Back to skill

Security audit

Ai Intelligent Customer Segmentation

Security checks for vulnerabilities and agentic risk

Overview

The skill has a clear customer-segmentation purpose, but its install steps run unaudited code and dependencies from a mutable GitHub repository.

Review the referenced GitHub repository and its dependencies before installing, prefer a pinned commit or signed release, run it in a virtual environment or sandbox without unnecessary secrets, and confirm your customer-data use complies with privacy, consent, retention, and anti-discrimination requirements.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:39
Finding

Mutable Remote Payload Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39-42
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: High

Vulnerable Code:

bash
git clone https://github.com/openclaw-skills/ai-intelligent-customer-segmentation
cd ai-intelligent-customer-segmentation
pip install -r requirements.txt
python app.py

Technical Analysis

The installation instructions retrieve an external Git repository without pinning it to a reviewed commit, signed tag, or integrity-verified release. They subsequently execute app.py from that repository. Neither app.py nor the remote repository's dependency manifest is included in the audited artifact.

Consequently, the effective executable payload can change after this skill package has been reviewed. Whoever controls or compromises the referenced repository can modify the default branch and cause later installations to execute different code. The submitted artifact contains no directly embedded malicious payload, but its documented workflow crosses the audit boundary by obtaining and executing mutable remote code.

Attack Path

  1. An attacker compromises the referenced repository or gains authority to modify its default branch.
  2. The attacker adds malicious behavior to app.py or another imported module.
  3. A user or agent follows the installation commands in SKILL.md.
  4. git clone retrieves the attacker-controlled revision without commit or integrity verification.
  5. python app.py executes the changed payload.
  6. The payload operates with the permissions and environmental access of the invoking user.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the invoking user's account. Depending on that account's privileges and environment, the payload could read or alter accessible files, access environment variables and credentials, initiate network connections, or tamper with local ...[truncated 176 chars]

Remediation
View remediation

Remediation Suggestions

  • Include the complete executable implementation in the skill package so it is covered by review.
  • If remote retrieval is necessary, pin the repository to a specific reviewed commit hash rather than a mutable branch.
  • Distribute signed, versioned releases and verify cryptographic signatures or checksums before execution.
  • Require an explicit review step between downloading the repository and running any code.
  • Execute the application in an isolated, least-privileged environment without unnecessary credentials, filesystem access, or network permissions.
  • Document the exact reviewed source revision in both SKILL.md and skill.json.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:39
Finding

Installation of Unavailable and Unverified Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39-42
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

bash
git clone https://github.com/openclaw-skills/ai-intelligent-customer-segmentation
cd ai-intelligent-customer-segmentation
pip install -r requirements.txt
python app.py

Technical Analysis

The workflow directs users to install Python packages from a requirements.txt file located in a separately downloaded repository. That manifest is absent from the audited project, so its package names, versions, indexes, hashes, transitive dependencies, and installation hooks could not be examined.

The command does not demonstrate hash verification or use of a reviewed lock file. Python package installation can execute package build or installation logic, meaning a malicious or compromised dependency may run code during pip install, before app.py starts. The available files do not prove that any dependency is currently malicious; the vulnerability is the unverified and unauditable dependency installation path.

Attack Path

  1. An attacker modifies the remotely hosted requirements.txt, compromises a listed package, or introduces a malicious package through an unsafe dependency source.
  2. A user clones the repository and runs the documented pip install -r requirements.txt command.
  3. pip resolves and downloads the attacker-controlled package or package version.
  4. Malicious build or installation logic executes during installation, or malicious package code executes when imported by the application.
  5. The package gains access to resources available to the invoking Python or pip process.

Impact Assessment

Exploitation could result in arbitrary code execution with the invoking user's privileges. Accessible source files, application data, environment variables, credentials, and network resources may be exposed or modified. The audited a ...[truncated 140 chars]

Remediation
View remediation

Remediation Suggestions

  • Include the dependency manifest and lock file in the audited artifact.
  • Pin every direct and transitive dependency to an exact reviewed version.
  • Use a hash-locked installation process, such as a generated requirements file containing hashes and installation with pip --require-hashes.
  • Use only trusted package indexes and explicitly configure permitted sources.
  • Scan dependencies for known vulnerabilities and malicious or typosquatted packages before release.
  • Install dependencies inside a dedicated virtual environment or sandbox using a non-privileged account.
  • Prevent dependency installation scripts from accessing unnecessary secrets, files, and network resources.
  • Re-audit dependencies whenever the lock file or remote implementation changes.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly targets customer segmentation, profiling, and precision marketing, which inherently involve personal data processing and behavioral analysis, yet the description provides no warnings about privacy, lawful basis, consent, or downstream misuse risks. In this context, omission of handling guidance can lead users to deploy profiling workflows without adequate safeguards, increasing the chance of privacy violations, discriminatory targeting, or noncompliance with data protection requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing natural-language content in the skill description is presented only in Chinese, with no indication that users can select another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. This may conflict with language or locale choice expectations under the policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description is entirely in Chinese ('AI 客户分层 - RFM分析、精准营销'), which suggests the skill may be presented or operated in a fixed language. The file does not indicate any user language choice or explain that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.