Back to skill

Security audit

Ai Intelligent Defect Detection

Security checks for vulnerabilities and agentic risk

Overview

The skill describes a defect-detection app, but its install instructions fetch and run mutable remote code that is not included in the reviewed artifact.

Review before installing. Only run this skill's install commands if you trust the external GitHub repository and its Python dependencies, or after pinning the repository to a reviewed commit and using a sandbox or virtual environment with limited filesystem and credential access.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:42
Finding

Unpinned Remote Payload Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 42–45
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
git clone https://github.com/openclaw-skills/ai-intelligent-defect-detection
cd ai-intelligent-defect-detection
pip install -r requirements.txt
python app.py

Technical Analysis

The installation instructions clone the default branch of an external Git repository without pinning it to a reviewed commit, tag digest, or cryptographically verified artifact. They then install dependencies selected by the remote requirements.txt and execute the remote app.py.

The local package contains only SKILL.md and skill.json; it does not include the advertised application implementation, app.py, or requirements.txt. Consequently, the code ultimately installed and executed is outside the audited artifact and can change after review. A compromise of the repository, its maintainers, or its dependencies could therefore replace the effective payload without modifying this Skill package.

Attack Path

  1. An attacker gains control of, or contributes malicious content to, the referenced repository or one of its dependencies.
  2. The attacker modifies the default branch, requirements.txt, app.py, or a transitively installed package.
  3. A user or agent follows the documented installation instructions.
  4. git clone retrieves the attacker-controlled revision.
  5. pip install -r requirements.txt installs remotely selected packages and may run package build or installation logic.
  6. python app.py directly executes the retrieved application code with the invoking user's privileges.

Impact Assessment

Successful exploitation permits arbitrary code execution under the account running the commands. The payload could read or alter files accessible to that account, access environment variables and credentials, make network requests, tamper with project data, or ...[truncated 235 chars]

Remediation
View remediation

Remediation Suggestions

  • Package the reviewed implementation and required resources directly within the Skill artifact.
  • If remote retrieval is unavoidable, pin the repository to an immutable, reviewed commit hash rather than cloning a mutable default branch.
  • Verify downloaded content using an expected cryptographic hash or trusted signature before installation or execution.
  • Pin every Python dependency to an exact version and require hashes, such as through a lock file and pip install --require-hashes.
  • Review direct and transitive dependencies and use trusted package indexes explicitly.
  • Avoid immediately executing newly downloaded code. Separate retrieval, verification, installation, and execution into distinct approval steps.
  • Run the application in a least-privilege sandbox or container with restricted filesystem access, credentials, and outbound networking.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The provided skill context says this skill is for '缺陷检测,表面缺陷 + 质量检测', but the manifest description at L4 is only the generic text 'AI intelligent ai-intelligent-defect-detection'. This does not describe the concrete defect-detection/quality-inspection behavior the skill claims to provide, creating a semantic mismatch between declared purpose and manifest behavior description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown contains the core skill name/description content in Chinese only, including the top-level description and section content, with no indication that users may choose another language. Per the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description only says "AI intelligent ai-intelligent-defect-detection," which does not clearly indicate when this skill should be invoked or what user requests it is meant to handle. This lack of specificity can cause overly broad or unintended activation because there are no constraints, examples, or exclusions describing the intended trigger context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.