Back to skill

Security audit

skill-fixon-homepage

Security checks for vulnerabilities and agentic risk

Overview

This homepage chat skill broadly matches its stated purpose, but it exposes a networked chat service with authentication, file handling, credential logging, and session metadata problems that need review before use.

Install only after review or remediation. At minimum, require authentication on all non-health endpoints, validate or server-generate session IDs, stop logging tokens and avoid credentials in query strings, restrict the bind address or use a protected reverse proxy, enforce 0600/0700 permissions for config/data/logs, disclose retention and Gateway forwarding, and pin dependencies in an isolated environment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/main.py:103
Finding

Missing Authorization Header Bypasses Chat Endpoint Authentication

Content
View full analysis
Remediation
View remediation
None: if not expected_key: raise HTTPException(status_code=500, detail="Service API key is not configured") if not authorization or not authorization.startswith("Bearer "): raise HTTPException(status_code=401, detail="Authentication required") token = authorization[len("Bearer "):] if not hmac.compare_digest(token, expected_key): raise HTTPException(status_code=401, detail="Invalid API key") ``` Apply this check through a shared FastAPI dependency to every protected endpoint. Restrict network exposure using an explicit trusted bind address, reverse-proxy access controls, and firewall rules. Add tests covering missing, malformed, empty, and incorrect authorization headers. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:42
Finding

Unvalidated Session Identifier Enables Path Traversal and Arbitrary JSON-File Overwrite

Content
View full analysis
timedelta(hours=SESSION_EXPIRE_HOURS): return [] return data.get('messages', []) return [] def save_session_history(session_id, messages): session_file = DATA_DIR / f"{session_id}.json" with open(session_file, 'w') as f: json.dump({'messages': messages, 'timestamp': datetime.now().isoformat()}, f) ``` ### Technical Analysis The client-controlled `session_id` is directly interpolated into a filesystem path. No character allowlist, canonicalization, or containment check ensures that the resulting path remains under `DATA_DIR`. A value containing `../` can traverse to another directory. A leading absolute path can also cause `pathlib` path composition to discard the intended base directory. The implementation always adds `.json`, limiting targets to paths with that suffix, but an attacker can still read and overwrite accessible JSON files. If an existing target is valid JSON with a recent timestamp and a `messages` array, its content is loaded as conversation history and passed to the Agent. The file is subsequently replaced with session data. ### Attack Path 1. The attacker reaches `/homepage/chat`, potentially using the separate missing-header authentication bypass. 2. The attacker chooses a traversal or absolute `session_id`, such as `../../../../tmp/target` or `/tmp/target`. 3. The service resolves the effective target as a JSON file outside `~/.openclaw/homepage/data`. 4. If that file ...[truncated 873 chars]
Remediation
View remediation
Path: if not SESSION_ID_PATTERN.fullmatch(session_id): raise HTTPException(status_code=400, detail="Invalid session identifier") base = DATA_DIR.resolve() target = (base / f"{session_id}.json").resolve() if target.parent != base: raise HTTPException(status_code=400, detail="Invalid session path") return target ``` Use this single validated path function for reads and writes. Create files with restrictive permissions, reject symbolic links, and use atomic writes through a temporary file in the same validated directory followed by `os.replace`. Limit message and session sizes to prevent resource exhaustion. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:70
Finding

Gateway Authentication Token Is Written to Application Logs

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/main.py:124
Finding

Unauthenticated Endpoint Exposes Session Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/init.sh:14
Finding

Credential-Bearing Configuration Is Created Without Explicitly Restrictive Permissions

Content
View full analysis
"$CONFIG_DIR/config.yaml" << 'EOF' # OpenClaw 主页插件配置 # Agent 配置 agent: id: "your-agent-id" api_key: "your-api-key" model: "openclaw-default" url: "http://localhost:18789" # 安全配置 security: api_key: "your-secure-api-key" # 服务配置 server: host: "0.0.0.0" port: 8080 # 会话配置 session: expire_hours: 24 max_history: 50 EOF echo "✅ 已创建默认配置文件: $CONFIG_DIR/config.yaml" echo " 请编辑此文件,配置你的 Agent ID 和 API Key" else echo "ℹ️ 配置文件已存在: $CONFIG_DIR/config.yaml" fi ``` ### Technical Analysis The initializer creates a configuration file intended to contain both the Gateway API key and service API key, but it does not set a restrictive `umask` or explicitly apply file and directory modes. The resulting permissions depend on the invoking environment's current `umask`. In a permissive environment, other local users may be able to read the plaintext credentials. The same configuration directory also stores conversation data and logs, increasing the sensitivity of appropriate directory permissions. ### Attack Path 1. A user runs `scripts/init.sh` under a permissive `umask`. 2. The script creates `~/.openclaw/homepage/config.yaml` without enforcing owner-only permissions. 3. The user replaces the placeholders with real API keys. 4. Another local account or process with filesystem access reads the configuration. 5. The exposed keys are used against the Homepage service or Gateway, subject to network reachability and key privileges. ### Impact Assessment A local attacker may recover the Homepage API key and Gateway token. This can grant unauthorized access to chat functionality and potentially direct Gateway capabilities. Exploitation requires local filesystem access or access thr ...[truncated 133 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/init.sh:45
Finding

Initialization Installs Mutable and Unpinned Runtime Dependencies

Content
View full analysis
/dev/null; then echo "✅ FastAPI 已安装" else echo "⏳ 安装 FastAPI..." pip3 install fastapi uvicorn pyyaml requests pydantic -q fi ``` The associated dependency declaration in `scripts/requirements.txt:1-5` is: ```text fastapi>=0.100.0 uvicorn>=0.23.0 pyyaml>=6.0 requests>=2.28.0 pydantic>=2.0.0 ``` ### Technical Analysis The initializer installs package names without exact versions, hashes, an isolated virtual environment, or an explicitly reviewed package source. The requirements file also uses mutable lower-bound constraints rather than reproducible versions. Future installation behavior can therefore change without changes to the audited Skill. A compromised upstream release, compromised configured package index, or incompatible future version could introduce arbitrary installation-time or runtime behavior. The code imports `websocket`, but the corresponding `websocket-client` package is absent from both the installation command and `requirements.txt`. This encourages ad hoc manual installation and increases the risk of installing an incorrect similarly named package. The script only tests whether FastAPI imports successfully. If FastAPI is present while other dependencies are absent or incompatible, installation is skipped entirely. ### Attack Path 1. A user runs `scripts/init.sh`. 2. FastAPI is absent, causing the script to invoke the environment's `pip3`. 3. Pip resolves mutable package versions from its configured index and executes normal package installation behavior. 4. A compromised package/index or unsafe future release is installed and later imported by the service. 5. The package executes with the privileges of the user running initializa ...[truncated 540 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding describes multiple concrete security issues inconsistent with the skill's privacy-focused description: listing all sessions, persisting chat histories locally, weak or optional authentication, and placing an upstream token in a WebSocket query string. Together these can enable unauthorized access to visitor conversations, metadata disclosure, and credential leakage through logs, browser history, proxies, or monitoring systems.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding describes multiple concrete security issues inconsistent with the skill's privacy-focused description: listing all sessions, persisting chat histories locally, weak or optional authentication, and placing an upstream token in a WebSocket query string. Together these can enable unauthorized access to visitor conversations, metadata disclosure, and credential leakage through logs, browser history, proxies, or monitoring systems.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/test.sh (reported line 25)May include surrounding context.

sh
# 健康检查
echo "1️⃣ 健康检查..."
curl -s "http://localhost:$PORT/homepage/health" | python3 -m json.tool 2>/dev/null || echo "   ❌ 失败 - 服务可能未启动"
echo ""

# 测试聊天接口

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/test.sh (reported line 30)May include surrounding context.

sh
# 测试聊天接口
echo "2️⃣ 测试聊天..."
RESPONSE=$(curl -s -X POST "http://localhost:$PORT/homepage/chat" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $API_KEY" \
    -d "{\"session_id\": \"$SESSION_ID\", \"message\": \"你好,请介绍一下自己\"}")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/test.sh (reported line 40)May include surrounding context.

sh
# 列出会话
echo "3️⃣ 列出会话..."
curl -s "http://localhost:$PORT/homepage/sessions" | python3 -m json.tool 2>/dev/null || echo "   失败"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool scope or permission boundaries despite documentation indicating capabilities that involve shell execution, file access, environment use, and a networked HTTP service. In an agent/plugin ecosystem, missing scope declarations increase the chance of over-privileged execution and make it harder for operators to assess or constrain what the skill can do.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file forces a single language for the skill description and operating instructions, and there is no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate organizational language/locale policy for broadly distributed skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script takes a gateway token from input, exports it as an environment variable, and immediately invokes an external CLI that may use it for network-authenticated operations. There is no confirmation prompt, visible logging, or explanatory comment warning the user that credentials are being consumed by a downstream agent process.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a homepage plugin that lets visitors chat with an AI assistant, but this init script also performs package installation via pip. Fetching and installing software from package indexes is not an obvious runtime requirement of the stated end-user purpose and introduces a broader capability than simply hosting the chat service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill persists conversation messages and timestamps under the user's home directory, which affects user data retention and privacy. There is no visible warning, comment, prompt, or accompanying markdown notice explaining that chat content will be stored locally for up to the session retention window.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sends the current user message plus recent conversation history to an external Gateway endpoint over WebSocket. While the module docstring mentions HTTP/Gateway usage, there is no user-facing warning, prompt, or comment disclosing that user content and session data are transmitted off-process.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The plugin exposes a session enumeration endpoint that returns all session IDs, message counts, and last-active timestamps, but the endpoint has no authentication or authorization checks. In a homepage chat plugin, this unnecessarily expands the attack surface and enables privacy-sensitive metadata disclosure about visitors and their activity.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/start.sh (reported line 34)May include surrounding context.

sh
# 启动服务
cd "$BASE_DIR"
nohup python3 main.py > "$LOG_FILE" 2>&1 &
PID=$!
echo $PID > "$PID_FILE"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script includes Chinese-only comments and user-visible status messages such as 服务未运行 and 服务已停止. This imposes a specific language on users without opt-in or documentation that the skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/test.sh (reported line 30)May include surrounding context.

sh
# 测试聊天接口
echo "2️⃣ 测试聊天..."
RESPONSE=$(curl -s -X POST "http://localhost:$PORT/homepage/chat" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $API_KEY" \
    -d "{\"session_id\": \"$SESSION_ID\", \"message\": \"你好,请介绍一下自己\"}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The test request hard-codes a Chinese prompt ("你好,请介绍一下自己"), and the script's user-facing comments/output are also in Chinese. This imposes a specific language/locale without offering user opt-in or documenting a justified region-specific constraint, which matches the policy-violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The comment "Agent 调用包装脚本" is natural-language text that fixes the script description to Chinese, with no indication that this locale choice is optional or region-specific. The policy requires avoiding forced language/locale constraints unless the user is given a choice or the limitation is justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring says the plugin "直接通过 HTTP API 调用 Gateway" and the function docstring at call_agent says it uses the Gateway WS API, but the actual implementation constructs a ws:// URL and uses websocket.create_connection. This is an active contradiction in the file-level documentation about how the gateway is contacted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The natural-language title and descriptive strings are written only in Chinese, suggesting a fixed language experience without any visible opt-in or locale choice. Under the policy, forcing a specific language can be a locale-policy issue unless the constraint is explicitly justified or user-selectable.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency uses a lower-bound version specifier instead of an exact pinned version, which makes builds non-reproducible and can silently pull in vulnerable or breaking upstream releases. In a web-facing plugin, this increases supply-chain risk because deployment time determines what code is installed.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
fastapi>=0.100.0
uvicorn>=0.23.0
pyyaml>=6.0
requests>=2.28.0

Unverifiable Dependency: fastapi has 3 known advisory(ies) (CVE-2021-32677 (Cross-Site Request Forgery (CSRF) in FastAPI); CVE-2021-32677 (FastAPI is a web framework for building APIs with Python 3.6+ based on standard ); CVE-2024-24762 (FastAPI is a web framework for building APIs with Python 3.8+ based on standard )), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

FastAPI has known advisories, and because the version is not pinned, it is impossible to determine from this manifest whether a vulnerable release will be installed. In a homepage/chat plugin that is likely web-accessible, inability to verify framework versioning meaningfully increases exposure.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Using uvicorn with a >= constraint leaves the installed version uncontrolled, which can result in inconsistent environments and accidental adoption of vulnerable releases. For an internet-exposed service component, that weakens supply-chain assurance even if no specific exploit is demonstrated here.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
fastapi>=0.100.0
uvicorn>=0.23.0
pyyaml>=6.0
requests>=2.28.0
pydantic>=2.0.0

Unverifiable Dependency: uvicorn has 4 known advisory(ies) (CVE-2020-7694 (Log injection in uvicorn); CVE-2020-7695 (HTTP response splitting in uvicorn); CVE-2020-7694 (This affects all versions of package uvicorn. The request logger provided by the) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

Uvicorn has known historical advisories, and the unpinned requirement prevents confirming whether deployed versions are safe. Since uvicorn is the HTTP server layer, unverifiable versioning can affect externally reachable request handling.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

An unpinned PyYAML dependency is riskier than many libraries because older or unsafe versions have a history of deserialization-related issues. If later code parses YAML from untrusted or semi-trusted sources, an unintended vulnerable version could materially increase attack surface.

Content

Scanner excerpt · scripts/requirements.txt (reported line 3)May include surrounding context.

text
fastapi>=0.100.0
uvicorn>=0.23.0
pyyaml>=6.0
requests>=2.28.0
pydantic>=2.0.0

Static analysis

No suspicious patterns detected.