Back to skill

Security audit

Automated Post

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent posting-and-archiving purpose, but it gives high-impact publishing and Feishu archival instructions with unsafe command templates and limited user control over persistent external storage.

Install only if you trust the website publishing script, the Feishu workspace, and the local OpenClaw agents involved. Treat topics, copy, tags, prompts, document content, and file paths as untrusted input; use argument-array APIs or structured tool calls instead of shell string substitution, and confirm or disable Feishu archival when content should not be stored externally.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:49
Finding

Shell Command Injection Through Unsafe Dynamic Argument Interpolation

Content
View full analysis
" --timeout 120 ### Start Xichun to generate an image openclaw agent --agent xichun --message "<图片提示词>" --timeout 180 ### Publish to the website cd ~/.openclaw/workspace/skills/post_to_website node post_skill.js "<作者>" "<文案>" "<标签>" "<图片路径>" ``` The archival workflow contains the same unsafe pattern: ```bash # Append content to the daily document node ~/.openclaw/workspace/skills/feishu-send-image/scripts/append_doc.js <文档token> <内容> # Upload an image to the document feishu_doc action=upload_image doc_token=<文档token> file_path=<图片路径> ``` ### Technical Analysis The Skill directs the agent to place user-controlled topics, AI-generated copy, image prompts, document content, tokens, and file paths directly into shell command templates. Double quotes do not make arbitrary data safe for shell execution. Shell constructs such as `$(command)` and backtick command substitution are still evaluated inside double-quoted arguments. The archival command is more exposed because its dynamic arguments are not quoted at all, allowing whitespace, command separators, redirections, pipes, and substitutions to affect command parsing. For example, a topic containing `$(malicious-command)` could cause the command to execute while the shell is constructing the `--message` argument. Likewise, unquoted archival content containing `; malicious-command` could terminate the intended command and start another one. The risk applies whenever these documented templates are instantiated as shell command strings. Final publication confirmation is not a sufficient mitigation because the topic and prompt commands are executed earlier in the workflow, and dangerous shell syntax may be concealed ...[truncated 1909 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs automatic archival of post content and images to Feishu documents, which causes external data transmission and persistent storage without any explicit user warning, consent step, or data-classification guardrail. In this skill’s context, the generated copy, images, tags, and author data may be sensitive or unpublished marketing material, so silent exfiltration to a third-party service creates a real confidentiality and privacy risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This duplicate finding points to the same persistence behavior: creating or appending to a standing daily Feishu document and uploading images, which preserves task data across sessions. In an automation skill that handles publishable content, this persistence can unintentionally aggregate sensitive drafts, metadata, and media in one long-lived location without explicit user awareness each time.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
### 实现方式
使用 feishu_doc 工具:
1. 查询当天是否有对应日期的文档
2. 如果没有,用 feishu_doc create 创建新文档
3. 如果有,用 feishu_doc append 追加内容
4. 用 feishu_doc upload_image 上传图片

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This duplicate finding points to the same persistence behavior: creating or appending to a standing daily Feishu document and uploading images, which preserves task data across sessions. In an automation skill that handles publishable content, this persistence can unintentionally aggregate sensitive drafts, metadata, and media in one long-lived location without explicit user awareness each time.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
### 实现方式
使用 feishu_doc 工具:
1. 查询当天是否有对应日期的文档
2. 如果没有,用 feishu_doc create 创建新文档
3. 如果有,用 feishu_doc append 追加内容
4. 用 feishu_doc upload_image 上传图片

Static analysis

No suspicious patterns detected.