Back to skill

Security audit

雄韬B2B数字化基因诊断

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a B2B diagnosis/reporting purpose, but it uses broad auto-activation, mandatory branding, persistent unpinned software installation, and unsafe report-generation instructions that need review before use.

Review this skill before installing in any sensitive environment. Only use it if you accept XTOCN-branded outputs, persistent Playwright/Chromium installation, local report files in the working directory, and the need to sanitize company names and report text before PDF generation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:478
Finding

Mandatory Third-Party Branding and Promotional Output Hijacking

Content
View full analysis
雄韬XTOCN
B2B企业数字化诊断报告
{{COMPANY_NAME}}
{{DATE}}
能力型专注
``` ```html
雄韬XTOCN | www.xtocn.com | 本报告由AI辅助生成,仅供参考
``` `templates/report-style.css:1-10`: ```css /* 雄韬XTOCN B2B数字化诊断报告 - 通用样式 */ @page { size: A4; margin: 20mm 18mm; @top-center { content: "雄韬XTOCN | B2B企业数字化诊断报告"; font-size: 9pt; color: #999; font-family: "Microsoft YaHei", "PingFang SC", sans-serif; } ``` ### Technical Analysis The Skill changes the Agent's presented identity to an XTOCN-branded assistant and mandates insertion of ...[truncated 1859 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:349
Finding

Unpinned Global Installation of Executable Playwright and Chromium Dependencies

Content
View full analysis
本 Skill 会自动安装 Playwright 命令行工具。首次生成 PDF 时,还需要下载一次 Chromium 浏览器内核(约180MB),仅需一次,后续秒出。 **自动安装链路:** 1. OpenClaw 平台根据 `metadata.install` 自动执行 `npm install -g playwright` → 获得 `playwright` CLI 命令 2. 首次生成 PDF 时,Skill 检测 Chromium 是否已下载,如未下载则自动执行 `npx playwright install chromium` 3. Chromium 就绪后,HTML → PDF 渲染秒级完成 **Agent 执行时按以下逻辑:** ``` 检查 npx playwright --version ├─ 未安装 → 提示用户"Playwright 正在安装中...",执行 npm install -g playwright └─ 已安装 → 继续 检查 Chromium 内核是否存在(检查 $LOCALAPPDATA/ms-playwright/chromium-*/chrome-win64/chrome.exe) ├─ 不存在 → 提示用户"首次使用需下载浏览器内核(约180MB),仅此一次..." │ 执行 npx playwright install chromium │ ├─ 成功 → 继续渲染 │ └─ 失败(网络问题)→ 走降级方案:提示用户用浏览器打开 HTML 手动打印 PDF └─ 已存在 → 直接渲染 PDF ``` ``` Package metadata at `SKILL.md:4`: ```yaml metadata: { "openclaw": { "emoji": "🏭", "requires": { "anyBins": ["npx"] }, "install": [{ "id": "playwright", "kind": "node", "formula": "playwright", "bins": ["playwright"], "label": "安装 Playwright (PDF渲染引擎)" }] } } ``` ### Technical Analysis The Skill installs the package named `playwright` globally without a version constraint, lockfile, integrity hash, or provenance check. It subsequently uses that mutable package to download a Chromium binary. Because the dependency is not pinned, two executions at different times can retrieve different executable code even though the audited project remains unchanged. A compromised package release, registry, mirror, DNS path, account, or package-manager configuration could therefore alter the effective runtime payload. Global installation unnecessarily increases scope by modifying the host's shared Node.js envi ...[truncated 1347 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:388
Finding

Command and Path Injection Through User-Controlled Company Names

Content
View full analysis
` HTML - `{{ACTION_LIST}}` → 行动清单的 `
  • ` HTML - 其他行业/问题相关变量 → 根据诊断内容填充 - 删除未使用的条件块(如 `{{#TIEBREAKER}}...{{/TIEBREAKER}}`) 3. 写入文件:`{当前工作目录}/B2B数字化诊断报告-{企业名称}-{日期}.html` ``` `SKILL.md:423-432`: ```markdown **第4步:渲染 PDF** ```bash npx playwright pdf "file:///{当前工作目录绝对路径}/B2B数字化诊断报告-{企业名称}-{日期}.html" "{当前工作目录绝对路径}/B2B数字化诊断报告-{企业名称}-{日期}.pdf" ``` 注意: - HTML 路径必须使用 `file:///` 协议 + 绝对路径 - Windows 路径中的反斜杠需要替换为正斜杠 - 路径中的空格和中文字符无需转义 ``` ### Technical Analysis The Skill explicitly obtains the company name from the user, embeds it in output filenames, and then incorporates those filenames into a shell command. It defines no validation, allowlist, normalization, or containment check. Double quotes are not a complete defense against shell injection. In common POSIX shells, command substitution such as `$(command)` and backtick substitution remain active inside double-quoted strings. PowerShell has its own interpolation and metacharacter behavior. Path separators and traversal elements can also redirect output outside the intended working directory. The risk exists because the instructions encourage constructing a command string and executing it through a shell rather than passing fixed arguments directly to a process API. ### Attack Path 1. An attacker provides a crafted company name containing shell substitution, metacharacters, path separators, or traversal sequences. 2. The Skill copies that value into the HTML and PDF filenames. 3. The Agent builds the documented `npx playwright pdf ...[truncated 1051 chars]
  • Remediation
    View remediation

    T09 · Insecure Skill Coding Practices

    Warning
    Location
    templates/report-ability.html:3
    Finding

    Raw HTML Injection in Locally Rendered Reports

    Content
    View full analysis
    ` HTML - `{{ACTION_LIST}}` → 行动清单的 `
  • ` HTML - 其他行业/问题相关变量 → 根据诊断内容填充 - 删除未使用的条件块(如 `{{#TIEBREAKER}}...{{/TIEBREAKER}}`) ``` Representative sinks from `templates/report-ability.html:3-40`: ```html B2B企业数字化诊断报告 - {{COMPANY_NAME}} .tag-ability { background: #e3f2fd; color: #0d47a1; display:inline-block;padding:3px 10px;border-radius:3px;font-weight:700; } .highlight-box { background: #e8f0fe; border:1px solid #90caf9; padding:14px 18px; border-radius:4px; margin:12px 0; }
    雄韬XTOCN
    B2B企业数字化诊断报告
    {{COMPANY_NAME}}
    {{DATE}}
    能力型专注
    一、诊断结论
    🏭 能力型专注
    3道题得分:能力 {{ABILITY_SCORE}}分 | 行业 {{INDUSTRY_SCORE}}分 | 问题 {{PROBLEM_SCORE}}分
    选择路径:{{ANSWER_PATH}}
    {{#TIEBREAKER}}决胜题:{{TIEBREAKER_ANSWER}} → {{TIEBREAKER_RESULT}}{{/TIEBREAKER}}
  • Remediation
    View remediation
    Vulnerability Patterns
    • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    Findings (19)

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The skill auto-activates when users mention broad terms like “数字化”, “官网怎么做”, “小程序”, or “怎么做聚焦”, which are common discussion topics and not narrow invocation phrases. The trigger section does not provide exclusion conditions or negative examples to distinguish casual discussion from intentional skill use.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The skill does not clearly and upfront disclose that PDF generation writes files into the current working directory and may install software or download a large browser binary. In a skill that otherwise appears to be a simple diagnosis questionnaire, this weak transparency can lead to uninformed consent and unexpected local side effects.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    For a questionnaire-and-report skill, instructing the agent to install software, download Chromium, copy files, run shell commands, and write artifacts to the working directory is an unnecessary expansion of privileges and attack surface. This increases the chances of unsafe command execution, environmental side effects, and abuse of local resources if the workflow or inputs are manipulated.

    Content

    No source excerpt is available for this finding.

    Rp1

    Medium
    Category
    MCP Rug Pull
    Confidence
    91% confidence
    Finding

    The skill directs the agent to invoke npx playwright without pinning a specific version, which can pull whatever package/version is current at execution time. That creates a supply-chain risk and undermines reproducibility, especially because the command is coupled to software installation and browser-download behavior.

    Content

    No source excerpt is available for this finding.

    Rp1

    Medium
    Category
    MCP Rug Pull
    Confidence
    91% confidence
    Finding

    This unpinned npx playwright usage introduces the same supply-chain exposure at a separate execution point in the PDF workflow. If a compromised or incompatible upstream package is resolved, the agent may execute untrusted code during install or runtime.

    Content

    No source excerpt is available for this finding.

    Rp1

    Medium
    Category
    MCP Rug Pull
    Confidence
    91% confidence
    Finding

    The skill again relies on npx playwright without version pinning during a workflow that downloads and runs browser tooling. Repeated unpinned runtime resolution increases the chance of non-deterministic behavior and malicious package substitution.

    Content

    No source excerpt is available for this finding.

    Rp1

    Medium
    Category
    MCP Rug Pull
    Confidence
    91% confidence
    Finding

    This PDF-rendering command executes Playwright from npx without an exact version, so the executable code path depends on mutable upstream state. In a skill that writes files and launches headless browser components, that materially increases risk beyond a simple formatting task.

    Content

    No source excerpt is available for this finding.

    Rp1

    Medium
    Category
    MCP Rug Pull
    Confidence
    91% confidence
    Finding

    Another unpinned npx playwright reference appears in the verification/render pipeline, preserving the same supply-chain and reproducibility issues. Because the skill is designed to automate execution, users may not realize they are trusting mutable third-party code each time the workflow runs.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    This markdown file contains user-facing skill content exclusively in Chinese, and there is no indication that the user can opt into another language or that the skill is intended only for a Chinese-language audience. That can violate a language/locale policy requiring neutrality or user choice.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    This markdown skill forces a specific language/locale presentation throughout the document, and there is no indication that users can opt into Chinese or select another language. Under the policy, language-only content without user choice or clear region-specific justification is a natural-language policy violation.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The HTML document hard-codes lang="zh-CN", indicating the skill output is fixed to Simplified Chinese. This is a natural-language/locale policy concern because the template does not provide any user opt-in, locale selection, or justification that the skill is intended only for a China-specific audience.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The HTML root sets lang="zh-CN", indicating the output is fixed to Simplified Chinese. Under the policy rules, forcing a specific language or locale without user opt-in or documented justification is a natural-language policy violation.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    90% confidence
    Finding

    This markdown file presents all user-facing content in a single language without stating that the skill is intended only for Chinese-speaking users or offering any language choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that the language is optional or limited to a justified region-specific audience. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    This markdown file presents all user-facing guidance in Chinese, and there is no indication that the skill is region-specific or that users may choose another language. Under the policy rule for language or locale constraints, forcing a single language without opt-in is a natural-language policy concern.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    90% confidence
    Finding

    This markdown file is entirely written in Chinese and presents the skill content as a fixed-language experience, with no indication that users may choose another language or locale. Under the policy rubric, forcing a specific language without user opt-in is a natural-language policy concern.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    82% confidence
    Finding

    This markdown file contains only Chinese-language content and provides no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The HTML document declares lang="zh-CN", and all visible content in the template is written only in Simplified Chinese. For a general-purpose report template, this constitutes a language/locale constraint without any indication of user opt-in or a documented region-specific justification.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    87% confidence
    Finding

    This stylesheet hardcodes Chinese text in visible report elements, including the header and page numbering, which imposes a specific language/locale on all generated output. The file does not indicate that the skill is China-specific or that users can opt into another language, so this may violate language/locale policy expectations.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.