Back to skill

Security audit

木瓜法律助手

Security checks for vulnerabilities and agentic risk

Overview

This legal assistant is coherent, but it needs review because it can send confidential legal data and the API token to a configurable external URL, including a test endpoint.

Install only if you trust the Mugua API endpoint you configure and can prevent event/user input from changing base_url. Do not use real privileged or highly sensitive legal documents until the destination is locked to an approved production host, sensitive-data handling is understood, and users explicitly consent before transmission.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skill.py:19
Finding

Configurable API Endpoint Enables Credential Disclosure, Sensitive Data Exfiltration, and SSRF

Content
View full analysis
str: """Consistent with the base_url configuration in metadata.json: prefer runtime injection, otherwise use the SKILL_META default.""" creds = context.get("credentials") or {} ctx_cfg = context.get("config") or {} ev_cfg = event.get("config") or {} url = creds.get("base_url") or ctx_cfg.get("base_url") or ev_cfg.get("base_url") if not url: url = SKILL_META["config"]["base_url"] return url.rstrip("/") + "/" ``` The resolved URL is subsequently used for authenticated network requests: ```python url = f"{base_url}v1/legal-chat/completions" headers = { "Content-Type": "application/json", "Authorization": f"Bearer {api_key}" } payload = { "prompt": prompt, "stream": stream, "enable_network": enable_network } response = requests.post( url=url, json=payload, headers=headers, timeout=SKILL_META['config']['timeout'] ) ``` The case-analysis path sends files and structured case information to the same configurable destination: ```python url = f"{base_url}v1/case-analysis/generate" headers = {"Authorization": f"Bearer {api_key}"} if files: data = { "analysis_mode": analysis_mode, "stream": str(stream).lower(), "input": input_text or "" } files_data = [("files[]", (f["name"], f["content"], f["type"])) for f in files] response = requests.post( url=url, data=data, files=files_data, headers=headers, timeout=60 ) else: payload = {"analysis_mode": analysis_mode, "stream": stream} # The payload may subsequently contain inpu ...[truncated 3196 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unnecessary and Unpinned Third-Party Dependencies Increase Supply-Chain Risk

Content
View full analysis
=2.31.0 typing>=3.7.4.3 ``` ### Technical Analysis Both dependencies use open-ended lower-bound constraints, so future installations may resolve to versions that were not reviewed during this audit. This prevents reproducible dependency installation and expands exposure to compromised or incompatible future releases. The `typing` dependency is also unnecessary for supported Python versions where `typing` is part of the standard library. Its inclusion contradicts the project documentation in `SKILL.md`, which states that only `requests` should be declared and that standard-library `typing` should not be added as a pip dependency. No evidence was found that either declared package is intentionally malicious. The concern is avoidable supply-chain exposure and configuration inconsistency rather than a confirmed malicious package payload. ### Attack Path 1. The Skill is installed in a new or rebuilt environment. 2. The package resolver selects any available versions satisfying the open-ended `>=` constraints. 3. An unreviewed, compromised, or behaviorally incompatible future release may be installed. 4. That package executes with the same process privileges as the Skill when imported or used. For `typing`, the unnecessary package installation adds a dependency and package-index interaction that the Skill does not need for its declared functionality. ### Impact Assessment If dependency resolution selects a compromised release, malicious package code could execute with the privileges of the Skill runtime and potentially access process data, credentials, or network resources. No such compromise is demonstrated in the reviewed project, so the present finding is a preventative supply-chain hardening issue with low immedi ...[truncated 13 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill name and all user-facing documentation are presented only in Chinese, and the examples and descriptions imply Chinese-language use without any opt-in or alternative language guidance. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill documentation states that user legal-case content and API credentials may be sent to an external service, and the default endpoint is a test-domain remote API. In the context of legal consultation, transmitted data may include sensitive personal, employment, or case information, creating confidentiality and compliance risk if the endpoint is misconfigured, non-production, or not sufficiently trusted.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
- **案件完整分析**:基于当事人信息、案由、事实和诉求生成完整案件分析报告

## HTTP 端点(必须严格一致)
`base_url` 末尾带 `/`(默认 `https://api.test.mugua.muguafabao.com/`)。本 Skill 在服务端按下列路径请求,**不得**改用其它路径或自行 `curl` 猜测地址。

| 能力 | 方法 | 完整 URL(拼接规则) |
|------|------|----------------------|

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This section confirms the runtime lookup order for base_url and api_key and documents a fallback to an external test endpoint, increasing the chance that sensitive legal text is transmitted off-platform by default. Because the skill handles potentially confidential legal matters, external transmission is more dangerous here than in a low-sensitivity context.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

text

## 配置说明
- `base_url`: 木瓜 API 根地址(与 `metadata.json` 中 `required_configs` 一致)。运行时按顺序读取 `context.credentials.base_url`、`context.config.base_url`、`event.config.base_url`;均未提供时使用代码内默认 `https://api.test.mugua.muguafabao.com/`。法律咨询实际请求为 `{base_url}v1/legal-chat/completions`。
- `api_key`: 木瓜 API 鉴权 Token(Bearer),对应 `context.credentials.api_key`。
- `requirements.txt` 仅声明 `requests`;勿将标准库 `typing` 写入 pip 依赖(与注册元数据一致)。

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest states that the skill provides legal consultation and case analysis via an external API, but it does not include a clear user-facing warning that legal questions, case facts, files, and party information may be transmitted to a third party. Because legal data is often highly sensitive, the absence of an explicit disclosure and consent mechanism materially increases privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are very broad legal-domain terms such as '法律咨询' and '案件分析', which can cause the skill to activate for a wide range of sensitive legal conversations without clear scope limits. In this context, overbroad activation increases the chance that users will unknowingly send privileged, personal, or case-related information to the external legal API.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The metadata defines a configurable external base URL and defaults to a remote API endpoint, confirming that user inputs and case-analysis content may leave the host environment. External transmission is not inherently malicious, but in a legal-assistant context it is security-relevant because the transmitted content may include confidential legal strategy, personal information, or uploaded files.

Content

Scanner excerpt · metadata.json (reported line 19)May include surrounding context.

json
{
      "name": "base_url",
      "type": "string",
      "description": "木瓜法律 API 根地址(与 skill.py 中 _resolve_base_url 一致:OpenClaw 注入至 context.credentials / context.config / event.config 的 base_url;未注入时使用代码内默认)。默认 https://api.test.mugua.muguafabao.com/ ,实际请求路径见 SKILL.md(v1/legal-chat/completions 与 v1/case-analysis/generate)",
      "required": true,
      "default": "https://api.test.mugua.muguafabao.com/"
    }

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The repeated external endpoint reference reinforces that the skill depends on a third-party network service and may transmit user-provided legal materials outside the local platform boundary. In this specific skill, the danger is elevated by the nature of the data handled: case facts, files, parties, demands, and legal consultations can contain highly sensitive or privileged information.

Content

Scanner excerpt · metadata.json (reported line 21)May include surrounding context.

json
"type": "string",
      "description": "木瓜法律 API 根地址(与 skill.py 中 _resolve_base_url 一致:OpenClaw 注入至 context.credentials / context.config / event.config 的 base_url;未注入时使用代码内默认)。默认 https://api.test.mugua.muguafabao.com/ ,实际请求路径见 SKILL.md(v1/legal-chat/completions 与 v1/case-analysis/generate)",
      "required": true,
      "default": "https://api.test.mugua.muguafabao.com/"
    }
  ],
  "input_params": {

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata, descriptions, triggers, and user-facing error/output strings are written entirely in Chinese, which effectively forces a specific language experience. There is no indication that the user can opt into this locale or that the skill is intentionally restricted to a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.py (reported line 13)May include surrounding context.

python
"endpoint": "/skills/mugua-legal",
    "auth_type": "api_key",
    "config": {
        "base_url": "https://api.test.mugua.muguafabao.com/",
        "timeout": 30,  # 请求超时时间
        "max_file_size": 10 * 1024 * 1024  # 10MB文件大小限制
    }

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The skill transmits user-supplied legal prompts to an external third-party endpoint, which can include highly sensitive personal or case information. In the context of a legal-assistant skill, this raises real confidentiality and privacy risk because legal content is often privileged or regulated, and the code provides no minimization, allowlisting, or trust-boundary enforcement around the destination.

Content

Scanner excerpt · skill.py (reported line 60)May include surrounding context.

python
}

    try:
        response = requests.post(
            url=url,
            json=payload,
            headers=headers,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill sends user-provided legal prompts to an external API via HTTP, and elsewhere also uploads case-analysis text and files. Although the docstrings describe the API interface, there is no confirmation prompt, visible user-facing log/print, or explicit warning that potentially sensitive legal matter data will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This request can transmit structured case facts, party identities, demands, and potentially uploaded file contents to an external API, making the confidentiality risk higher than ordinary text prompts. The danger is amplified because _resolve_base_url permits runtime-controlled endpoint override, so sensitive legal data could be sent to an attacker-controlled server if event/context configuration is compromised or insufficiently trusted.

Content

Scanner excerpt · skill.py (reported line 198)May include surrounding context.

python
"demands": demands
            })
        try:
            response = requests.post(
                url=url,
                json=payload,
                headers=headers,

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency on requests is not pinned to an exact version, which makes builds non-reproducible and can result in installing a vulnerable or incompatible release over time. In this skill context, the risk is somewhat elevated because the package is used for external API access, and requests has had multiple security advisories, so lack of pinning weakens supply-chain control.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.31.0
typing>=3.7.4.3

# Required configuration (for ClawHub metadata consistency)

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

requests has multiple known advisories, and because the manifest does not pin the package, it is impossible to verify from this file whether deployment will select a patched release. This creates uncertainty around whether known vulnerabilities may be introduced at install time, especially in environments that rebuild frequently or resolve dependencies differently.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
83% confidence
Finding

The dependency on typing is also unpinned, which creates the same reproducibility and supply-chain integrity issue. While the direct security impact is limited here and typing is generally low risk, leaving it version-ranged still permits unexpected package resolution changes or dependency confusion in some environments.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.31.0
typing>=3.7.4.3

# Required configuration (for ClawHub metadata consistency)
# api_key: Bearer Token for Mugua Legal API

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The handler reads an API key from runtime credentials and uses it for outbound authorization, but the file provides no user-facing notice that credentialed external access is being used. For safety review purposes, sensitive credential use should be accompanied by some form of disclosure unless already documented elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.