Back to skill

Security audit

Auto Config Skiller

Security checks for vulnerabilities and agentic risk

Overview

This setup skill is mostly aligned with its stated automation purpose, but it automatically runs mutable remote installers and installs broad unpinned components in ways users should review carefully before use.

Install only in a disposable or low-privilege environment after reviewing each external source. Do not run the automatic setup on a machine with sensitive credentials, and avoid using downloaded persona text as a system prompt unless you have manually reviewed and pinned it. Protect or rotate any API keys entered into the generated .env file.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/diagnose_and_install.py:198
Finding

Automatic Execution of an Unverified Remote Installation Script

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/diagnose_and_install.py:305
Finding

Unverified Remote Persona Downloaded with TLS Validation Disabled

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/diagnose_and_install.py:402
Finding

Unpinned Packages, Skills, and Repository Branches Create a Broad Supply-Chain Risk

Content
View full analysis
>> 提示: 接下来将启动官方飞书工具,如需跳过请 Ctrl+C{Colors.ENDC}") result = subprocess.run(['npx', '-y', '@larksuite/openclaw-lark-tools', 'install'], text=True) ``` ```python result = subprocess.run( ['npx', '-y', 'clawhub@latest', 'install', slug, '--no-input', '--dir', base_dir], capture_output=True, text=True ) ``` Repositories are selected through mutable branches: ```python url = config["url"] tag = config.get("tag", "main") if os.path.exists(target_path): result = subprocess.run( ['git', '-C', target_path, 'pull', 'origin', tag], capture_output=True, text=True ) else: result = subprocess.run( ['git', 'clone', '-b', tag, '--depth', '1', url, target_path], capture_output=True, text=True ) ``` The secondary setup script installs dependency files obtained from cloned repositories: ```bash for name in "${!SKILLS[@]}"; do target_path="${SKILLS_DIR}/${name}" if [ -f "${target_path}/requirements.txt" ]; then echo -e "${BLUE}- 安装 ${name} 的依赖...${NC}" pip3 install -r "${target_path}/requirements.txt" -q fi done ``` ### Technical Analysis `npx -y` can retrieve and execute packages without an interactive package-install confirmation. `clawhub@latest` explicitly selects a mutable release, while the Feishu package has no exact version. Git sources are pinned only to `main` or `master`, both o ...[truncated 1766 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/diagnose_and_install.py:134
Finding

Secrets Are Echoed During Entry and Written Without Explicit Restrictive Permissions

Content
View full analysis
{key}: ").strip() final_config.append(f"{key}={val}\n") # 写入 .env with open(env_path, 'w', encoding='utf-8') as f: f.writelines(final_config) ``` ### Technical Analysis The same visible `input()` mechanism is used for ordinary configuration and secret values such as `FEISHU_APP_SECRET` and `OPENAI_API_KEY`. This causes secret characters to be displayed while entered and may expose them through terminal recording, screen sharing, or observation. The `.env` file is created with ordinary `open()` semantics. Its final permissions depend on the user's process umask, and the code does not enforce owner-only access. The file also stores the secrets in plaintext. No direct network transmission of these values was found in the reviewed project. The confirmed issue is local input and storage security, not credential exfiltration. ### Attack Path 1. A user runs the interactive configuration process. 2. The progr ...[truncated 900 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (45)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/USAGE_GUIDE.md (reported line 55)May include surrounding context.

md
print(f"{Colors.RED}拒绝 (请检查文件夹权限){Colors.ENDC}")

def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 45)May include surrounding context.

python
print(f"{Colors.RED}拒绝 (请检查文件夹权限){Colors.ENDC}")

def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 129)May include surrounding context.

python
print(f"{Colors.RED}拒绝 (请检查文件夹权限){Colors.ENDC}")

def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 179)May include surrounding context.

python
print(f"{Colors.RED}拒绝 (请检查文件夹权限){Colors.ENDC}")

def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup_base_skills.sh (reported line 70)May include surrounding context.

sh
print(f"{Colors.RED}拒绝 (请检查文件夹权限){Colors.ENDC}")

def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup_base_skills.sh (reported line 71)May include surrounding context.

sh
print(f"{Colors.RED}拒绝 (请检查文件夹权限){Colors.ENDC}")

def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 47)May include surrounding context.

python
def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):
        print(f"{Colors.GREEN}已发现{Colors.ENDC}")
    else:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 125)May include surrounding context.

python
def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):
        print(f"{Colors.GREEN}已发现{Colors.ENDC}")
    else:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup_base_skills.sh (reported line 69)May include surrounding context.

sh
def check_env_file():
    print(f"  - .env 配置文件: ", end="", flush=True)
    base_dir = os.path.abspath(os.path.join(os.path.dirname(__file__), ".."))
    env_path = os.path.join(base_dir, ".env")
    if os.path.exists(env_path):
        print(f"{Colors.GREEN}已发现{Colors.ENDC}")
    else:

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This line writes user-supplied secrets into a .env file without applying restrictive permissions or other protections. In a setup assistant, storing API keys in plaintext can lead to credential exposure through local compromise, accidental commits, shared systems, or permissive umasks.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 175)May include surrounding context.

python
val = input(f"  > {key}: ").strip()
        final_config.append(f"{key}={val}\n")

    # 写入 .env
    with open(env_path, 'w', encoding='utf-8') as f:
        f.writelines(final_config)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This workflow executes a remote installer script directly from the network through a shell pipeline without a meaningful safety warning or confirmation. In a setup tool that automatically installs components, this is especially dangerous because it normalizes blind remote code execution for users who may not inspect the source.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
100% confidence
Finding

Fetching a shell script from the internet and piping it directly into bash is a classic high-risk remote code execution pattern. In an automation helper that users may trust to bootstrap environments, this is especially dangerous because compromise of the remote source immediately compromises the host.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 202)May include surrounding context.

python
print_step("正在自动部署 Tencent SkillHub (国内加速源)...")
    try:
        # 使用用户提供的快速安装脚本
        install_cmd = "curl -fsSL https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/install.sh | bash -s -- --no-skills"
        result = subprocess.run(install_cmd, shell=True, text=True)
        if result.returncode == 0:
            print(f"{Colors.GREEN}SkillHub CLI 部署成功{Colors.ENDC}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using subprocess.run with shell=True on a command string that fetches and executes remote content compounds the risk: the shell interprets the pipeline and any environment-sensitive behavior, while the fetched script gains full execution. This is a strong true positive even though the command string is constant, because the tool is being used to perform arbitrary remote-code installation.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 203)May include surrounding context.

python
try:
        # 使用用户提供的快速安装脚本
        install_cmd = "curl -fsSL https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/install.sh | bash -s -- --no-skills"
        result = subprocess.run(install_cmd, shell=True, text=True)
        if result.returncode == 0:
            print(f"{Colors.GREEN}SkillHub CLI 部署成功{Colors.ENDC}")
            # 自动将本地路径加入当前进程环境,确保后续直接调用有效

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The persona downloader suppresses transport verification and silently writes remote content into a local file presented as agent persona material. Because the script later encourages using that content as a system prompt, this becomes a high-risk trust-boundary violation rather than a harmless convenience feature.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The comment says SSL warnings are merely ignored, but the code actually disables both hostname and certificate verification before downloading remote content. That materially weakens transport security and allows man-in-the-middle tampering of files that are then saved for later use in the agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises automated setup, package installation, configuration changes, and network retrieval from external sources without prominently warning users that it will modify the local environment and reach out to third-party services. This is dangerous because users may invoke it expecting guidance only, while it could trigger shell scripts, dependency installs, or repository fetches that alter system state and expand the attack surface.

Content

No source excerpt is available for this finding.

Ssd 2

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The phrase claiming automatic bypass of login restrictions and network barriers is a strong red flag because it normalizes evasion of access controls as a convenience feature. In a skill whose purpose is to fetch and install external content, this could enable unauthorized access paths, unsafe mirrors, or tooling designed to circumvent platform controls, significantly increasing the risk of policy violations and supply-chain compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The guide instructs users to enter Feishu secrets and AI API keys and states that a .env file will be generated automatically, but it gives no warning about secure storage, file permissions, exclusion from version control, or risks of exposing credentials. In a setup assistant that normalizes one-click automation, this increases the chance users will mishandle secrets or leave them in an insecure location.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide normalizes downloading third-party personas and injecting them directly as the agent's system prompt, which gives untrusted external content the highest instruction priority in many agent architectures. This can introduce prompt injection, unsafe tool use directives, data exfiltration instructions, or policy overrides that are hard for end users to detect.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 30)May include surrounding context.

python
print(f"  - 网络连通性 ({host}): ", end="", flush=True)
    try:
        # 使用 ping 测试 (Mac/Linux -c 1)
        subprocess.check_output(['ping', '-c', '1', '-W', '2', host], stderr=subprocess.STDOUT)
        print(f"{Colors.GREEN}畅通{Colors.ENDC}")
        return True
    except:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 57)May include surrounding context.

python
print(f"  - OpenClaw 版本: ", end="", flush=True)
    try:
        # 尝试通过 CLI 获取版本
        result = subprocess.run(['openclaw', '--version'], capture_output=True, text=True)
        version = result.stdout.strip().split('\n')[-1] # 取最后一行
        if version:
            print(f"{Colors.GREEN}{version}{Colors.ENDC}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 72)May include surrounding context.

python
IS_CLAWHUB_LOGGED_IN = False
    try:
        # 探测版本
        result = subprocess.run(['npx', 'clawhub', '--cli-version'], capture_output=True, text=True, timeout=5)
        if result.returncode == 0:
            version = result.stdout.strip().split()[-1]
            # 增加登录状态检测

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 76)May include surrounding context.

python
if result.returncode == 0:
            version = result.stdout.strip().split()[-1]
            # 增加登录状态检测
            login_check = subprocess.run(['npx', 'clawhub', 'whoami'], capture_output=True, text=True)
            if login_check.returncode == 0:
                print(f"{Colors.GREEN}已登录 ({version}){Colors.ENDC}")
                IS_CLAWHUB_LOGGED_IN = True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/diagnose_and_install.py (reported line 110)May include surrounding context.

python
print(f"  - 飞书官方工具栈: ", end="", flush=True)
    try:
        # 探测飞书官方工具包
        result = subprocess.run(['npx', '@larksuite/openclaw-lark-tools', '--help'], 
                             capture_output=True, text=True, timeout=5)
        if result.returncode == 0:
            print(f"{Colors.GREEN}发现并可用{Colors.ENDC}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script interactively collects secrets such as API keys and writes them into a .env file without warning about local secret storage, file permissions, or operational handling. In a setup assistant this increases the chance users expose credentials through weak filesystem protections, backups, logs, or accidental commits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.