Back to skill

Security audit

旅游攻略多平台抓取助手

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent travel-guide harvesting purpose, but its launcher and browser workflow create review-worthy local execution and authenticated-browser risks.

Review before installing. Use only with trusted destination inputs, avoid running the launcher on untrusted text, use a dedicated low-privilege browser profile/account for CDP, close unrelated tabs, and verify the external xiaohongshu-crawler extraction script before allowing browser eval.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-tourism-guide.sh:106
Finding

Arbitrary Python Code Execution Through Unsanitized Destination Input

Content
View full analysis
> "$TASK_FILE" << EOF - 搜索URL: https://www.xiaohongshu.com/search_result?keyword=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))")&type=note&sort=collect_count - 三种排序都要获取: hot / collect_count / time_descending - 正文提取: 必须使用 eval + 提取脚本 agent-browser --cdp 18800 eval "\$(cat $HOME/.openclaw/workspace/skills/xiaohongshu-crawler/scripts/extract-article.js)" --json - 特有问题: 二维码拦截 → 通知用户扫码登录 EOF ;; mafengwo) cat >> "$TASK_FILE" << EOF - 搜索URL: https://www.mafengwo.cn/search/q.php?q=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))")&t=blog - 必须提取浏览量(马蜂窝特有指标) - 特有问题: 目的地页面404 → 改用搜索 EOF ;; ctrip) cat >> "$TASK_FILE" << EOF - 景点页面: https://you.ctrip.com/sight/$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))").html - 游记页面: https://you.ctrip.com/travels/$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))").html - 必须提取 ⭐x.x/5 格式评分(携程特有) EOF ;; ``` ### Technical Analysis The destination argument is taken directly from `$1`: ```bash DEST="$1" ``` It is subsequently interpolated into Python source code: ```bash python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))" ``` Shell quoting does not make this safe for the Python parser. A destination containing a single quote can terminate the Python string passed to `urllib.parse.quote`, insert additional Python statements, and comment out the remaining syntax. This is a source-code injection vulnerability rather than ordinary URL-encoding failure. The same unsafe construction occurs four times for the Xiaohongshu, Mafengwo, and Ctrip task templates. ### Attack Path 1. An attacker or untrusted caller controls the destination supplied ...[truncated 1340 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/start-tourism-guide.sh:103
Finding

Execution of an Unpinned External Skill Script in an Authenticated Browser Context

Content
View full analysis
> "$TASK_FILE" << EOF - 搜索URL: https://www.xiaohongshu.com/search_result?keyword=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))")&type=note&sort=collect_count - 三种排序都要获取: hot / collect_count / time_descending - 正文提取: 必须使用 eval + 提取脚本 agent-browser --cdp 18800 eval "\$(cat $HOME/.openclaw/workspace/skills/xiaohongshu-crawler/scripts/extract-article.js)" --json - 特有问题: 二维码拦截 → 通知用户扫码登录 EOF ``` The corresponding instruction in `SKILL.md` is: ```bash # 4. 获取完整内容 + 分享链接(必须用 eval + JavaScript) agent-browser --cdp 18800 eval "$(cat ~/.openclaw/workspace/skills/xiaohongshu-crawler/scripts/extract-article.js)" --json ``` ### Technical Analysis The Skill directs a subagent to load JavaScript from another installed Skill and execute it through `agent-browser eval`. The referenced file is not part of the audited project, and the project does not verify its version, origin, ownership, permissions, or cryptographic digest before execution. Consequently, the effective browser-side code can change independently after this Skill has been reviewed. The project metadata also advertises a local script named `scripts/extract-article.js`, but that file is absent from the supplied project. The executable workflow instead depends on the external path under `~/.openclaw/workspace/skills/xiaohongshu-crawler/`. Executing the dependency in a browser tab is particularly sensitive because the workflow explicitly expects a logged-in Xiaohongshu session. JavaScript executed in that page context can inspect page content and perform actions available to the current origin. ### Attack Path 1. The `xiaohongshu-crawler` dependency is ...[truncated 1418 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/start-tourism-guide.sh:30
Finding

Over-Privileged Chrome Remote-Debugging Session Exposes Authenticated Browser State

Content
View full analysis
/dev/null | grep -q .; then echo "⚠️ Chrome浏览器未启动,CDP端口 18800 不可用" echo "正在尝试启动浏览器..." if command -v google-chrome >/dev/null 2>&1; then google-chrome --remote-debugging-port=18800 --no-first-run --no-default-browser-check & echo "✅ 已启动 google-chrome --remote-debugging-port=18800 &" sleep 3 elif command -v chrome >/dev/null 2>&1; then chrome --remote-debugging-port=18800 --no-first-run --no-default-browser-check & echo "✅ 已启动 chrome --remote-debugging-port=18800 &" sleep 3 else echo "❌ 无法自动找到chrome,请手动启动:" echo " google-chrome --remote-debugging-port=18800 &" exit 1 fi fi ``` The Skill instructions explicitly rely on logged-in browser state: ```markdown - 文章内容需要登录:通过连接用户已登录浏览器解决 ``` ### Technical Analysis Chrome DevTools Protocol provides broad control over browser targets. A CDP client can inspect page content, execute JavaScript, navigate tabs, and interact with authenticated websites. The launcher automatically enables CDP on port 18800 but does not: - Create a dedicated temporary browser profile. - Explicitly isolate the browser from the user's normal authenticated profile. - Authenticate or authorize CDP clients. - Record and validate which process connects to CDP. - Shut down the debugging browser when the task completes. - Explicitly bind the debugging endpoint to a controlled interface in the launch command. Although the script probes the endpoint through `localhost`, that probe does not itself enforce listener isolation or client authorization. The workflow therefore grants substantially broader access than is required merely to retrieve publ ...[truncated 1267 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells the agent to execute local JavaScript via shell substitution: eval "$(cat ...extract-article.js)". This pattern runs code from a filesystem path without integrity checks, so a modified or replaced script could execute arbitrary commands or exfiltrate data under the agent's privileges.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes phrases like “攻略抓取” and especially destination/theme-only phrases such as “台州攻略” and “亲子游攻略”, which are broad natural requests a user might say without intending to invoke this specific harvesting workflow. The file does not provide negative examples or narrower activation constraints to distinguish when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill prescribes automatic browser launching and filesystem writes without a clear upfront warning or consent gate. Because these actions change local state and may attach to a debuggable browser session, accidental invocation could lead to unexpected exposure of browsing context or unwanted file creation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The repeated finding reflects the same persistence design: fixed-path status and data files intended for cross-session recovery. In context, this makes the skill more sensitive because it also interacts with logged-in browser sessions and third-party content, so retained artifacts may capture more than innocuous workflow metadata.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

bash
# 为每个平台创建 3 个文件
# 任务文件(Main Agent 写一次)
write ~/.openclaw/workspace/tasks/小红书_2026-04-24_任务.md
# 状态文件(Subagent 写进度,Main Agent 读状态)
write ~/.openclaw/workspace/tasks/小红书_2026-04-24_状态.md
# 数据文件(Subagent 写攻略,Main Agent 读汇总)

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The repeated finding reflects the same persistence design: fixed-path status and data files intended for cross-session recovery. In context, this makes the skill more sensitive because it also interacts with logged-in browser sessions and third-party content, so retained artifacts may capture more than innocuous workflow metadata.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

bash
# 为每个平台创建 3 个文件
# 任务文件(Main Agent 写一次)
write ~/.openclaw/workspace/tasks/小红书_2026-04-24_任务.md
# 状态文件(Subagent 写进度,Main Agent 读状态)
write ~/.openclaw/workspace/tasks/小红书_2026-04-24_状态.md
# 数据文件(Subagent 写攻略,Main Agent 读汇总)

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

This section again instructs creation of persistent task files in a shared workspace directory. Reusing durable files across runs can leak historical task context and harvested content into future executions or to other components with workspace access.

Content

Scanner excerpt · SKILL.md (reported line 845)May include surrounding context.

Step 1: 准备三文件(Main Agent)

bash
# 创建任务目录
mkdir -p ~/.openclaw/workspace/tasks

# 为每个平台创建 3 个文件
write ~/.openclaw/workspace/tasks/小红书_2026-04-24_任务.md

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The embedded task first states 仅写此文件 for the data file, implying the data file is the only writable target. Immediately afterward, the same task requires updating the status file after each article and on errors, which directly contradicts the earlier instruction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes instructions to start Chrome with remote debugging and to monitor, kill, and restart subagents. Those actions exceed simple content harvesting and can affect local system state and other running agent sessions, expanding the operational scope in a way that could be abused or cause collateral disruption.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script's user-facing natural language is entirely in Chinese and presents usage and operational messages only in that language. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified or alternatives are offered.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script later embeds DEST inside a double-quoted shell command passed to python3 -c within a here-doc, so shell command substitution like $(...) in DEST will be expanded when the line is constructed. That means a user-supplied destination can trigger arbitrary command execution while generating task files, despite the comment implying URL handling is safe.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script automatically starts Chrome with a remote debugging port exposed on localhost and proceeds to create task files without explicit user confirmation. Exposing CDP increases attack surface because any local process can potentially control the browser session, inspect data, and drive authenticated actions if the port is reachable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The document presents all instructions, triggers, prompts, output templates, and user-facing status messages exclusively in Chinese, with no indication that the user may choose another language. Under the policy, a forced language without opt-in can be a natural-language policy violation unless the locale limitation is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.