Back to skill

Security audit

Ai Intelligent Live Streaming Assistant

Security checks for vulnerabilities and agentic risk

Overview

The skill describes plausible livestream-assistant behavior, but it asks users to run unreviewed code from a mutable remote repository and under-discloses platform automation and data handling.

Review the remote repository before running the install commands, prefer a pinned commit and isolated virtual environment or container, and only connect livestream accounts after understanding what chat, gift, replay, and analytics data the app can access or modify.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:39
Finding

Unpinned Remote Payload and Dependency Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39–42
Vulnerability Type: Remote payload retrieval and insecure dependency execution
Risk Level: Medium

Complete Code Snippet:

bash
git clone https://github.com/openclaw-skills/ai-intelligent-live-streaming-assistant
cd ai-intelligent-live-streaming-assistant
pip install -r requirements.txt
python app.py

Technical Analysis

The documented installation procedure clones a mutable external Git repository without specifying a reviewed commit hash or immutable release tag. It then installs dependencies from a remote-controlled requirements.txt and executes app.py.

Neither requirements.txt nor app.py is included in the audited package. Their contents therefore could not be reviewed, and the effective payload is determined by the external repository at installation time. Changes to that repository after this audit would directly change the code and dependencies executed by users.

The dependency installation also lacks version and integrity controls in the reviewed instructions. There is no evidence of pinned package versions, cryptographic hashes, lock-file verification, or provenance validation. This creates a supply-chain exposure in addition to the mutable remote-code risk.

Attack Path

  1. An attacker compromises the referenced repository, a maintainer account, or the repository's dependency manifest.
  2. The attacker modifies app.py, requirements.txt, or related repository content to introduce a malicious payload.
  3. A user follows the installation instructions and clones the repository's current state.
  4. pip install -r requirements.txt installs attacker-controlled or substituted dependency code, potentially running package build or installation hooks.
  5. python app.py directly executes the remotely supplied application.
  6. The payload operates with the privileges of the user who ran the commands.

Impact Asse

...[truncated 572 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include the complete application source, dependency manifest, and relevant installation scripts in the auditable Skill package.
  2. If remote retrieval is unavoidable, check out an immutable, reviewed commit hash rather than the repository's mutable default branch.
  3. Verify downloaded source using a trusted cryptographic digest or a signed release before installation or execution.
  4. Pin every direct and transitive Python dependency to an approved version and require hashes, such as through a hash-locked requirements file.
  5. Use a reproducible lock file generated from a reviewed dependency set, and continuously scan dependencies for known vulnerabilities and package-name substitution risks.
  6. Separate download, verification, dependency installation, and execution into distinct steps. Do not instruct users to execute newly downloaded code before inspection.
  7. Install and run the application in an isolated virtual environment or container under a dedicated, least-privileged account.
  8. Document the required filesystem, credential, and network permissions so users can restrict the application's execution scope.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises automated replies, moderation-style chat handling, analytics, and auto-clipping, all of which imply processing user-generated content and performing actions on connected platform accounts. Without any disclosure of what data is collected, what actions are automated, platform permission scope, retention, or user/operator controls, users may unknowingly enable behavior that affects third parties or violates privacy and platform expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language description and headings are entirely in Chinese, and the file does not indicate that the skill is intentionally region-specific or provide an opt-in language choice. Per SQP-3, forcing a specific language without user choice can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description only says the skill is an 'AI live streaming assistant' for comment management and data analysis, but provides no specific invocation phrases, scope limits, or exclusion conditions. In a manifest file, this broad wording can contribute to ambiguous activation and unintended matching in general live-streaming contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The description is written only in Chinese and the tags include 'chinese', which suggests the skill may be oriented to a specific language/locale. There is no indication that users can opt into this locale behavior or that the restriction is intentionally limited to a justified region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.