Back to skill

Security audit

每日科技播报

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Chinese-language tech news digest skill, with optional publishing documentation that users should handle more carefully.

Installers can treat the runtime skill as low risk if they are comfortable with outbound requests to Sina Tech and IT Home and Chinese-language output. Do not copy the optional publishing commands as written in a sensitive environment: use a pinned, trusted ClawHub CLI and avoid passing tokens directly on the command line.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:81
Finding

Unpinned ClawHub CLI execution through npx

Content
View full analysis

Vulnerability Details

File Location: README.md:81-92
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

bash
npx clawhub login
npx clawhub publish skills/daily-tech-broadcast --slug daily-tech-broadcast --name "每日科技播报" --version 1.0.0 --changelog "Initial release: 新浪科技/IT之家抓取,无需 API Key"
npx clawhub publish . --slug daily-tech-broadcast --name "每日科技播报" --version 1.0.0 --changelog "Initial release"

Technical Analysis

The documentation instructs users to execute the clawhub npm package through npx without specifying a package version or integrity value. If the package is not already installed locally, npx may retrieve and execute the current registry release.

Consequently, the code that runs is not fixed to the package version reviewed when this Skill was published. A compromised package, registry account, dependency, or unexpectedly incompatible future release could execute arbitrary installation or runtime code. These commands are publisher-oriented operations and are not necessary for the Skill's declared runtime function of downloading public news headlines.

Attack Path

  1. An attacker compromises the clawhub package, one of its dependencies, or the relevant package-publishing account.
  2. A malicious version is published under the package name referenced by the README.
  3. A user follows the documentation and runs an unversioned npx clawhub command.
  4. npx downloads the compromised release when no trusted local copy is available.
  5. Package installation or execution code runs with the privileges of the invoking user.

Impact Assessment

Successful exploitation could run arbitrary code with the invoking user's operating-system privileges. Depending on that user's access, the malicious package could read workspace files and user-accessible credentials, alter source code, access authenticated development tooling, or make outb ...[truncated 168 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the CLI to a specific reviewed version, such as npx clawhub@<reviewed-version>.
  • Use a lockfile and verify package integrity before execution.
  • Prefer a separately installed, organization-approved CLI rather than allowing npx to download code on demand.
  • Document the expected package publisher, version, checksum, and verification procedure.
  • Move publishing instructions into maintainer documentation so ordinary Skill users are not encouraged to execute unnecessary package-management commands.
  • Run publishing tools in a restricted environment without access to unrelated credentials or sensitive workspace files.

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:82
Finding

Authentication token exposed through command-line arguments

Content
View full analysis

Vulnerability Details

File Location: README.md:82-83
Vulnerability Type: Sensitive token exposure in process arguments and shell history
Risk Level: Medium

Vulnerable Code

bash
npx clawhub login --token <paste-token> --no-browser

Technical Analysis

The documented remote-login procedure places the ClawHub authentication token directly in a command-line argument. Command-line secrets may be retained in shell history, terminal transcripts, remote-session logs, CI logs, monitoring records, or command auditing systems. On some operating systems, other local users or monitoring processes may also be able to inspect process arguments while the command is running.

The Skill does not itself collect or transmit the token, but its documented procedure encourages insecure handling of a sensitive credential. Token-based publishing is unrelated to the minimum runtime privileges required to fetch public news headlines.

Attack Path

  1. A user copies a valid ClawHub token into the documented command.
  2. The command, including the token, is recorded in shell history, terminal logging, automation output, or process metadata.
  3. Another local user, administrator, log reader, or compromised monitoring component accesses that record.
  4. The attacker extracts and reuses the token before it expires or is revoked.
  5. The attacker performs operations authorized by the token against the associated ClawHub account.

Impact Assessment

The obtainable access is limited to the permissions assigned to the exposed token. Depending on its scope, an attacker may be able to authenticate as the user, publish or modify Skill packages, access account resources, or distribute altered releases. This could also create a downstream supply-chain risk for users who install packages controlled through the compromised account.

Remediation
View remediation

Remediation Suggestions

  • Do not pass authentication tokens directly as command-line arguments.
  • Prefer a CLI mechanism that reads the token from protected standard input without echoing it.
  • Use an operating-system credential store or the CLI's protected authentication configuration.
  • If environment-variable input is the only supported alternative, disable shell tracing, avoid logging the environment, scope the variable to one process, and unset it immediately afterward.
  • Use short-lived, narrowly scoped tokens that can only perform the required publishing action.
  • Add explicit instructions to rotate the token if it has already appeared in shell history or logs.
  • Keep publishing credentials and procedures outside the runtime documentation for the headline-fetching Skill.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Chinese manual-trigger description says the skill should run when a user says phrases like '执行每日科技播报', but it does not define strict activation boundaries, exclusions, or confirmation requirements. In agent environments, broad trigger language can cause unintended invocation, leading to unplanned outbound HTTP requests and automatic message delivery to channels.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub without pinning a specific package version. npx may fetch and execute the latest published package, which creates a supply-chain risk: a compromised or malicious upstream release could execute arbitrary code on the publisher's machine, and the surrounding text also discusses handling authentication tokens, increasing the sensitivity of the environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This line again directs execution of npx clawhub without version pinning. Because npx resolves packages dynamically, users may run unintended code if the package is updated, hijacked, or typo-squatted, making this a real supply-chain execution risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README continues the same unpinned npx clawhub usage pattern in a token-based login flow. In this context, an attacker controlling the fetched package could steal the supplied token or run arbitrary commands on the host, so the risk is amplified by credential exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This publication command uses npx clawhub without locking the package version. Publishing workflows usually run with repository write access and user credentials, so executing an unpinned remote package can lead to code execution, credential theft, or tampering with published artifacts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The alternate publish example repeats the same unpinned npx clawhub pattern. Because it is presented as normal installation/publishing guidance, users are likely to copy-paste it, making accidental execution of a compromised upstream package plausible.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The English description uses a similarly broad phrase, 'run daily tech broadcast', without clarifying whether mentions, examples, or relayed text should activate the skill. In orchestration systems, ambiguous activation can be abused to trigger network access or content posting unexpectedly.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs running a local Python script that performs HTTP fetching from external news sites, but the manifest does not declare any tool scope or permissions describing that network capability. This creates a mismatch between declared and actual behavior, reducing reviewability and allowing network access to be granted implicitly rather than intentionally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad phrases such as '科技要闻' and '推一下科技新闻', which are common conversational requests and may cause the skill to activate when the user did not intend this specific implementation. Unintended invocation matters here because the skill performs network retrieval and executes a script, so misrouting a request could cause unnecessary external access or unexpected behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring states the skill's behavior entirely in Chinese, and the script is presented as a general-purpose daily tech broadcast tool rather than a clearly region-specific or Chinese-only skill. This creates a natural-language locale policy issue because the skill forces a specific language without offering the user a choice or documenting an opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The broadcast title, date formatting, fallback text, and attribution are all hard-coded in Chinese, so every user receives Chinese output regardless of preference. Because no language selection or opt-in is provided, this is a natural-language policy violation under the locale-choice requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README states that the skill fetches external news and is suitable for pushing digests to Discord/Feishu channels, but it does not prominently warn that running the skill performs outbound network requests and may deliver fetched content to third-party platforms. This can surprise users in restricted or privacy-sensitive environments and increase the chance of unintended data egress.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.