Back to skill

Security audit

小红书笔记搬运

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned content reposting automation, but it can publish to real external accounts and handles local files unsafely without enough confirmation or scoping.

Install only if you intend to repost Xiaohongshu material to the listed Facebook and WordPress targets. Use test or draft publishing first, confirm the target accounts every run, validate image URLs and titles before invoking scripts, avoid storing sensitive content in the shared upload directory, and treat WP_TOKEN as a live publishing credential.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/download_images.sh:18
Finding

Unrestricted URL Retrieval Enables Server-Side Request Forgery and Local File Access

Content
View full analysis

Vulnerability Details

File Location: scripts/download_images.sh, lines 18-27
Vulnerability Type: Unrestricted external resource retrieval
Risk Level: High

Vulnerable Code

bash
# Download images
for url in "${@:2}"; do
    filename=$(basename "$url" | sed 's/webp$/jpg/')
    
    # Download with Referer
    curl -H "Referer: https://www.xiaohongshu.com/" \
         -o "$SAVE_DIR/$filename" "$url"
    
    # Copy to upload directory
    cp "$SAVE_DIR/$filename" "$UPLOAD_DIR/"
    
    echo "Downloaded: $filename"
done

Technical Analysis

Every URL supplied after the title argument is passed directly to curl. The script does not validate the URL scheme, hostname, resolved IP address, response type, or response size.

The caller is therefore not restricted to downloading images from Xiaohongshu. Depending on the protocols supported by the installed curl build, a malicious caller can request:

  • Localhost or internal HTTP services.
  • Cloud instance metadata endpoints.
  • Private or link-local network addresses.
  • Local files through the file:// scheme.
  • Arbitrarily large resources that consume local disk capacity.
  • Non-image content that is subsequently placed in the upload staging directory.

The hardcoded Referer header does not constrain the destination and provides no SSRF protection. The retrieved data is written using the privileges of the user running the Skill.

Attack Path

  1. An attacker controls or influences an image URL passed to download_images.sh.
  2. The attacker supplies a URL such as a localhost endpoint, private-network service, cloud metadata endpoint, or file:// resource.
  3. The script passes the URL directly to curl.
  4. curl retrieves the resource with the network and filesystem access available to the Skill process.
  5. The response is stored under the archive directory and copied into /tmp/openclaw/uploads.
  6. The ret ...[truncated 681 chars]
Remediation
View remediation

Remediation Suggestions

  • Parse each URL before invoking curl.
  • Permit only the https scheme.
  • Maintain an explicit allowlist of approved Xiaohongshu image CDN hostnames.
  • Reject embedded credentials, localhost names, IP literals, and destinations resolving to loopback, private, link-local, multicast, or reserved address ranges.
  • If redirects are enabled in the future, validate every redirect destination against the same allowlist.
  • Configure connection and transfer timeouts.
  • Enforce a maximum response size.
  • Download into a newly created temporary file and verify the content using an image decoder rather than trusting the extension or Content-Type header.
  • Reject responses that are not valid supported image formats.
  • Run the downloader with restricted network access and minimal filesystem permissions.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/download_images.sh:5
Finding

Unsanitized Note Title Enables Directory Traversal and Writes Outside the Archive Root

Content
View full analysis

Vulnerability Details

File Location: scripts/download_images.sh, lines 5-11
Vulnerability Type: Path traversal
Risk Level: High

Vulnerable Code

bash
TITLE="$1"
ACCOUNT="学未教育"
SAVE_DIR="$HOME/Downloads/铁头/$ACCOUNT/$TITLE"
UPLOAD_DIR="/tmp/openclaw/uploads"

# Create save directory
mkdir -p "$SAVE_DIR"

The resulting path is later used as a download destination:

bash
curl -H "Referer: https://www.xiaohongshu.com/" \
     -o "$SAVE_DIR/$filename" "$url"

Technical Analysis

The first command-line argument is treated as a note title and inserted directly into a filesystem path. No validation rejects absolute paths, path separators, .. components, control characters, or other unsafe path syntax.

Shell quoting prevents command injection but does not prevent filesystem path traversal. A title containing traversal components can cause SAVE_DIR to resolve outside:

text
$HOME/Downloads/铁头/学未教育/

The script then creates the resolved directory and writes downloaded content into it. Existing files can be overwritten when the process has write permission and the generated filename matches an existing file.

Attack Path

  1. An attacker controls or influences the title passed as the first argument.
  2. The attacker provides a title containing traversal components, such as ../../../../tmp/attacker-controlled-directory.
  3. SAVE_DIR resolves outside the intended archive root.
  4. mkdir -p creates the attacker-selected directory when permissions allow.
  5. curl -o writes downloaded content into that directory.
  6. If the destination filename corresponds to an existing writable file, that file can be replaced.

Impact Assessment

Exploitation permits directory creation and file writes outside the documented archive location. The attacker can overwrite files writable by the Skill process when the destination path and filename can be arranged appropriate ...[truncated 274 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not use an untrusted display title directly as a directory name.
  • Convert titles into constrained slugs containing only an approved character set.
  • Reject absolute paths, /, \, .., null bytes, and control characters.
  • Resolve the candidate destination to a canonical path and verify that it remains beneath a fixed archive root.
  • Generate filesystem identifiers independently from titles, such as random UUIDs, and store the original title only as metadata.
  • Open downloaded files using exclusive creation where overwriting is unnecessary.
  • Reject symbolic links in every path component.
  • Run the script with only the filesystem privileges required for its archive and staging directories.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/prepare_upload.py:14
Finding

Predictable Shared Temporary Directory Permits Symlink-Based File Overwrites

Content
View full analysis

Vulnerability Details

File Location: scripts/prepare_upload.py, lines 14-33
Vulnerability Type: Unsafe temporary-file and symlink handling
Risk Level: Medium

Vulnerable Code

python
def prepare_upload_dir(save_dir, upload_dir="/tmp/openclaw/uploads"):
    """Prepare upload directory by clearing and copying images."""
    # Clear upload directory
    if os.path.exists(upload_dir):
        for f in os.listdir(upload_dir):
            fp = os.path.join(upload_dir, f)
            if os.path.isfile(fp):
                os.remove(fp)
    else:
        os.makedirs(upload_dir)
    
    # Copy images
    for f in os.listdir(save_dir):
        if f.lower().endswith(('.jpg', '.jpeg', '.png')):
            src = os.path.join(save_dir, f)
            dst = os.path.join(upload_dir, f)
            with open(src, 'rb') as s:
                with open(dst, 'wb') as d:
                    d.write(s.read())
            print(f"Copied: {f}")

Technical Analysis

The script uses the fixed path /tmp/openclaw/uploads, which can be predictable and shared among processes. It does not verify:

  • That the directory is owned by the current user.
  • That the directory itself is not a symbolic link.
  • That destination files are not symbolic links.
  • That destination files are created exclusively.
  • That directory permissions prevent access by other local users.

Python's open(dst, 'wb') follows symbolic links and truncates the resolved target. If an attacker can create a symbolic link with the same name as an image that will be copied, the script can overwrite the link target using the privileges of the Skill process.

A symlink at /tmp/openclaw/uploads can also redirect cleanup and staging operations into a different directory. The checks and writes are not atomic, leaving time-of-check-to-time-of-use opportunities.

Attack Path

  1. A local attacker predicts the staging direct ...[truncated 927 chars]
Remediation
View remediation

Remediation Suggestions

  • Create a unique per-run staging directory with tempfile.mkdtemp() or tempfile.TemporaryDirectory().
  • Apply permissions of 0700 to the directory.
  • Verify directory ownership with os.lstat() and reject symbolic links.
  • Open destination files using exclusive creation and no-follow semantics, such as os.open() with O_CREAT | O_EXCL | O_NOFOLLOW where supported.
  • Verify source files with lstat() before opening them and reject symbolic links or non-regular files.
  • Avoid check-then-use sequences on attacker-accessible paths.
  • Atomically publish or replace a completed private staging directory.
  • Remove the private staging directory after the upload completes.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/download_images.sh:13
Finding

Incorrectly Quoted Wildcard Leaves Stale Files in the Upload Directory

Content
View full analysis

Vulnerability Details

File Location: scripts/download_images.sh, lines 13-14
Vulnerability Type: Incomplete cleanup causing cross-task data exposure
Risk Level: Medium

Vulnerable Code

bash
# Clear upload directory
rm -rf "$UPLOAD_DIR/*"
mkdir -p "$UPLOAD_DIR"

Technical Analysis

The wildcard is included inside a quoted string. Consequently, the shell does not expand * into the existing directory entries. The command attempts to remove a literal path named:

text
/tmp/openclaw/uploads/*

In ordinary operation, previous files remain in the upload directory. This contradicts the documented requirement that the directory be cleared before each publication.

The Facebook workflow selects all files from /tmp/openclaw/uploads. Stale files from an earlier task can therefore be mixed with newly downloaded images and uploaded to the wrong account or post.

Attack Path

  1. One task stages images in /tmp/openclaw/uploads.
  2. A later invocation executes rm -rf "$UPLOAD_DIR/*".
  3. Because wildcard expansion is suppressed, the previous images remain.
  4. The later task copies its new images into the same directory.
  5. The documented file-dialog automation selects all entries in the directory.
  6. Images belonging to the earlier task are unintentionally published with the later post.

Impact Assessment

This issue can cause cross-task or cross-account disclosure of staged images. It may publish confidential, private, or incorrect content to Facebook under the configured page.

The vulnerability does not provide operating-system privilege escalation. Its principal impact is confidentiality loss, unauthorized publication, data integrity failure, and reputational damage within the connected social-media workflow.

Remediation
View remediation

Remediation Suggestions

  • Do not use a quoted glob for directory cleanup.
  • Prefer a newly created private, per-task staging directory rather than reusing a global directory.
  • If a fixed directory must be cleaned, first verify its canonical path, ownership, permissions, and non-symlink status.
  • Enumerate entries safely and delete only validated contents.
  • Include hidden files in cleanup; a simple * glob does not cover dotfiles even when expanded.
  • Stop execution if cleanup fails instead of continuing with stale content.
  • Add a pre-upload check that compares staged files against an explicit manifest for the current task.
  • Configure the file-dialog automation to select only files listed in that manifest rather than selecting every directory entry.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (28)

Tainted flow: 'headers' from os.environ.get (line 20, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/wp_publish.py (reported line 30)May include surrounding context.

python
"status": status
    }
    
    response = requests.post(url, headers=headers, json=data)
    
    if response.status_code == 200 or response.status_code == 201:
        result = response.json()

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

声明描述的是一个面向小红书到 Facebook/WordPress 的自动化发布流程,但该代码片段实际只涉及本地文件系统操作和图片格式处理。它会清空上传目录、复制图片,并定义了一个 webp 转 jpg 的辅助函数;没有任何网络请求、API 调用、认证、发布逻辑、笔记内容提取或跨平台同步逻辑。因此,这段代码的实际主要用途是为后续上传准备图片目录,属于整体流程中的辅助步骤,但单独看并不能准确代表已声明的核心能力,存在明显描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个同时面向小红书、Facebook 和 WordPress 的搬运自动化流程;但提供的代码片段只做了一件事:读取本地内容文件并调用 WordPress API 发布文章。它没有任何 Facebook 集成,也没有任何与小红书内容获取、转换或同步有关的逻辑。因此,代码行为仅覆盖声明中的一部分,且缺少描述中的核心跨平台搬运能力,构成描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The document includes a high-risk filesystem operation, rm -rf /tmp/openclaw/uploads/*, as routine guidance in a publishing workflow. In agent or operator use, destructive shell snippets can be reused blindly; if the path is wrong, symlinked, empty after variable substitution in future adaptations, or run with elevated privileges, this can cause broad data loss.

Content

Scanner excerpt · references/pitfalls.md (reported line 25)May include surrounding context.

🔴 每次发布前必须清空上传目录

bash
rm -rf /tmp/openclaw/uploads/*

🔴 macOS 文件对话框属于独立进程

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The document includes a high-risk filesystem operation, rm -rf /tmp/openclaw/uploads/*, as routine guidance in a publishing workflow. In agent or operator use, destructive shell snippets can be reused blindly; if the path is wrong, symlinked, empty after variable substitution in future adaptations, or run with elevated privileges, this can cause broad data loss.

Content

Scanner excerpt · references/pitfalls.md (reported line 25)May include surrounding context.

🔴 每次发布前必须清空上传目录

bash
rm -rf /tmp/openclaw/uploads/*

🔴 macOS 文件对话框属于独立进程

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The cleanup command is unsafe because it attempts to delete files in a fixed directory using rm -rf as part of normal operation, but the quoting is wrong: "$UPLOAD_DIR/*" prevents wildcard expansion, making behavior error-prone and indicating unsafe deletion logic. Even aside from the quoting bug, destructive deletion in /tmp-based shared staging can remove data unexpectedly and becomes more dangerous if the path is later made configurable or altered via environment or symlink manipulation.

Content

Scanner excerpt · scripts/download_images.sh (reported line 14)May include surrounding context.

sh
mkdir -p "$SAVE_DIR"

# 清空上传目录
rm -rf "$UPLOAD_DIR/*"
mkdir -p "$UPLOAD_DIR"

# 下载图片

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README documents automation that downloads third-party content to local storage and republishes it to Facebook and WordPress, but it provides no warning, consent boundary, or explanation of what data will be transferred and modified locally. In an agent skill context, this is risky because users may trigger cross-platform publication and filesystem changes without understanding the scope, increasing the chance of unintended disclosure, copyright/privacy violations, or accidental posting.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes network access, local file operations, shell commands, and likely environment-backed credentials, but it declares no explicit tool scope or permission boundaries. That makes the skill over-privileged by default and increases the chance of unintended data access, content publication, or shell misuse when executed by an agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is designed to scrape content from one platform and publish it to external services, but it provides no explicit warning about data transmission, rights, privacy, or the real-world effect of publication. In context, this increases the risk of accidental exfiltration, unauthorized reposting, or policy/legal violations during normal use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill includes broad macOS UI automation through osascript and System Events, which can interact with system dialogs beyond the narrow publishing task. UI scripting is fragile and can be redirected by focus changes or dialog spoofing, causing unintended file selection or other unintended local actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The WordPress API example uses bearer-token authentication to publish directly to a live site, but the skill does not clearly warn that the request has immediate external side effects. This can cause accidental publication, misuse of production credentials, or disclosure of content to the public internet.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This is a real external-transmission behavior: the curl command sends content and an authorization bearer token to the WordPress API. In a publishing skill that may be expected, but it is still security-relevant because it transmits data off-host and can create or modify public content on an external service.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

REST API

bash
curl -X POST "https://public-api.wordpress.com/wp/v2/sites/252834205/posts" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs use of a destructive deletion command to clear a directory before publishing, but provides no safeguards such as path validation, confirmation prompts, or safer alternatives. In an automation skill, operators may copy or parameterize this command, and any path mistake or variable expansion issue could delete unintended files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document exposes a live WordPress post creation API endpoint tied to a specific site and provides no warning that use of this endpoint can publish content to an external production account. In the context of an automation skill explicitly designed to republish content cross-platform, this increases the chance of unintended or unauthorized posting, account misuse, and reputational harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented workflow explicitly automates cross-posting from Xiaohongshu to Facebook and WordPress, including upload and publication steps, but omits any notice that these actions affect real external accounts. Because this skill's purpose is content搬运 and publishing, the lack of safety interlocks makes accidental live posting and unauthorized distribution materially more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script automatically deletes prior contents of the upload staging directory before each run, with no confirmation, backup, or safety checks. In an automation skill that moves content between platforms, this can cause unintended data loss or removal of unrelated files if the staging directory is shared or contains pending uploads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function unconditionally deletes all regular files in a fixed upload directory before copying new images, with no confirmation, backup, or validation that the directory is dedicated to ephemeral data. In an automation skill that publishes content, this can destroy unrelated files if the path is reused, misconfigured, or symlinked, making it a real destructive-file-handling issue even if not overtly malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script performs an immediate external publish to WordPress once invoked, with no interactive confirmation, dry-run mode, or explicit disclosure at execution time. In an agent or automation context, this increases the risk of accidental publication of sensitive, copyrighted, or unreviewed content to a public site.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/wp_publish.py (reported line 30)May include surrounding context.

python
"status": status
    }
    
    response = requests.post(url, headers=headers, json=data)
    
    if response.status_code == 200 or response.status_code == 201:
        result = response.json()

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The changelog content is entirely in Chinese, beginning with the Chinese title at L01 and continuing throughout the document, with no indication that the user can choose another language or that the skill is restricted to a Chinese-speaking or region-specific audience. This creates a natural-language policy concern because it imposes a locale/language choice without explicit opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing documentation in this file is written in Chinese, and there is no indication that users may choose another language or that the locale restriction is intentional and justified. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The instructions store content under persistent local directories and use a temporary upload directory, but they do not adequately warn about retention, residual sensitive data, or cleanup failure. This can leave scraped content on disk longer than intended and expose it to other local users, backups, or later accidental reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest presents the skill entirely in Chinese-facing naming and description, with no indication that users can choose another language or that the locale restriction is intentional for a region-specific tool. Under the policy rule for natural-language violations, this can be considered a language/locale constraint without opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

All instructional content in the file is written in Chinese, with no indication that other languages are supported or that Chinese is a justified locale-specific requirement. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.