Back to skill

Security audit

Chinese Content Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese content-generation CLI skill with expected external API use and no evidence of deception, persistence, or destructive behavior.

Install only if you are comfortable with your prompts and titles being sent to DeepSeek and trend lookup contacting Juejin. Prefer a pinned installer version instead of @latest, and configure a dedicated DeepSeek API key with limited billing exposure.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:30
Vulnerability Type: Insecure dependency installation
Risk Level: Medium

Vulnerable Code

bash
npx clawhub@latest install chinese-content-generator

Technical Analysis

The documented installation command instructs users to download and execute the mutable latest release of the third-party clawhub package. No exact version, package integrity hash, signature verification, or lockfile constrains the code that npx will execute.

Consequently, the effective installation code can change after this Skill has been audited. This creates a supply-chain trust gap: a compromised package publisher, registry account, package release, or upstream distribution channel could cause users following the documentation to execute code that was not part of the reviewed project.

This finding does not establish that the current clawhub package is malicious. The risk arises from executing a mutable, externally supplied dependency without pinning or verification.

Attack Path

  1. An attacker compromises the upstream package publisher, registry account, release process, or another relevant distribution component.
  2. The attacker publishes a malicious release that becomes the package's latest version.
  3. A user follows the installation command in SKILL.md.
  4. npx retrieves and executes the attacker-controlled package release.
  5. The malicious package runs with the privileges and environment available to the user performing the installation.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. Depending on that user's privileges and environment, the malicious dependency could access readable local files and credentials, alter user-owned configuration, install additional components, or make network requests.

The immediate privilege level is normally that of the user invoking npx; ...[truncated 214 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version:
    bash
    npx clawhub@<audited-exact-version> install chinese-content-generator
    
  2. Document the expected package registry and publisher identity so namespace or registry substitution is easier to detect.
  3. Verify package provenance through supported registry signatures, attestations, or an independently published checksum before execution.
  4. Use a lockfile and integrity metadata where the installation workflow supports them.
  5. Review each dependency update before changing the pinned version.
  6. Advise users not to run the installer with administrator or root privileges unless strictly necessary.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding describes undeclared access to ~/.openclaw/.env and api.deepseek.com while the skill claims only benign content-generation features. Hidden credential access plus external transmission substantially increases risk because secrets may be exposed or used without clear authorization.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This finding describes undeclared access to ~/.openclaw/.env and api.deepseek.com while the skill claims only benign content-generation features. Hidden credential access plus external transmission substantially increases risk because secrets may be exposed or used without clear authorization.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding describes undeclared access to ~/.openclaw/.env and api.deepseek.com while the skill claims only benign content-generation features. Hidden credential access plus external transmission substantially increases risk because secrets may be exposed or used without clear authorization.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · generate.js (reported line 13)May include surrounding context.

js
const fs = require('fs');
const path = require('path');

const CONFIG_PATH = path.join(process.env.HOME, '.openclaw', '.env');

function getApiKey() {
  try {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · optimize-title.js (reported line 12)May include surrounding context.

js
const fs = require('fs');
const path = require('path');

const CONFIG_PATH = path.join(process.env.HOME, '.openclaw', '.env');

function getApiKey() {
  try {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
73% confidence
Finding

The skill documentation and analysis indicate the skill reads environment/config secrets but declares no explicit tool scope or permissions. That creates a transparency and containment problem: users cannot accurately assess that local sensitive data may be accessed, and a host framework may grant broader capability than intended.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

Installing via npx clawhub@latest uses an unpinned, mutable package version, which exposes users to supply-chain risk if the package is compromised or changed unexpectedly. A future malicious or broken release could be executed at install time without user review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration sets "language": "zh-CN" as the language behavior, and the rest of the skill description presents the tool as operating only in Chinese. Under the policy for natural-language violations, forcing a specific language/locale without user opt-in should be flagged unless a justified regional constraint is documented, which is not clearly provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file description and prompt design are explicitly Chinese-only, framing the tool as a Chinese social media content generator and instructing output for Chinese platforms. There is no indication that users can opt into another language or that the locale restriction is documented as a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends the user-supplied topic to api.deepseek.com without any explicit notice, consent, or data-handling warning at the point of use. If users include confidential project names, internal plans, or personal data in the topic, that information is transmitted to a third-party service unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends user-provided title content to an external AI service (api.deepseek.com) without clearly warning the user that their input will leave the local environment. This creates a privacy and data-handling risk, especially if users paste confidential draft titles, internal project names, or embargoed content assuming the tool is local-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language prompt hard-codes Chinese output and targets Chinese social media platforms ('适合中文社交媒体(掘金/知乎/公众号)') rather than letting the user choose language or locale. This is a policy concern because the skill imposes a specific language/locale behavior by default without explicit user selection or justification that it is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's title/commentary and all console output are written in Chinese, which imposes a specific language on users without any opt-in or fallback. The stated policy flags language or locale constraints unless the skill offers a choice or clearly documents a justified region-specific purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes content generation, hot-topic tracking, and SEO optimization. While calling an external model API is expected for generation, directly accessing a hidden file under the user's home directory to extract credentials is a broader capability that is not justified by the stated purpose itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.