Back to skill

Security audit

Ai Intelligent Knowledge Qa

Security checks for vulnerabilities and agentic risk

Overview

This looks like a knowledge-Q&A skill, but it asks users to install and run unpinned external code and does not clearly explain sensitive data handling.

Install only after reviewing the external repository, pinning it to a trusted commit, and inspecting its requirements and app entry point. Run it in an isolated environment and avoid providing sensitive documents, customer data, or API keys until data flows, retention, and access controls are documented.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:43
Finding

Unpinned Remote Repository Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–46
Vulnerability Type: Unverified remote payload retrieval and insecure dependency installation
Risk Level: High

Vulnerable Code Snippet:

bash
git clone https://github.com/openclaw-skills/ai-intelligent-knowledge-qa
cd ai-intelligent-knowledge-qa
pip install -r requirements.txt
python app.py

Technical Analysis

The project contains only SKILL.md; the application source, dependency manifest, and executable entry point are not included in the audited artifact. The installation instructions instead direct users to clone a mutable external Git repository, install the dependencies specified by that repository, and execute its app.py.

The repository is not pinned to a reviewed commit or immutable release. No checksum, cryptographic signature, or other integrity verification is required before execution. The effective application payload can therefore change after this Skill has been reviewed.

Running pip install -r requirements.txt also delegates trust to dependencies selected by the remote repository. Python package installation can execute package build or installation hooks. Because neither the remote requirements.txt nor its resolved dependency set was present in the audited artifact, their safety, version pinning, and package sources could not be verified.

Attack Path

  1. An attacker compromises the referenced GitHub repository, gains control of a dependency, or causes a malicious update to be accepted upstream.
  2. The attacker modifies app.py, requirements.txt, or another imported file to contain attacker-controlled code.
  3. A user follows the documented installation procedure without receiving any warning that the retrieved content differs from the version originally reviewed.
  4. pip install -r requirements.txt may execute malicious package installation hooks.
  5. python app.py executes the remotely supplied ap ...[truncated 785 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the complete application source and dependency manifest in the Skill package so the executed implementation is part of the reviewed artifact.
  2. If remote retrieval is unavoidable, pin the repository to a specific reviewed commit hash rather than cloning the mutable default branch.
  3. Verify downloaded content using a trusted cryptographic signature or a securely distributed checksum before installation or execution.
  4. Pin every Python dependency to an exact version and use a lock file containing package hashes, such as hashes enforced through pip --require-hashes.
  5. Restrict dependency installation to trusted package indexes and review transitive dependencies for dependency-confusion and typosquatting risks.
  6. Separate retrieval, verification, installation, and execution into explicit steps. Do not automatically execute newly downloaded code.
  7. Run the application under a dedicated, least-privileged account or isolated container with minimal filesystem, credential, and network access.
  8. Document all required permissions, external services, network destinations, and sensitive configuration before users execute the application.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises AI Q&A, semantic retrieval, GPT integration, and multi-channel access, but provides no warning about what user data may be collected, transmitted to third-party AI providers, stored in vector databases, or exposed across channels. In a knowledge-QA system, users may submit sensitive internal documents, customer data, or personal information, so missing privacy and data-handling guidance can lead to unintentional disclosure or non-compliant processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The visible natural-language content in the description and documentation is entirely in Chinese, and the file does not indicate that this language choice is optional or limited to a region-specific use case. This can violate a language/locale policy when users are not given an explicit choice or justification for the enforced language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.