Back to skill

Security audit

Baidu Yijian Vision

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Baidu vision client, but it can upload any local file path it is given to Baidu and lacks clear file-scope safeguards.

Install only if you are comfortable sending selected local images, video frames, prompts, and workspace skill metadata to Baidu Yijian using your API key. Avoid letting untrusted prompts choose file paths, and prefer running it in a constrained workspace until file validation, upload confirmation, and pinned dependencies are added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/types.mjs:250
Finding

Arbitrary Local File Disclosure Through Unvalidated Image Inputs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:23
Finding

Mutable Git Branch Dependency Without a Committed Lockfile

Content
View full analysis
Remediation
View remediation
" ``` 2. Generate, review, and commit a package lockfile. 3. Use `npm ci` in CI and release workflows so dependency resolution fails when it differs from the lockfile. 4. Review dependency lifecycle scripts and use installation policies that disable scripts where they are unnecessary. 5. Pin release-critical dependencies to exact reviewed versions and use automated update tooling that produces auditable change requests. 6. Run dependency installation and packaging in an isolated environment with minimal credentials, restricted filesystem access, and controlled outbound network access. 7. Verify dependency provenance and integrity before producing or publishing release artifacts. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/utils.mjs (reported line 50)May include surrounding context.

js
export function getApiKey() {
  const key = process.env.YIJIAN_API_KEY;
  if (!key) {
    throw new Error('YIJIAN_API_KEY environment variable is not set. Please configure it in ~/.claude/settings.json under "env".');
  }
  return key;
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The primary heading and the rest of the operational documentation are presented in Chinese, and the examples/instructions assume Chinese-language interaction. There is no statement offering users a language choice or documenting a justified locale restriction, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file uses only Chinese for all instructions and examples, which can amount to a language/locale policy violation when no user opt-in or alternative language is provided. The document does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

On failure of public skills, the code enumerates private workspace skills and returns their IDs, names, and descriptions. This broadens the skill from image/video analysis into internal capability discovery and may leak metadata about private tools to any caller who can trigger this path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The user-facing hint string is written only in Chinese, which imposes a specific language choice on downstream users or agents regardless of their locale. This is a natural-language policy issue because the file provides no opt-in, language selection, or justification for restricting the message to Chinese.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

If no matching specialized vision skill succeeds, the router silently falls back to a generic multimodal model, expanding behavior beyond the advertised Yijian vision scope. This can bypass capability boundaries, produce lower-assurance outputs for safety-critical use cases, and send sensitive image/task data to a broader backend than the caller expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code sends user-supplied inputs and a bearer API key to a remote endpoint, but the file provides no explicit user-facing notice, consent step, or data handling warning before transmitting potentially sensitive image/video data. In a vision-analysis skill, inputs may contain personal, proprietary, or safety-monitoring imagery, so silent transmission to a third-party service creates a real privacy and compliance risk even if the behavior is functionally expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

When a local file path is provided, the code converts the image to a data URI and includes the file contents in an outbound HTTPS request to a remote multimodal API. This can cause unintentional exfiltration of sensitive local images because the CLI and function do not require explicit confirmation, warning, or clear consent before transmitting local data off host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code reads arbitrary local files as images and converts their contents to base64 for downstream API use, which can expose user data from the filesystem. Although the functions are commented for developers, there is no user-facing confirmation, warning, or visible disclosure in this file about reading and serializing local file contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This helper reads a local file path and converts the full file contents into a base64 data URI, which may later be embedded or transmitted. There is no user-facing warning, confirmation, or disclosure in this code path about reading local files and transforming their contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

该工作流全文以中文指令和示例呈现,且未说明可根据用户偏好切换语言,也未声明这是仅限中文场景的技能。按规则,强制特定语言而没有用户选择或合理、明确的地域性说明,属于自然语言政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

该 markdown 文档从标题开始即以中文呈现,全文未说明这是特定区域/用户群的限定版本,也未提供语言选择。根据规则,强制特定语言而无用户 opt-in 属于自然语言层面的语言/区域策略违规。

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency uses a caret range (^7.0.1), which allows future minor and patch releases to be installed. This weakens build reproducibility and can introduce unexpected vulnerable or malicious code through the supply chain, though here it is limited to a devDependency and does not by itself prove compromise.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
"test:all": "npm test && npm run test:integration"
  },
  "devDependencies": {
    "archiver": "^7.0.1",
    "openclaw": "github:openclaw/openclaw#main"
  },
  "optionalDependencies": {

Unverifiable Dependency: openclaw has 16 known advisory(ies) (CVE-2026-53846 (OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency); CVE-2026-32064 (OpenClaw's andbox browser noVNC observer lacked VNC authentication); CVE-2026-32006 (OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallbac) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The openclaw dependency is pulled directly from github:openclaw/openclaw#main, which tracks a moving branch rather than a fixed release or commit. Because advisories are known for this package and the exact resolved revision is not pinned, consumers may unknowingly install an affected or newly introduced vulnerable state, significantly increasing supply-chain risk.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The optional dependency sharp is specified with a caret range (^0.33.0), so installs may resolve to newer releases than originally tested. That creates a supply-chain and reproducibility risk, although the practical impact is somewhat reduced because the package is optional rather than mandatory.

Content

Scanner excerpt · package.json (reported line 28)May include surrounding context.

json
"openclaw": "github:openclaw/openclaw#main"
  },
  "optionalDependencies": {
    "sharp": "^0.33.0"
  }
}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The script retrieves an API key and uses it in an Authorization header for a network request. While this is functionally expected for an API client, this file does not include a visible disclosure or warning to users that credentials are required and will be used for outbound authentication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The only usage examples shown to users are Chinese prompts, which implicitly steer usage toward a specific language without offering alternatives or stating that the tool is region-specific. This can conflict with language/locale neutrality expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The function opens a user-supplied file path and reads up to 64 KB to compute a stable identifier, which is access to local user data. The code has developer comments but no user-facing notice that file contents are being read for fingerprinting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.