Back to skill

Security audit

Openclaw封装Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent crawler-to-Feishu purpose, but it ships sensitive credentials, stores session cookies unsafely, and exposes a command-injection path from search text.

Do not install this version in a real workspace without remediation. Rotate the Feishu app secret, revoke the bundled Xiaohongshu session, remove cookie.txt and hardcoded chat IDs from the package, replace shell exec with argument-based process spawning, and require an explicit, validated destination before posting search results or login QR screenshots.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:89
Finding

Shell Command Injection Through an Attacker-Controlled Search Keyword

Content
View full analysis
{ const cmd = `"${this.pythonEnv}" "${this.pythonScript}" "${command}"`; exec(cmd, { cwd: __dirname, encoding: 'utf8', timeout: 120000, maxBuffer: 1024 * 1024 * 10 }, (error, stdout, stderr) => { if (error) { resolve({ success: false, error: stderr || error.message }); } else { resolve({ success: true, output: stdout }); } }); }); } ``` ### Technical Analysis The search keyword originates from an incoming OpenClaw message and is directly interpolated into a command string passed to Node.js `child_process.exec()`. The `exec()` function invokes a system shell, so embedded shell syntax is interpreted rather than treated solely as a Python argument. Wrapping the value in double quotes is not a sufficient defense. POSIX shells still process command substitution inside double quotes, and platform-specific metacharacters or quoting rules may allow argument termination and command injection on Windows. No allowlist, escaping routine, or control-character validation is applied before shell execution. This behavior exceeds the privileges required to run the crawler. The Skill only needs to launch a fixed Python interpreter with a fixed script and one data argument; it does not require a shell. ### Attack Path 1. An attacker gains permission to submit a `run-xhs` message through a Feishu group ...[truncated 1201 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
cookie.txt:1
Finding

Authenticated Xiaohongshu Session Credentials Distributed in Plaintext

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
config.py:88
Finding

Hardcoded Feishu Application Secret Exposes Tenant API Access

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
example_openclaw_skill.py:17
Finding

Search Data and Login QR Screenshots Can Be Sent to a Hardcoded Feishu Group

Content
View full analysis
dict: target_chat = chat_id or FEISHU_CHAT_ID bot = FeishuAppBot() bot.send_text_to_chat( target_chat, f"Searching Xiaohongshu keyword: {keyword}" ) manager = CookieManager() cookie = await manager.ensure_valid_cookie(target_chat) results = await search_with_browser(keyword, max_notes=5) bot.send_notes_summary(target_chat, keyword, results) ``` When login is required, `auto_login_with_qrcode.py`, lines 160-176, uses the same destination: ```python self.bot.send_text_to_chat( self.chat_id, "The Xiaohongshu cookie has expired. Scan the following login image." ) success = self.bot.send_image_to_chat( self.chat_id, self.qr_code_path ) ``` ### Technical Analysis If the caller does not explicitly supply a chat ID, the Skill falls back to a concrete group identifier bundled by the developer. This creates a cross-context disclosure risk: the destination is not derived from or cryptographically bound to the invoking conversation. The declared functionality requires returning crawler results to Feishu, but it does not require sending them to a developer-selected fixed group. The problem is particularly sensitive because the same destination receives a login QR screenshot when authentication expires. A login QR image is time-limited authentication material. Sending it to a group with unintended members may allow another member to initiate or interfere with the login flow. ### Attack Path 1. A user or integration invokes the Skill without an explicit `chat_id`. 2. `xhs_search_skill()` chooses the hardcoded group ID. 3. The Skill sends the ...[truncated 904 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
cookie_manager.py:113
Finding

Browser Session Cookies Are Exported to a Predictable Plaintext File

Content
View full analysis
Optional[str]: async with async_playwright() as p: browser = await p.chromium.launch_persistent_context( user_data_dir=str(self.user_data_dir), headless=True, args=["--no-first-run", "--no-default-browser-check"], ) page = await browser.new_page() await page.goto("https://www.xiaohongshu.com", timeout=30000) await page.wait_for_timeout(2000) cookies = await browser.cookies() await browser.close() cookie_str = "; ".join( [f"{c['name']}={c['value']}" for c in cookies] ) self.save_cookie(cookie_str) return cookie_str def save_cookie(self, cookie_str: str): try: self.cookie_file.write_text(cookie_str, encoding="utf-8") log.info(f"Cookie saved to: {self.cookie_file}") except Exception as e: log.error(f"Cookie save failed: {e}") ``` The destination is configured in `config.py`, lines 18-19: ```python COOKIE_FILE = BASE_DIR / "cookie.txt" ``` ### Technical Analysis The code exports all cookies visible to the persistent browser context and writes them as an unencrypted string to a predictable path inside the Skill directory. It does not explicitly create the file with owner-only permissions, encrypt the content, limit the exported cookie set, or perform atomic secure replacement. Although the browser profile is dedicated to Xiaohongshu, duplicating bearer credentials outside the browser's protected profile increases the attack surface. Package tools, backups, local indexing, other processes, and accidental source-control commits can all capture the file. This risk is demonstrated concretely by the populated `cookie.txt` included in the audited pack ...[truncated 912 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Third-Party Dependencies and Browser Artifacts Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (40)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
**注意**:`path` 应该指向 Skill 文件夹,而不是 `index.js` 文件。

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file hard-codes a Feishu application ID and secret directly in source code, which exposes sensitive credentials to anyone with repository or artifact access. If these credentials are valid, an attacker could reuse them to impersonate the application, access Feishu-integrated resources, or abuse the tenant's API quota and trust relationships.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation exposes a hardcoded Feishu App ID and App Secret directly in example configuration blocks. Even in documentation, publishing live-looking secrets can enable unauthorized use of the Feishu application, token minting, bot abuse, or access to connected organizational resources if the credentials are real or reused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation states that login QR codes and scraped Xiaohongshu results are sent to a Feishu group, but it does not clearly warn users that group members may see authentication-related material and search outputs. In this context, broadcasting login prompts and collected content to a shared chat can expose account activity, operational data, and potentially sensitive searches to unintended recipients.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation mentions automatic cookie checking, saving, and reuse, but does not explicitly warn that Xiaohongshu login cookies are stored locally and reused for future authenticated access. Stored session cookies are sensitive credentials; if mishandled, copied, or retained without user awareness, they can enable unauthorized account access and expand the blast radius of compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code captures a screenshot of the login page and sends it to Feishu, which transmits page content off-host to an external chat system. Even if the intent is operational convenience, the screenshot may include more than just the QR code, such as account hints, UI state, or other sensitive page content, creating an unnecessary data exposure channel.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The accept-language header forces zh-CN/zh preferences, which is a natural-language locale choice embedded in the skill. The file does not indicate that this is optional, user-configurable, or required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code extracts all browser cookies from a persistent profile and writes them to disk as a plain-text cookie string, which can expose active authentication tokens if the file, logs, host, or process environment are later compromised. In skill context, this is more dangerous because the module is explicitly designed to harvest and reuse login state for Xiaohongshu, making session hijacking and account takeover a realistic consequence rather than a theoretical one.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill sends search-related content to a Feishu chat via bot messaging without any explicit notice or consent flow in this file. If a user submits sensitive keywords or if results contain personal or confidential information, the skill can disclose that data into a group chat or external messaging system unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill forwards user-provided keywords to an external browser-based search function without clearly informing the user that their input is being sent to a third-party service. This creates a privacy and data-handling risk, especially if users enter internal project names, personal data, or other sensitive terms assuming processing is local.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · feishu_app_bot.py (reported line 70)May include surrounding context.

python
url = "https://open.feishu.cn/open-apis/auth/v3/tenant_access_token/internal"
        
        try:
            response = requests.post(
                url,
                json={
                    "app_id": self.app_id,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill transmits text and note summaries to an external SaaS platform, which is expected for a messaging bot but still represents data egress. In a skill setting, lack of explicit disclosure and data-classification checks can lead to accidental sharing of sensitive content, especially when summaries may include links, author names, or other scraped data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · feishu_app_bot.py (reported line 124)May include surrounding context.

python
"content": json.dumps({"text": text})
            }

            response = requests.post(
                url,
                headers=headers,
                params=params,

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · feishu_app_bot.py (reported line 189)May include surrounding context.

python
"content": json.dumps({"text": text})
            }

            response = requests.post(
                url,
                headers=headers,
                params=params,

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · feishu_app_bot.py (reported line 295)May include surrounding context.

python
"content": json.dumps({"text": text})
            }

            response = requests.post(
                url,
                headers=headers,
                params=params,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code reads a local file and uploads its contents to Feishu without any user-facing disclosure or consent checkpoint. In an agent environment, this can cause inadvertent exfiltration of local sensitive files if the image path is influenced by external input or if users do not realize data leaves the host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The module includes a chat enumeration capability that lists all chats available to the bot, which expands access to organizational metadata beyond the narrow need of sending a message to a known chat. In agent-skill contexts, such discovery functions can facilitate unintended reconnaissance, privacy leakage, or misuse of broader bot permissions if exposed to untrusted callers.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · feishu_bot.py (reported line 206)May include surrounding context.

python
"""
        try:
            headers = {"Content-Type": "application/json"}
            response = requests.post(
                self.webhook_url,
                headers=headers,
                json=payload,

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file-based fallback for loading the webhook URL cannot work as written because Path is used without being imported. This can cause the bot to fail when the environment variable is absent, which may break alerting or monitoring workflows and suppress expected outbound notifications during operational failures.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill indicates that search results are sent to a Feishu group, but at execution time it only says the search is starting and does not obtain explicit consent for external sharing. This can leak searched terms or collected content to a group context, which is a privacy and data-handling issue, especially for sensitive queries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill invokes a subprocess via child_process.exec using values derived from configuration and user-controlled input. Although the Python script path is fixed, both pythonEnv and the command string are interpolated into a shell command, creating command-injection risk and expanding the skill's capabilities beyond simple message handling into arbitrary process execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and all user-facing prompts are written only in Chinese, which imposes a specific language on users without any opt-in or alternative. The policy for this audit flags language or locale constraints when they are forced rather than user-selectable or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file's docstrings, log messages, returned field names, and CLI output are all hard-coded in Chinese, indicating the skill is designed to operate in a single language without any user opt-in or locale selection. The policy for this audit flags language-forcing behavior when no explicit choice or documented justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill automates scraping Xiaohongshu content and, when cookies expire, sends login QR screenshots to a Feishu group, but the overview does not clearly warn users about this data flow. This creates privacy and operational risk because search terms, scraped content, and authentication-related images may be disclosed to unintended group members or retained in chat history without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing natural language entirely in Chinese, including the package description and usage guidance. Because the skill does not offer a language choice or document that it is intentionally limited to Chinese-speaking users, it may violate a language/locale policy requiring user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:124