Back to skill

Security audit

每日毛选文章推送

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated daily article delivery purpose, but its optional image generator can run another local script with the user's full environment, including unrelated secrets.

Review this before installing if your agent environment contains valuable API keys or cloud credentials. Avoid using SEEDREAM_SCRIPT or the optional image generator unless you trust the referenced di-seedream-gen script, and run it with a minimal environment. Verify the Telegram chat ID, bot token, and output directory before enabling scheduled runs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_daily.py:29
Finding

External Image Generator Inherits the Entire Process Environment

Content
View full analysis
Optional[Path]: candidates = [ Path(os.environ.get("SEEDREAM_SCRIPT", "")), Path.home() / ".openclaw" / "skills" / "di-seedream-gen" / "scripts" / "generate_image.py", Path.home() / ".openclaw" / "workspace-imagor" / "skills" / "di-seedream-gen" / "scripts" / "generate_image.py", Path.home() / ".openclaw" / "workspace" / "skills" / "di-seedream-gen" / "scripts" / "generate_image.py", ] for p in candidates: if p.exists(): return p return None ``` ```python api_key = os.environ.get("SEEDREAM_API_KEY", "") if not api_key: sys.exit(1) script = find_seedream_script() if not script: sys.exit(1) output_file = output_dir / f"{today}.png" env = os.environ.copy() env["SEEDREAM_API_KEY"] = api_key cmd = [ sys.executable, str(script), "--prompt", prompt, "--filename", str(output_file), "--size", args.size, "--model", args.model ] result = subprocess.run( cmd, env=env, capture_output=True, text=True, timeout=120 ) ``` ### Technical Analysis The script permits the `SEEDREAM_SCRIPT` environment variable to select a local Python program. It also searches several external OpenClaw Skill installation paths. The selected program is then executed as a child process. The use of an argument list rather than `shell=True` prevents conventional shell metacharacter injection. However, the child process receives `os.environ.copy()`, which forwards every environment variable accessible to the parent process. This may include unrelated secrets such as: - `DEEPSEEK_API_KEY` - `TELEGRAM_BOT_TOKEN` - Cloud-provider credentials - CI/CD access tokens - Database credentials - Other API keys sto ...[truncated 2240 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (54)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/daily_article.py (reported line 129)May include surrounding context.

python
n(config_file, 'r', encoding='utf-8') as f:
                user_config = json.load(f)
                default_config.update(user_config)
        except Exception as e:
            logging.warning(f"读取配置文件失败: {e}")
    
    return default_config


def send_telegram(message: str) -> bool:
    """发送 Telegram 消息"""
    try:
        import requests
        
        bot_token = os.environ.get('TELEGRAM_BOT_TOKEN')
        chat_id = os.environ.get('TELEGRAM_CHAT_ID')
        
        if not bot_token or not chat_id:
            logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
            return False
        
        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        data = {
            'chat_id': chat_id,
            'text': message,
            'parse_mode': 'HTML',
            'disable_web_page_preview': True
        }
        
        response = requests.post(url, data=data, timeout=30)
        result = response.json()

Tainted flow: 'url' from os.environ.get (line 136, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/daily_article.py (reported line 144)May include surrounding context.

python
'disable_web_page_preview': True
        }
        
        response = requests.post(url, data=data, timeout=30)
        result = response.json()
        
        if result.get('ok'):

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/daily_article_final.py (reported line 455)May include surrounding context.

python
}).encode()

        req = urllib.request.Request(url, data=data, method="POST")
        with urllib.request.urlopen(req, timeout=30) as response:
            result = json.loads(response.read().decode())
            if result.get("ok"):
                print("   ✅ Telegram 推送成功")

Tainted flow: 'req' from os.environ.get (line 561, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/daily_article_v55.py (reported line 562)May include surrounding context.

python
}).encode()

        req = urllib.request.Request(url, data=data, method='POST')
        with urllib.request.urlopen(req, timeout=30) as response:
            result = json.loads(response.read().decode())
            if result.get('ok'):
                print('   ✅ Telegram 推送成功')

Tainted flow: 'DEEPSEEK_API_KEY' from os.environ.get (line 17, credential/environment) → httpx.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/deep_gen.py (reported line 75)May include surrounding context.

python
try:
        logger.info(f"调用 DeepSeek API 生成文章深度解读(OpenClaw版):{title}")
        resp = httpx.post(
            f"{DEEPSEEK_BASE_URL}/chat/completions",
            headers={
                "Authorization": f"Bearer {DEEPSEEK_API_KEY}",

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation truly performs undeclared state tracking, cache writes, and broader corpus handling than advertised, then the skill is materially more capable than stated. Undeclared persistence and outbound delivery increase the risk of unintended data retention, privacy issues, and trust erosion, especially for an automated daily task.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill for daily Mao anthology article delivery with AI interpretation, Obsidian document generation, and Telegram pushing. This file instead presents itself as a quote-image generator and its code loads quotes, builds image prompts, and invokes an external image-generation script, which is materially different from article selection/publishing behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script dynamically searches for and executes another skill's script from several user-writable locations, including an environment-variable-controlled path. This creates a trust-boundary violation: if an attacker can place or replace generate_image.py in one of those locations, this script will execute untrusted code under the current user's privileges.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
88% confidence
Finding

The script copies the entire parent environment and passes it to a separately located script that may be untrusted. This can leak unrelated secrets, tokens, proxy settings, and credentials from the current environment to that child process, expanding the blast radius if the invoked script is malicious or compromised.

Content

Scanner excerpt · scripts/generate_daily.py (reported line 105)May include surrounding context.

python
print(f"🎨 提示词: {prompt[:80]}...")

    output_file = output_dir / f"{today}.png"
    env = os.environ.copy()
    env["SEEDREAM_API_KEY"] = api_key

    cmd = [

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly states that the skill will automatically push generated content to Telegram and write files into an Obsidian directory, but it does not clearly warn users about external data transmission, persistent local writes, or the sensitivity of configured paths and chat destinations. In an automation skill, this can cause users to enable outbound delivery and filesystem writes without understanding where content is stored or sent, increasing the risk of unintended disclosure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill manifest declares required binaries, env vars, and dependent skills, but does not explicitly declare tool scope or permissions despite documented behavior involving shell execution, local file reads/writes, and outbound network access to Telegram. This creates a transparency and least-privilege problem: users and platforms cannot accurately assess or constrain what the skill is allowed to do before execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The phrase '强制进行一次高强度认知重启' describes the skill in terms of forcing a particular mental or ideological experience on the user. This natural-language framing does not offer user choice or opt-in and can be interpreted as violating organizational expectations around user autonomy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file repeatedly labels sections as English (title_en, background_en, 启示_en, etc.) while still providing Chinese-only content, effectively forcing one language/locale for all users. Under the policy, language constraints should be optional, user-selectable, or clearly justified; that is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level natural-language description is entirely in Chinese and presents the script as a Chinese-language experience without indicating any language choice or opt-in. Under the stated policy, forcing a specific language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/daily_article.py (reported line 136)May include surrounding context.

python
logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
            return False
        
        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        data = {
            'chat_id': chat_id,
            'text': message,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/daily_article_final.py (reported line 446)May include surrounding context.

python
logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
            return False
        
        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        data = {
            'chat_id': chat_id,
            'text': message,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code defines the skill as a Chinese-only daily push system and its generated content, CLI descriptions, and status output are written in Chinese by default. The policy explicitly disallows forcing a specific language or locale unless the user is given a choice or the constraint is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.