Back to skill

Security audit

yoooclaw-world-cup-match-talk-scene

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed World Cup talking-points generator, but it can read broad recent phone notifications without app or group scoping and ships an insecure web-probing script.

Review this skill before installing if you are uncomfortable with an agent reading phone notifications. Use it only when you are willing to provide or confirm a narrow app, group, and time range, and treat public-source results cautiously because the included scraper weakens HTTPS verification and source allowlisting.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:29
Finding

Overbroad Access to Recent Phone Notifications

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:29 and SKILL.md:130-175
Vulnerability Type: Excessive notification access and violation of least privilege
Risk Level: High

Relevant instruction excerpt, translated into English:

text
If notification context is needed, query recent notifications without restricting
the group or application scope.

If a user request involves notifications, fan groups, viewing groups, phone
reminders, or notification-derived discussion material, notifications must be
queried before generating the notification-related module.

Use exec to run openclaw ntf search. If the user does not provide a time range,
query from yesterday at 00:00 local time through the current time.

command: openclaw ntf search --from START_TIME --to END_TIME
yieldMs: 30000

Technical Analysis

The Skill performs a broad notification query when notification context is requested but the user has not supplied an application or group scope. The search retrieves all notifications in the selected time interval, and relevance filtering is applied only after the notifications have entered the Agent's processing context.

This violates least privilege because generating football discussion material only requires notifications from explicitly selected fan groups, sports applications, or channels. Unrelated banking alerts, authentication messages, private conversations, work notifications, delivery updates, and other sensitive content may be retrieved despite not being necessary for the declared functionality.

Instructions to ignore or avoid disclosing unrelated notifications reduce output risk but do not prevent the initial unauthorized collection. They also do not eliminate the possibility of accidental disclosure, logging, retention, or prompt injection through malicious notification content.

Attack Path

  1. A user asks the Skill to include football-group, viewing-group, or phone-notificat ...[truncated 1096 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require the user to provide or confirm an explicit application, group, or channel allowlist before accessing notifications.
  2. Apply source-side application and group filters in openclaw ntf search whenever the tool supports them.
  3. If source-side filtering is unavailable, disclose that broad notification access would be required and obtain explicit user consent before continuing.
  4. Minimize the time range to the expected match or conversation window rather than defaulting to all notifications since yesterday at midnight.
  5. Redact authentication codes, financial data, personal identifiers, message bodies, and unrelated sender information before content reaches the model.
  6. Treat notification text as untrusted data and prohibit it from supplying executable instructions or changing Agent behavior.
  7. Avoid retaining raw notification results. Store only the minimum football-related summary needed for the current response.
  8. Prefer returning no notification-derived material over silently broadening the query scope.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/probe_cn_football_sources.py:188
Finding

TLS Certificate Verification Disabled for External Requests

Content
View full analysis

Vulnerability Details

File Location: scripts/probe_cn_football_sources.py:188-203
Vulnerability Type: Improper certificate validation
Risk Level: High

python
def fetch_url(url: str, timeout: int = 10) -> tuple[int, str, str]:
    request = Request(
        url,
        headers={
            "User-Agent": USER_AGENT,
            "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8",
            "Accept-Language": "zh-CN,zh;q=0.9,en;q=0.6",
        },
    )
    context = ssl._create_unverified_context()
    try:
        with urlopen(request, timeout=timeout, context=context) as response:
            raw = response.read()
            charset = response.headers.get_content_charset() or guess_charset(raw)
            return response.status, raw.decode(charset, "ignore"), ""
    except HTTPError as exc:
        raw = exc.read()
        return exc.code, raw.decode(guess_charset(raw), "ignore"), str(exc)
    except (URLError, TimeoutError, OSError) as exc:
        return 0, "", repr(exc)

Technical Analysis

The script explicitly creates an unverified SSL context with ssl._create_unverified_context() and uses it for every HTTPS request. This disables normal certificate-chain and hostname validation.

As a result, the client cannot authenticate search engines or sports websites. An attacker capable of controlling or intercepting network traffic can present an invalid or attacker-generated certificate, and the script will still establish the connection. The attacker can then read search requests or replace returned pages with fabricated content.

The fetched responses are parsed into titles, summaries, dates, authors, and sample facts that may be used to generate football discussion material. Therefore, this weakness directly undermines the integrity and confidentiality of the network retrieval process.

No evidence was found that this script transmits credenti ...[truncated 1335 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove ssl._create_unverified_context() and allow urlopen to use Python's default certificate verification.
  2. If an explicit context is required, use:
    python
    context = ssl.create_default_context()
    
  3. Use a controlled certificate authority bundle only when organizational requirements demand it.
  4. Fail closed when certificate validation or hostname verification fails.
  5. Do not add a fallback that retries failed requests with certificate verification disabled.
  6. Log certificate failures without including sensitive query contents.
  7. Validate redirects and require all final destinations to use HTTPS and remain within the approved domain allowlist.
  8. Add tests confirming that self-signed certificates, expired certificates, and hostname mismatches are rejected.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/probe_cn_football_sources.py:230
Finding

External Host Allowlist Bypass Through Substring Matching

Content
View full analysis

Vulnerability Details

File Location: scripts/probe_cn_football_sources.py:230-244
Vulnerability Type: Improper URL and hostname validation
Risk Level: Medium

python
def extract_search_links(body: str, domains: Iterable[str]) -> list[str]:
    extractor = TextExtractor()
    extractor.feed(body)
    candidates = extractor.links + re.findall(r"https?%3A%2F%2F[^\"'<>\\\s]+", body)
    urls: list[str] = []
    for candidate in candidates:
        candidate = html.unescape(unquote(candidate))
        if candidate.startswith("//"):
            candidate = "https:" + candidate
        if not candidate.startswith(("http://", "https://")):
            continue
        parsed = urlparse(candidate)
        if any(domain in parsed.netloc for domain in domains):
            urls.append(clean_tracking_url(candidate))
    return urls

Technical Analysis

The script determines whether a search-result URL belongs to an approved source by checking whether an approved domain string appears anywhere in parsed.netloc.

Substring matching does not enforce a DNS label boundary. For example, an attacker-controlled hostname such as news.zhibo8.com.attacker.example contains the allowed string news.zhibo8.com and therefore passes the check even though its registrable domain is attacker.example. Similar bypasses are possible for the other configured source domains.

The code also allows plain HTTP URLs and does not show final-destination validation after redirects. Consequently, an approved-looking search result can direct the scraper to an unauthorized host or potentially redirect an initially approved URL to one.

This weakness is compounded by disabled TLS certificate verification, although each issue can be exploited independently.

Attack Path

  1. An attacker causes a search-result page to contain a URL whose hostname embeds an allowed domain, such as news.zhibo8.com.attacker.example ...[truncated 1072 chars]
Remediation
View remediation

Remediation Suggestions

  1. Extract and normalize the hostname rather than comparing against netloc:
    python
    host = (urlparse(candidate).hostname or "").lower().rstrip(".")
    
  2. Require an exact hostname or proper subdomain boundary:
    python
    allowed = any(host == domain or host.endswith("." + domain) for domain in domains)
    
  3. Normalize configured domains to lowercase and remove trailing dots before comparison.
  4. Reject URLs containing usernames, malformed ports, invalid hostname encodings, or ambiguous parser representations.
  5. Permit HTTPS only unless plain HTTP is explicitly required and justified.
  6. Revalidate the final URL after every redirect and reject redirects outside the approved allowlist.
  7. Combine strict hostname validation with standard TLS certificate verification.
  8. Add regression tests covering malicious hosts such as allowed.example.attacker.test, allowed.example@attacker.test, trailing-dot variants, encoded hostnames, and redirect-based bypasses.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims to generate World Cup talking points and query notifications when needed, but its documented workflow materially expands into broad web scraping/probing behavior and does not accurately disclose these operational behaviors. Description-behavior mismatch is dangerous because it defeats informed consent and review: users and platform controls may authorize a benign-sounding writing skill while it performs more invasive collection activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill says it will proactively query phone notifications for notification- or group-related requests, but the user-facing description does not provide a clear privacy warning or explain the scope of data access. Accessing phone notifications is highly sensitive; without prominent upfront notice and consent boundaries, users may unknowingly authorize review of private communications and unrelated personal data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill directs the agent to use networked search and to write probe results to /tmp, but it declares no explicit tool scope or permission boundaries. That creates a least-privilege failure: the runtime may grant broader capabilities than users expect, making later misuse or accidental overreach harder to detect and govern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation criteria are broad enough to match ordinary writing, chat-help, or social-post requests, increasing the chance the skill is invoked outside a narrowly intended football-analysis context. Over-broad triggering matters because this skill can escalate into network collection and possibly notification access, so accidental invocation can expose data or cause unnecessary tool use.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

When the user does not specify sources, the skill instructs querying recent notifications without limiting group/app scope. This default broad collection is a data-minimization failure: even if only relevant snippets are later extracted, the agent first gains access to a large set of potentially sensitive notifications unrelated to the football task.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions say to query all returned notifications and then extract relevant content, which encourages bulk collection before filtering. This increases privacy risk because unrelated personal, financial, work, or social notifications may be ingested by the model, and semantic filtering after collection does not undo the initial exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template explicitly instructs using phone notifications and fan group messages to extract 'signals' and transform them into talking points, but it does not require an explicit privacy notice, consent check, minimization rule, or restriction on sensitive content. Because the skill metadata also says it will proactively query phone notifications when requests involve notifications or chat groups, this creates a real privacy-risk workflow where personal communications may be accessed and repurposed beyond the user's clear informed intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file title and template content require generating a social post in Chinese (e.g., '朋友圈文案') and provide no indication that the user can choose another language or locale. This is a natural-language policy concern because it imposes a specific language by default rather than making it optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire template is written as a prescriptive Chinese-language script, including instructions to repeat the phrasing directly. There is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context, which creates a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring itself is not the root issue, but it masks the fact that the scraper later disables TLS certificate verification for all HTTPS requests. That mismatch can mislead reviewers into trusting network behavior that is actually vulnerable to man-in-the-middle interception and content tampering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Creating an unverified SSL context disables certificate validation for every outbound HTTPS request made by the scraper. An attacker on the network path, a hostile proxy, or a compromised Wi-Fi environment could impersonate target sites and feed falsified content into the skill's output pipeline.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown template hardcodes Chinese-language headings and instructions throughout the file. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's headings and instructional template text are entirely in Chinese, which implies the skill content is intended to operate in a fixed language. Under the policy, a skill should not force a specific language unless it offers opt-in or clearly documents a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Accept-Language header is hard-coded to prefer zh-CN and zh, which imposes a specific language/locale behavior regardless of user preference. This is a natural-language policy concern because the file does not offer a language choice or explain a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/probe_cn_football_sources.py:195