Back to skill

Security audit

项目资料跨平台迁移

Security checks for vulnerabilities and agentic risk

Overview

This migration skill is coherent, but it needs review because it preserves live credentials by default and its privacy-copy tool can accidentally include credential files or binary secrets.

Install only if you are comfortable creating local archives that may contain complete conversations, memory/persona files, tool configuration, and live credentials. Treat private backup packages like secret vaults, avoid cloud sync or sharing, encrypt them yourself, and do not rely on the current --share package mode for safe external sharing until credentials/ and binary/unknown files are blocked or manually audited.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/desensitize.py:160
Finding

Privacy share packages retain credential directories and copy binary files without sanitization

Content
View full analysis

Vulnerability Details

File Location: scripts/desensitize.py, lines 160–180
Vulnerability Type: Sensitive data exposure in privacy share-package generation
Risk Level: High

Technical Analysis

The make_share_package function recursively processes the entire source migration package. Its directory filter excludes only entries listed in SKIP_DIRS, which does not include the documented credentials/ directory.

Text files receive limited regex-based masking, while every other file type is copied byte-for-byte into the share package:

python
def make_share_package(src_dir, out_dir, manifest, mf):
    """整目录 → 分享包:_share/ 脱敏副本 + _credentials_needed.md。"""
    share_dir = os.path.join(out_dir, "_share")
    os.makedirs(share_dir, exist_ok=True)
    hits, copied, binaries, masked_files = {}, 0, [], 0
    for root, dirs, files in os.walk(src_dir):
        dirs[:] = [d for d in dirs if d not in SKIP_DIRS]
        for fn in sorted(files):
            if fn in SKIP_FILES or fn.endswith((".pyc", ".pyo")) or fn.startswith("_desensitize_map"):
                continue
            sp = os.path.join(root, fn)
            dp = os.path.join(share_dir, os.path.relpath(sp, src_dir))
            if fn.endswith(TEXT_EXT):
                desensitize_text_file(sp, dp, manifest, hits)
                masked_files += 1
            else:
                # 非文本(图片/二进制)原样复制;截图可能含敏感信息,登记待人工确认
                os.makedirs(os.path.dirname(dp) or ".", exist_ok=True)
                shutil.copy2(sp, dp)
                binaries.append(os.path.relpath(sp, src_dir))
            copied += 1

This conflicts with the documented privacy boundary in SKILL.md, which states that a share package excludes credentials/. Merely printing a warning about binary files does not enforce that boundary or prevent the resulting package from being distributed.

The text sanitizer is also not a safe fallback for credential files: it recognizes only selected extensions and credentia ...[truncated 1614 chars]

Remediation
View remediation

Remediation Suggestions

  1. Exclude credentials/ unconditionally while constructing _share/, regardless of filename or extension.
  2. Use an explicit allowlist of safe shareable paths and formats instead of recursively copying the private package by default.
  3. Fail closed for images, archives, databases, key stores, and unknown file formats. Require explicit per-file approval before including them.
  4. Treat common secret-bearing formats such as .pem, .key, .p12, .pfx, .kdbx, SQLite databases, browser exports, and archives as forbidden.
  5. Perform a final structural validation that rejects any share artifact containing credentials/, mapping files, private-key material, or other prohibited paths.
  6. Write output to a fresh directory and fail if _share/ already exists, preventing stale sensitive files from surviving a later sanitized run.
  7. Add regression tests demonstrating that:
    • credentials/ never appears in share output;
    • non-text files are rejected unless explicitly approved;
    • unsupported credential formats cause generation to fail;
    • the completed share tree passes a post-generation secret and forbidden-path check.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (35)

Ssd 3

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

This section directly recommends leaving API keys and tokens in the backup package and restoring them for immediate use. If the backup is exfiltrated, shared, synced, or restored onto a less secure machine, attackers can gain direct access to external services, data stores, or paid APIs without further compromise.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description frames backups as preserving everything so the restored environment can be used immediately, which normalizes carrying over sensitive credentials alongside dialogue and configuration. In a migration tool, this context is especially dangerous because archives are intended to be portable, copied, and reused, making secret leakage more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The README explicitly advises keeping API keys and tokens inside backup artifacts so the restored agent works immediately. That creates a high risk of secret exposure through copied archives, disk compromise, accidental sharing, or weaker access controls on the destination machine, and this skill’s purpose—moving data across frameworks and machines—materially increases the blast radius.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The behavior notes reinforce that private backups should remain unredacted and include credentials, encouraging long-term retention of sensitive secrets across backup artifacts. Even if intended for local use, backups are commonly duplicated, moved, or cloud-synced, so treating them as secret-bearing blobs substantially raises compromise risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a comprehensive backup-and-restore/migration skill that can fully capture and recreate an Agent on another machine/framework. The supplied code chunk does not implement backup or restore mechanics. Instead, it acts as a workflow guard: listing five confirmation gates, recording confirmations to _confirm_gates.json, sampling rounds-*.jsonl files for manual review, and enforcing that all gates are confirmed before packaging. While this may support a larger migration system, this chunk’s actual purpose is materially narrower and different from the declared end-user capability. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是“完整备份并还原 Agent”,强调无损迁移与即用恢复;但提供的代码仅是 desensitize.py,一个可选的隐私副本配套脚本。其主要行为是通过正则识别敏感内容,对文本文件进行扫描或脱敏替换,生成占位符映射与凭据缺口说明,并在目录模式下复制文件到 _share 目录。代码中没有任何关于 Agent 状态导出、会话备份、记忆/人格序列化、工具配置迁移、环境重建、跨框架适配或恢复执行的实现。因此这不是对声明主功能的支持性细节,而是一个 materially different 的独立功能,构成明显描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个完整迁移/备份恢复能力,覆盖对话、记忆、人格、工具、环境,并强调可在新机器无感恢复。实际代码是单一脚本 environment_snapshot.py,其核心行为是环境元数据采集:探测系统和工具版本、扫描疑似配置/钩子/权限规则文件的路径、从指定 JSON 配置中提取模型相关非敏感字段,并做敏感信息自检后写入 JSON 文件。脚本没有读取或导出历史对话、记忆、人格数据,也没有打包备份、恢复写回、同步到目标机器、重建运行环境或执行任何还原流程。代码注释还明确说明‘只描述环境,不搬运隐私’、‘本快照用于目标环境对照补齐;凭据不经此文件传递’,这与声明中的‘完整备份并还原’存在明显且实质性的能力差距。因此属于描述与实际行为不符的明显 mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码块的主要功能是“备份运行入口校验”,属于流程前的守门脚本,而非实际的备份/还原实现。它解析命令行参数,验证任务名称是否合法、确认源和目标框架是否填写、检测备份目录是否位于被禁止的位置,并对在线平台给出警告。最终输出 JSON 结果并用退出码表示是否允许继续。与声明中“完整备份并还原 Agent 历史对话、记忆、人格、工具、环境”“跨框架跨电脑无感迁移”“零损失还原即用”等核心能力相比,代码行为明显更窄且不同,缺失了实际导出、复制、打包、恢复、重建环境等关键实现,因此属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about comprehensive backup and restoration of an agent’s state and history across platforms and frameworks. The actual code does not implement any backup, export, import, restore, migration, or agent-state handling. Instead, it is a repository release-check utility focused on version synchronization across scripts, checksum validation against _meta.json, file inventory completeness, and documentation terminology checks. Its optional write behavior updates metadata checksums, which is also unrelated to backup/restore. Therefore, the code’s actual primary purpose materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

描述宣称的是一个“完整备份并还原 Agent 全状态、跨框架跨机器无感迁移”的能力集合,范围包括对话、记忆、人格、工具、环境等。而实际代码是一个单独的 restore_dialogue.py 脚本,其核心行为是读取备份目录下的 JSONL 对话记录,按顺序生成 _restored_dialogue.md 和 _restored_stats.json,并附带对 _environment.json 的解析与提示。代码没有看到任何写回目标框架配置、恢复工具链、注入记忆/人格、重建运行环境、安装依赖、迁移多平台状态等行为。它更像“对话记录可读化/统计恢复工具”,仅覆盖声明中“历史对话还原”的一部分,且还是只读导出形式。因此描述显著夸大了该代码块的实际能力,构成明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a comprehensive backup/restore and cross-framework migration capability for agent state, including conversations, memory, persona, tools, and environment. However, the provided code does not perform backup, restoration, migration, replication, serialization of full agent state, or interaction with any agent framework. Its sole purpose is to validate JSONL files for formatting and sequencing correctness. While such validation could be a supporting utility within a migration toolkit, this code chunk by itself materially differs from the declared primary purpose and lacks the core advertised capabilities.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly directs preservation and restoration of raw conversations, memory, persona, environment, and private credential files in reusable packages. This creates a concentrated archive of high-value secrets and personal/contextual data that can be stolen, copied, or restored into an unintended agent or machine, enabling account compromise and broad privacy loss.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Requiring verbatim raw-conversation retention and inclusion of private credential files for immediate reuse maximizes data fidelity at the expense of confidentiality. If the backup package is exposed, an attacker gains not only sensitive transcripts but also operational secrets that may provide direct access to APIs, tools, or accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill prominently instructs backing up and restoring credentials and sensitive project state, but the warning posture is weak compared with the sensitivity of the data. Users are encouraged to bundle reusable secrets for convenience, which materially raises the risk of credential theft, accidental exfiltration, or reuse on an unintended system.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
字段结构(`scripts/environment_snapshot.py` 采集,纯 Python 标准库,mac/win/linux 尽力采集):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
字段结构(`scripts/environment_snapshot.py` 采集,纯 Python 标准库,mac/win/linux 尽力采集):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
字段结构(`scripts/environment_snapshot.py` 采集,纯 Python 标准库,mac/win/linux 尽力采集):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 347)May include surrounding context.

md
字段结构(`scripts/environment_snapshot.py` 采集,纯 Python 标准库,mac/win/linux 尽力采集):

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 406)May include surrounding context.

md
字段结构(`scripts/environment_snapshot.py` 采集,纯 Python 标准库,mac/win/linux 尽力采集):

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The privacy section states that the default behavior is no redaction and that credentials are bundled unchanged for private backup and machine migration. Defaulting to cleartext secret preservation is dangerous because 'private' backups are frequently copied, synced, misplaced, or opened in less-trusted environments, turning convenience into a high-impact compromise path.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The packaging step instructs that private-scenario credential files should be included unchanged in the backup package. This normalizes the creation of portable secret bundles, which are highly attractive targets and can be reused immediately if obtained by an attacker.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The restore procedure instructs direct reuse of packaged credentials so the environment works immediately. That bypasses an important safety boundary: destination-side user verification and fresh secret provisioning, making any leaked backup immediately operational for an attacker or unintended recipient.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/environment_snapshot.py (reported line 66)May include surrounding context.

python
FRAMEWORK_CONFIG_CANDIDATES = {
    "claude-code": [
        "~/.claude.json                       # 早期版本:全局配置(含项目历史)在此单文件",
        "~/.claude/settings.json              # 新版拆分:用户级设置移入 ~/.claude/ 目录",
    ],
    "codex": [
        "~/.codex/config.toml                 # macOS / Linux 默认位置",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/environment_snapshot.py (reported line 69)May include surrounding context.

python
"~/.claude/settings.json              # 新版拆分:用户级设置移入 ~/.claude/ 目录",
    ],
    "codex": [
        "~/.codex/config.toml                 # macOS / Linux 默认位置",
        "~/.config/codex/config.toml          # XDG 规范位置(部分安装方式使用)",
    ],
    "openclaw": [

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural-language content almost entirely in Chinese, but it does not state that Chinese is optional, user-selected, or limited to a China-specific audience. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.