Back to skill

Security audit

Weekly Report Flow

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its weekly-report purpose, but it uses sensitive business tokens and includes under-scoped authentication and external-script behaviors that should be reviewed before installation.

Review before installing. Use least-privilege DevOps and EMOP tokens, avoid browser-session fallback unless you explicitly approve the account and scope, and inspect or pin the referenced local scripts before running the workflow with credentials present.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:16
Finding

Ambient Browser Authentication Used to Bypass an API Access Denial

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16–20
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable Code

markdown
1) **Pull DevOps workitems**
   - Use browser session if direct API returns 403.
   - Endpoint: `/projex/api/workitem/workitem/list?_input_charset=utf-8`
   - Header: `x-yunxiao-token: $DEVOPS_TOKEN`
   - Page size 200, iterate all pages.

Technical Analysis

An HTTP 403 response is an explicit access-control decision. The instruction directs the Agent to respond to that denial by switching from the supplied DevOps token to an authenticated browser session.

The browser session may contain cookies or other credentials with broader permissions than the dedicated token. This credential-context switch can defeat least-privilege isolation and cause requests to be executed under the interactive user's identity rather than a narrowly scoped service identity.

The instruction does not require explicit confirmation before using browser credentials, verify that the browser session belongs to the intended account, or constrain the browser session to a particular project and permission scope.

Attack Path

  1. The Agent sends a DevOps API request using DEVOPS_TOKEN.
  2. The API rejects the request with HTTP 403.
  3. Following the Skill instruction, the Agent switches to an existing authenticated browser session.
  4. The browser supplies ambient authentication credentials with potentially broader privileges.
  5. The Agent retrieves work-item data under the browser user's authorization context.
  6. Retrieved data is processed and may subsequently be included in a report sent to EMOP.

Impact Assessment

Successful exploitation or accidental misuse could expose DevOps work-item data that the dedicated token was not authorized to access. The effective privilege level is limited by the active browser user's DevOps permissions, which may include access to additional pro ...[truncated 252 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the automatic browser-session fallback and fail closed when the API returns HTTP 403.
  2. Require explicit user approval before changing authentication contexts.
  3. Use a dedicated, least-privilege service credential restricted to the required project, view, and read operations.
  4. Diagnose and correct token permissions rather than bypassing the denial through ambient browser credentials.
  5. Validate the destination origin, project ID, and requested resource before every authenticated request.
  6. If browser authentication is operationally required, use an isolated browser profile dedicated to this workflow and verify the authenticated account and authorization scope before retrieving data.
  7. Record the authentication method and approved scope in an audit log without recording tokens or session cookies.

T08 · Insecure Dependencies

Warning
Location
references/cli.md:1
Finding

Execution Workflow Depends on Mutable Scripts Outside the Audited Package

Content
View full analysis

Vulnerability Details

File Location: references/cli.md, lines 1–5
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

markdown
# Local scripts / entrypoints

- DevOps export script: `C:\Users\Administrator\.openclaw\workspace\aliyun_devops_weekly.py`
- Weekly submit script: `C:\Users\Administrator\.openclaw\workspace\weekly_submit.ps1`
- Output markdown: `C:\Users\Administrator\.openclaw\workspace\weekly_workitems.md`

Technical Analysis

The documented workflow references Python and PowerShell entrypoints stored outside the audited Skill package. Their source code, provenance, integrity controls, ownership, and behavior cannot be verified from the supplied project.

Because these paths point into a mutable workspace rather than versioned package-relative files, any process that invokes them implicitly trusts external code. A user, local process, or compromised workspace with write access could replace either script while preserving the documented filename.

The scripts are expected to operate in a context containing DEVOPS_TOKEN and EMOP_TOKEN. A substituted script could therefore access those environment variables, alter report content, transmit data elsewhere, or execute arbitrary commands with the invoking user's permissions.

Attack Path

  1. An attacker or compromised local process obtains write access to C:\Users\Administrator\.openclaw\workspace.
  2. The attacker replaces aliyun_devops_weekly.py or weekly_submit.ps1 with malicious code.
  3. The replacement retains the expected filename, so the documented invocation appears legitimate.
  4. A user or Agent runs the weekly-report workflow with DevOps and EMOP tokens present in the environment.
  5. The substituted script executes with the invoking process's operating-system permissions.
  6. The script may read environment tokens, access report data, alter submissions, execute additional local commands, or transmit sensitive information ...[truncated 485 chars]
Remediation
View remediation

Remediation Suggestions

  1. Bundle the required Python and PowerShell scripts inside the reviewed Skill package.
  2. Invoke scripts through package-relative paths rather than mutable absolute workspace paths.
  3. Version-control and audit the complete source of every executable entrypoint.
  4. Verify script integrity before execution using pinned cryptographic hashes or trusted signatures.
  5. Restrict script ownership and write permissions so untrusted users and processes cannot replace them.
  6. Run the scripts under a dedicated least-privilege account with access only to required files and endpoints.
  7. Pass narrowly scoped credentials only to the process that requires them, and remove credentials from the environment immediately after use.
  8. Prevent child processes from inheriting tokens unless inheritance is explicitly required.
  9. Validate outbound destinations so scripts can communicate only with the approved Aliyun DevOps and EMOP endpoints.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction requires summaries to be written in '200–300 Chinese characters,' which imposes a specific language on all uses of the skill. This is a natural-language policy concern because the file does not offer the user a language choice or explain a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.