Back to skill

Security audit

Ai Intelligent Cv Platform

Security checks for vulnerabilities and agentic risk

Overview

This skill is not proven malicious, but it asks users to install and run unpinned outside code for a broad computer-vision platform without enough safety or data-handling detail.

Review this skill before installing. Only run it in a constrained environment if you trust the referenced repository and its dependencies, preferably after pinning a specific commit and verifying dependency integrity. Do not rely on its outputs as the sole basis for medical, surveillance, or driving-related decisions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:41
Finding

Mutable Remote Repository Retrieved and Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 41–44
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Medium

bash
git clone https://github.com/openclaw-skills/ai-intelligent-cv-platform
cd ai-intelligent-cv-platform
pip install -r requirements.txt
python app.py

Technical Analysis

The packaged skill contains no local implementation of its advertised computer-vision functionality. Instead, its installation procedure directs users to clone a mutable external Git repository, install dependencies from an unaudited requirements.txt, and execute an unaudited app.py.

The repository is not pinned to an immutable commit, release artifact, or cryptographically verified digest. Consequently, the code executed by a user can differ from the code present when this skill was reviewed. Both Python package installation and application startup are code-execution channels: dependencies may execute build or installation hooks, while python app.py directly runs the retrieved application with the invoking user's privileges.

No malicious payload was present in the audited package, and compromise of the referenced repository or its dependencies was not established. The risk arises from delegating execution to mutable content outside the reviewed artifact and without integrity controls.

Attack Path

  1. An attacker compromises the referenced GitHub repository, gains control of an upstream dependency, or causes a malicious future revision to be published.
  2. The attacker adds malicious behavior to app.py, requirements.txt, or a dependency installation hook.
  3. A user follows the documented instructions and clones the current mutable repository state.
  4. pip install -r requirements.txt executes package installation logic, or python app.py executes the modified application.
  5. The payload runs with the permissions and environment access of the invoking user.

Impact Assessment

Successful exploitation could ...[truncated 448 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include the reviewed application code and dependency manifest directly in the skill package so its effective behavior is covered by the audit.
  2. If external retrieval is unavoidable, pin the repository to a specific immutable commit rather than cloning the mutable default branch.
  3. Verify retrieved content against a trusted cryptographic digest or signed release before installation or execution.
  4. Pin every Python dependency to an exact version and use a lock file containing package hashes, such as hashes enforced through pip --require-hashes.
  5. Obtain packages only from explicitly configured, trusted indexes and review transitive dependencies and installation hooks.
  6. Run the application in a restricted virtual environment or container with minimal filesystem access, no unnecessary credentials, limited network access, and no administrative privileges.
  7. Document the application's required permissions, network destinations, data handling, and model-download behavior.
  8. Add automated dependency, provenance, and source-code scanning to the release process, and repeat the audit whenever the pinned repository revision or dependency lock file changes.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises privacy-sensitive and safety-critical computer vision uses such as security monitoring, medical imaging, and autonomous driving without any warnings, limitations, human-review requirements, or compliance guidance. This can encourage unsafe deployment of imperfect CV outputs in contexts where misclassification, missed detections, or OCR errors could lead to privacy harms, unsafe decisions, or regulatory exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description only says "AI intelligent ai-intelligent-cv-platform," which is broad and nonspecific. In a manifest file, such vague wording can act like an ambiguous trigger or invocation description because it does not clarify the skill's scope, constraints, or when it should be used versus not used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill metadata and documentation are entirely in Chinese, with no indication that another language is available or that Chinese is a required locale. This can violate a language-choice policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.