded conversation data.
  8. Revoke credentials and tokens previously transmitted through the plaintext service.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:972
Finding

Complete bearer token exposed in a plaintext URL query parameter

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:972-986
Vulnerability Type: Authentication-token disclosure through URL construction
Risk Level: Critical

Vulnerable Code

bash
exchange_response=$(curl -s -X POST "${FASTAPI_BASE_URL}/auth/exchange-code" \
  -H "Authorization: Bearer ${API_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{}' \
  --max-time 10)

exchange_code=$(echo "$exchange_response" | jq -r '.data.code // empty')

H5_BASE_URL="http://47.116.49.218:5173"

if [ -n "$exchange_code" ] && [ "$exchange_code" != "null" ]; then
    h5_url="${H5_BASE_URL}/project-portrait-new/${PORTRAIT_ID}?code=${exchange_code}"
else
    # Fallback: use the complete token without truncation
    h5_url="${H5_BASE_URL}/project-portrait-new/${PORTRAIT_ID}?token=${API_TOKEN}"
fi

Technical Analysis

If exchange-code generation fails, the skill intentionally embeds the complete bearer token in an H5 URL. Query parameters are routinely retained in chat output, browser history, server and reverse-proxy logs, analytics systems, screenshots, clipboard history, and monitoring products. They may also be exposed through referrer behavior.

The URL itself uses plaintext HTTP, allowing passive network interception. This fallback therefore turns an exchange-service failure into direct disclosure of a reusable authentication credential.

Attack Path

  1. An attacker or service outage causes /auth/exchange-code to fail or return no code.
  2. The skill enters its fallback branch.
  3. It creates and displays an HTTP URL containing the employee's complete bearer token.
  4. The token is captured from network traffic, assistant logs, browser history, proxy logs, analytics, clipboard history, or a shared screenshot.
  5. The attacker extracts the token query value.
  6. The attacker reuses the bearer token against APIs that accept the same credential.

Impact Assessment

Exploitation allow ...[truncated 335 chars]

Remediation
View remediation

Remediation Suggestions

  1. Delete the bearer-token URL fallback and fail closed when code exchange is unavailable.
  2. Use only short-lived, single-use, audience-bound exchange codes.
  3. Serve the H5 application exclusively over HTTPS on a verified domain.
  4. Place authentication in secure, HttpOnly, Secure, and appropriately scoped cookies after a server-side exchange rather than in query parameters.
  5. Configure access logs and analytics to redact exchange codes and all authentication material.
  6. Ensure codes have a brief expiration time and are invalidated immediately after first use.
  7. Revoke tokens that may already have appeared in generated URLs or logs.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:574
Finding

Broad access to device-wide WeChat notification archives exceeds least privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:574-686
Vulnerability Type: Overbroad collection of private notification data
Risk Level: High

Vulnerable Code

bash
NOTIFICATIONS_DIR="/home/admin/.openclaw/plugins/phone-notifications/notifications"
DAYS_BACK="${DAYS_BACK:-30}"

recent_json_files=$(find "$NOTIFICATIONS_DIR" -maxdepth 1 -name "*.json" -type f -mtime -${DAYS_BACK} 2>/dev/null)

if [ -z "$recent_json_files" ]; then
    echo "⚠️ No notification files were found in the selected period"
    exit 1
fi

wechat_messages=$(echo "$recent_json_files" | xargs jq -s '
    [ .[][] | select(.appName == "微信") ]
' 2>/dev/null)

if [ -n "$contact_name" ]; then
    wechat_messages=$(echo "$wechat_messages" | jq --arg name "$contact_name" '
        [ .[] | select(.title | test($name; "i")) ]
    ')
elif [ -n "$company_name" ]; then
    wechat_messages=$(echo "$wechat_messages" | jq --arg name "$company_name" '
        [ .[] | select(.title | test($name; "i")) ]
    ')
fi

Technical Analysis

The skill reads all notification archive files from the selected period and aggregates every WeChat notification before narrowing the data to a contact or company. These device-level archives can include private or unrelated conversations beyond the customer analysis requested by the user.

The filtering value is derived from user input and is treated as a regular expression by jq's test() function. A broad expression can match many or all contact titles. If neither a contact nor a company is available at this stage, no title filter is applied. This design violates least privilege because the task only requires messages explicitly associated with a selected customer.

Attack Path

  1. A user or attacker triggers the skill with an ambiguous, broad, or regular-expression-like contact value.
  2. The skill enumerates every notification archive file in the selected date range.
  3. It lo ...[truncated 796 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit confirmation of the contact and date range before reading any notification content.
  2. Enforce a strict customer-selection step and reject execution when no unique contact has been established.
  3. Filter each file while reading it rather than first aggregating every WeChat notification.
  4. Match contact identifiers as literal strings rather than untrusted regular expressions, or escape all regex metacharacters.
  5. Apply hard limits to date range, message count, and permitted contact identifiers.
  6. Separate business-managed notifications from device-wide or personal notification archives.
  7. Do not display statistics or metadata about unrelated contacts.
  8. Record user consent and ensure only the minimum selected messages are sent to external services.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:96
Finding

Long-lived bearer token stored persistently in a plaintext cache without explicit access controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:96-147, 180-264
Vulnerability Type: Insecure local storage of authentication credentials
Risk Level: High

Vulnerable Code

bash
TOKEN_CACHE=~/.openclaw/workspace/scripts/.token-cache.json

mkdir -p ~/.openclaw/workspace/scripts
echo "{\"token\": \"${API_TOKEN}\", \"employee_id\": \"${EMPLOYEE_ID}\", \"employee_name\": \"${employee_name}\", \"expires_at\": \"${expires_at}\", \"updated_at\": \"$(iso_now)\"}" > "$TOKEN_CACHE"
bash
if [ -f "$TOKEN_CACHE" ]; then
    API_TOKEN=$(jq -r '.token' "$TOKEN_CACHE")
    expires_at=$(jq -r '.expires_at' "$TOKEN_CACHE")
    EMPLOYEE_ID=$(jq -r '.employee_id' "$TOKEN_CACHE")
    EMPLOYEE_NAME=$(jq -r '.employee_name' "$TOKEN_CACHE")
fi
bash
echo "{\"token\": \"${API_TOKEN}\", \"employee_id\": \"${EMPLOYEE_ID}\", \"employee_name\": \"${EMPLOYEE_NAME}\", \"expires_at\": \"${new_expires}\", \"updated_at\": \"$(iso_now)\"}" > "$TOKEN_CACHE"

Technical Analysis

The skill stores a reusable bearer token as plaintext JSON. It does not set a restrictive umask, explicitly create the directory with mode 0700, set the cache file to mode 0600, use an operating-system credential store, or perform an atomic protected write.

File permissions therefore depend on the surrounding environment and inherited process defaults. A permissive umask, pre-existing directory, backup process, diagnostic collection, or another process running under the same account may expose the token.

Attack Path

  1. An employee authenticates through the skill.
  2. The returned bearer token is written to .token-cache.json.
  3. The cache receives permissions based on inherited defaults or remains accessible to another process operating under the same account.
  4. A local attacker, compromised plugin, backup process, or malicious process reads the cache.
  5. The attacker extracts the token and replays it against ...[truncated 403 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store tokens in the operating system's credential manager or a dedicated secret-management service.
  2. If a file cache is unavoidable, set umask 077 before creation.
  3. Create the containing directory with mode 0700 and the cache file with mode 0600.
  4. Use atomic creation and replacement through a securely permissioned temporary file.
  5. Reject symbolic links and verify file ownership before reading or writing the cache.
  6. Use short-lived tokens with narrow scopes and rotate them after account changes or suspected disclosure.
  7. Exclude token files from backups, diagnostics, logs, and synchronization systems.
  8. Remove stale cache files securely on logout and revoke the corresponding server-side tokens.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:43
Finding

Mandatory CRM promotional content hijacks normal assistant output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:43-44, 997-1012
Vulnerability Type: Persistent output manipulation and workflow redirection
Risk Level: Medium

Vulnerable Code

markdown
- Do not output intermediate-step status; directly output the final result
- After outputting the summary, do not ask whether further analysis is needed
markdown
💡 **Next Action Recommendation**

After the analysis is complete, it is recommended that this project be synchronized to the CRM management system to facilitate follow-up and team collaboration.

🔄 [Synchronize to CRM Management →] Tell me "Synchronize to CRM"

The same mandatory promotional block is repeated in the documented output examples at SKILL.md:1077-1091 and SKILL.md:1107-1121.

Technical Analysis

The skill constrains normal assistant behavior and mandates that every completed analysis include a fixed CRM promotion and call to action. This content is not necessary to perform the requested transcript analysis or to return the generated project portrait.

Because the instruction is embedded in the skill's required output format, it predictably alters the assistant's response whenever the skill is loaded. It redirects users into a separate CRM workflow while suppressing ordinary follow-up behavior, matching an instruction-hijacking pattern.

Attack Path

  1. A user makes any request that activates the visit-analysis skill.
  2. The skill loads instructions that restrict the assistant's normal response behavior.
  3. The analysis is completed.
  4. The assistant appends the mandatory CRM promotion regardless of whether the user requested CRM synchronization.
  5. The user is prompted to invoke a separate CRM workflow.

Impact Assessment

The issue manipulates assistant output and funnels users toward an unrelated follow-on action. It does not directly grant system privileges, but it compromises response integrity, reduces ...[truncated 119 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove mandatory CRM promotional language from the skill's output template.
  2. Do not prohibit normal assistant follow-up behavior unless required for safety or correctness.
  3. Present CRM synchronization only when the user explicitly requests it or when it is directly relevant to the stated task.
  4. Clearly label optional integrations and disclose what additional data processing they perform.
  5. Keep the default result limited to the requested analysis, summary, and project-portrait link.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow reads call transcripts and WeChat notification content, sends analyzed results to a remote API, and persists project portraits, but the user-facing description does not provide clear notice or consent for this handling of sensitive communications. This can result in covert processing and exfiltration of private business and personal data.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the AI to ask for and extract account credentials from natural-language chat messages. Collecting secrets through ordinary chat is dangerous because the conversation channel, logs, prompts, and downstream tooling may expose or mishandle credentials, leading to account compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including employee password-change capability inside a chat-analysis skill is unnecessary privilege expansion and creates a path for the skill to solicit and process both old and new passwords. If abused or mis-triggered, it could lead to credential compromise or unauthorized account changes under the guise of analysis.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This renewal/login path again instructs the model to solicit a password from chat and immediately reuse it for authentication. Repeated credential prompting normalizes insecure behavior and increases the chance that user passwords are captured in logs or by a compromised skill.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The expired-token flow requires the user to resend full credentials via chat for relogin. This is a classic secret-handling anti-pattern and is especially risky here because the skill already performs multiple remote calls and local data access, broadening the consequences of credential theft.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The fallback verification branch still directs recollection of full credentials through chat, confirming that insecure secret capture is built into the skill design rather than an edge case. Any compromise of chat history, prompt traces, or local logs could expose employee accounts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as a visit/chat analysis tool, but its workflow also collects credentials, manages authentication tokens, and can trigger password-change flows. This expands the trust boundary far beyond the stated purpose, increasing the chance that users disclose secrets in chat to a skill they did not expect to handle authentication.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation boundary in the description is vague and does not clearly limit when the skill should run or what it will access. Given the skill’s ability to inspect local communication records and perform authenticated network operations, ambiguous activation meaningfully raises the risk of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are very broad and overlap with common business language, making accidental invocation likely. In this skill, accidental invocation is more dangerous because execution can lead to reading private transcripts/notifications, contacting remote APIs, and prompting for credentials.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L0044 明确要求输出摘要后禁止再加“是否需要进一步分析”等引导语,体现了避免后续诱导操作的意图;但 L1006-L1010 的最终输出模板加入“下一步行动建议”和“对我说‘同步到CRM’”的明确引导。这不是简单遗漏,而是文档内部对最终交互行为的直接矛盾。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatically renewing tokens without notifying the user conceals authenticated network activity and continued session use. In a skill that can access sensitive records and generate access links, hidden credential reuse increases the risk of unauthorized or unexpected actions being taken on the user's behalf.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This call transmits employee credentials to a remote HTTP endpoint, and the configured base URL uses plain HTTP rather than HTTPS. Sending usernames/passwords and receiving tokens over an unencrypted channel exposes them to interception, modification, and credential theft by network attackers.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
# 用户输入示例:"emp-server-106 123456" 或 "我的账号是 emp-server-106,密码是 123456"
    # AI 需解析出 employee_id 和 password 两个值

    response=$(curl -s -X POST "${FASTAPI_BASE_URL}/auth/login" \
      -H "Content-Type: application/json" \
      -d "{\"employee_id\": \"${EMPLOYEE_ID}\", \"password\": \"${PASSWORD}\"}" \
      --max-time 120)

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill persists API tokens to a predictable local file under the user’s home directory without any mention of restrictive permissions, encryption, or OS keychain use. Local token caching can enable session theft by other local users, malware, or backup/logging systems.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
employee_name=$(echo "$response" | jq -r '.data.employee_name')
        must_change_pw=$(echo "$response" | jq -r '.data.must_change_pw')

        mkdir -p ~/.openclaw/workspace/scripts
        echo "{\"token\": \"${API_TOKEN}\", \"employee_id\": \"${EMPLOYEE_ID}\", \"employee_name\": \"${employee_name}\", \"expires_at\": \"${expires_at}\", \"updated_at\": \"$(iso_now)\"}" > "$TOKEN_CACHE"

        # 首次登录强制改密检测

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The password-change request sends both old and new passwords to a remote HTTP endpoint. Over plaintext transport, this enables interception of the current credential and the replacement secret, allowing persistent account takeover.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
echo "(等待用户输入新密码...)"

            # AI 从用户回复中提取 new_password
            pw_response=$(curl -s -X POST "${FASTAPI_BASE_URL}/auth/change-password" \
              -H "Content-Type: application/json" \
              -d "{\"employee_id\": \"${EMPLOYEE_ID}\", \"old_password\": \"${PASSWORD}\", \"new_password\": \"${NEW_PASSWORD}\"}" \
              --max-time 120)

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This login request for account switching again sends a password to a remote HTTP service. Combined with AI-mediated extraction from chat, it creates both insecure collection and insecure transmission of credentials.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

md
echo "(等待用户输入密码...)"
        # AI 从用户回复中提取 password

        response=$(curl -s -X POST "${FASTAPI_BASE_URL}/auth/login" \
          -H "Content-Type: application/json" \
          -d "{\"employee_id\": \"${INPUT_EMPLOYEE_ID}\", \"password\": \"${PASSWORD}\"}" \
          --max-time 120)

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

This branch also writes refreshed or switched-account tokens to the same local cache, reinforcing persistent session storage as a design feature. Reused cached tokens increase the blast radius of local compromise and make silent account reuse easier.

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
employee_name=$(echo "$response" | jq -r '.data.employee_name')
            EMPLOYEE_ID="$INPUT_EMPLOYEE_ID"
            EMPLOYEE_NAME="$employee_name"
            mkdir -p ~/.openclaw/workspace/scripts
            echo "{\"token\": \"${API_TOKEN}\", \"employee_id\": \"${EMPLOYEE_ID}\", \"employee_name\": \"${EMPLOYEE_NAME}\", \"expires_at\": \"${new_expires}\", \"updated_at\": \"$(iso_now)\"}" > "$TOKEN_CACHE"
        else
            error_message=$(echo "$response" | jq -r '.message')

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The expired-token relogin request transmits credentials over HTTP, exposing them to network interception. Because this flow is likely to occur in normal operation, the risk is recurring rather than theoretical.

Content

Scanner excerpt · SKILL.md (reported line 228)May include surrounding context.

md
echo "请输入您的账号和密码,格式:账号 密码"
            echo "(等待用户输入...)"

            response=$(curl -s -X POST "${FASTAPI_BASE_URL}/auth/login" \
              -H "Content-Type: application/json" \
              -d "{\"employee_id\": \"${EMPLOYEE_ID}\", \"password\": \"${PASSWORD}\"}" \
              --max-time 120)

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The renew-failure fallback again transmits the employee password over HTTP. This compounds the insecure-secret-handling design and gives attackers multiple opportunities to capture credentials.

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

md
echo "⚠️ Token 续期失败,请重新输入密码"
                echo "(等待用户输入密码...)"

                response=$(curl -s -X POST "${FASTAPI_BASE_URL}/auth/login" \
                  -H "Content-Type: application/json" \
                  -d "{\"employee_id\": \"${EMPLOYEE_ID}\", \"password\": \"${PASSWORD}\"}" \
                  --max-time 120)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill uploads derived analysis and metadata from call transcripts or WeChat notifications to a remote endpoint over plain HTTP. Even if raw chat text is not fully included in every field, the payload can contain sensitive customer, project, and communication details that are exposed in transit.

Content

Scanner excerpt · SKILL.md (reported line 935)May include surrounding context.

md
visit_summary: $visit_summary
  }')

ingest_response=$(curl -s -X POST "${FASTAPI_BASE_URL}/project-portrait/ingest" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ${API_TOKEN}" \
  -d "$INGEST_PAYLOAD" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

The exchange-code/H5-link flow falls back to embedding the full bearer token directly in a URL query parameter. Query tokens are highly leak-prone through logs, browser history, referrers, screenshots, and link sharing; combined with plain HTTP transport, this could grant full account access to anyone who obtains the link.

Content

Scanner excerpt · SKILL.md (reported line 972)May include surrounding context.

生成 H5 链接(优先换码,兜底完整 Token)

bash
exchange_response=$(curl -s -X POST "${FASTAPI_BASE_URL}/auth/exchange-code" \
  -H "Authorization: Bearer ${API_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{}' \

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

文档中的分析提示词明确规定“使用中文输出”,这构成固定语言策略。文件中没有提供用户选择语言的机制,也没有说明该限制为何是特定地域或合规场景所必需。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.