Back to skill

Security audit

Api Billing

Security checks for vulnerabilities and agentic risk

Overview

This billing skill mostly does what it claims, but it ships credential-looking cloud keys and gives weak credential-storage guidance for sensitive account access.

Review this skill carefully before installing. Do not use the included credential examples, rotate any matching or reused keys, and only provide read-only billing credentials stored outside source control with strict local permissions. Treat Base64 as reversible encoding, not secret protection.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/api-reference.md:51
Finding

Cloud Access Credentials Embedded in Tracked Documentation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:52
Finding

Base64 Encoding Is Incorrectly Presented as Credential Protection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/query_volc_billing.py:96
Finding

Outbound API Requests Have No Explicit Timeouts

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims broad multi-platform billing features while apparently accessing a local sensitive credential file and implementing only a narrower subset. This kind of overclaiming can conceal the real security boundary of the skill, causing users to authorize or run a credential-reading workflow they did not accurately understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill claims broad multi-platform billing features while apparently accessing a local sensitive credential file and implementing only a narrower subset. This kind of overclaiming can conceal the real security boundary of the skill, causing users to authorize or run a credential-reading workflow they did not accurately understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill claims broad multi-platform billing features while apparently accessing a local sensitive credential file and implementing only a narrower subset. This kind of overclaiming can conceal the real security boundary of the skill, causing users to authorize or run a credential-reading workflow they did not accurately understand.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims broad multi-platform billing features while apparently accessing a local sensitive credential file and implementing only a narrower subset. This kind of overclaiming can conceal the real security boundary of the skill, causing users to authorize or run a credential-reading workflow they did not accurately understand.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The reference document includes what appear to be concrete access key values and secrets rather than obvious placeholders. Even if they are sample values, publishing credential-shaped strings in a billing/account skill is dangerous because users may reuse them, scanners may treat them as live secrets, and real credentials could grant access to account balance, billing history, or broader cloud resources.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill documentation declares access to local credential files and use of networked billing queries, but it does not define any explicit tool scope or permissions boundary. In agent environments, undeclared file-read and network capabilities increase the risk of overbroad access to sensitive secrets in ~/.openclaw/workspace and make review and containment harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document instructs use of Bearer tokens and access keys for multiple billing providers without warning users that these credentials are sensitive or that billing data is financial/account information. In a skill specifically designed to query balances and bills, this omission increases the chance that users paste secrets insecurely, store them in prompts, logs, or source files, and expose account data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s docstrings and all user-facing console messages are written in Chinese, which imposes a specific language on users. There is no opt-in, locale selection, or indication that this is a region-specific tool, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 36)May include surrounding context.

md
"""查询 DeepSeek 账户余额"""
    api_key = load_credentials()
    
    url = "https://api.deepseek.com/user/balance"
    headers = {
        "Authorization": f"Bearer {api_key}"
    }

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/query_deepseek_balance.py (reported line 35)May include surrounding context.

python
"""查询 DeepSeek 账户余额"""
    api_key = load_credentials()
    
    url = "https://api.deepseek.com/user/balance"
    headers = {
        "Authorization": f"Bearer {api_key}"
    }

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's user-facing docstring, usage text, and warnings are presented exclusively in Chinese. Under the policy rule for language/locale, this is a natural-language constraint that does not provide user opt-in or justify why the skill is region- or language-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

A language/locale policy issue can arise when a skill or reference forces a specific language without offering choice or documenting a justified locale restriction. This file presents all instructions and labels in Chinese only, with no note that the content is region-specific or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script's natural-language comments and all echoed user-facing messages are written only in Chinese, which imposes a specific language choice on users. The file does not offer any language selection, fallback, or documentation that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring and all user-facing messages in this script are written only in Chinese, which imposes a specific language on users. The file does not provide an opt-in, fallback language, or justification that the skill is intended exclusively for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level documentation states that credentials come from a Base64-encoded .volc_ak_sk.env file. However, load_credentials() simply reads VOLC_ACCESS_KEY_ID and VOLC_SECRET_KEY as raw strings, and the only related comment says the secret key is used directly without decoding. This is an active documentation/code contradiction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.