Back to skill

Security audit

内部工作流助手

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real OpenCreator workflow helper, but it needs review because it can send user media to public file hosts and run production API jobs without a clear consent and privacy boundary.

Install only if you intentionally want an agent to use OpenCreator production APIs. Do not provide confidential, regulated, unreleased, biometric, or sensitive media unless you are comfortable with it being sent to OpenCreator and possibly public temporary file hosts; prefer user-controlled or authenticated storage links and require confirmation before uploads or workflow runs. Pin installer versions or use a reviewed ClawHub install path where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/api-workflows.md:408
Finding

Unconsented Upload of User Media to Public Third-Party File Hosts

Content
View full analysis

Vulnerability Details

File Location: references/api-workflows.md:408-418
Vulnerability Type: Insecure handling and external disclosure of user-provided media
Risk Level: Medium

Vulnerable Code

markdown
## 9. 媒体文件托管(用户发来的图片/视频需上传)

OpenCreator 输入只接受直链 URL,本地文件需先上传托管。

| 优先级 | 服务 | 适用 | 命令 |
|---|---|---|---|
| 1 | **tmpfiles.org** | 视频 + 图片 | `curl -F "file=@file.mp4" https://tmpfiles.org/api/v1/upload` |
| 2 | **catbox.moe** | 仅图片 | `curl -F "reqtype=fileupload" -F "fileToUpload=@file.png" https://catbox.moe/user/api.php` |
| 3 | 告知用户 | — | 全部失败时暂停,请用户提供直链 |

> ⚠️ **tmpfiles 必须把 URL 改成 `/dl/` 直链**:
> `http://tmpfiles.org/12345/file.mp4` → `http://tmpfiles.org/dl/12345/file.mp4`

Technical Analysis

The mandatory workflow documentation instructs the agent to upload locally supplied user images and videos to tmpfiles.org or catbox.moe. These services are separate from the declared OpenCreator production API.

The upload procedure does not require:

  • Explicit informed consent before disclosure to the third party
  • A check for personal, confidential, proprietary, or regulated content
  • Authentication or access controls for the resulting media URL
  • A documented retention period or deletion procedure
  • Verification of the service's privacy and security guarantees
  • Confirmation that the user is authorized to redistribute the media
  • HTTPS for every subsequent retrieval operation

The example converts the upload response into an http:// download URL. If followed literally, this may expose media retrieval to passive monitoring, content substitution, or link manipulation on an untrusted network.

Although uploading media is functionally related to providing URL-based input to OpenCreator, automatically using unrelated public file hosts exceeds the minimum privacy-preserving scope required. First-party authenticated storage, user-controlled storage, or an explicit consent boun ...[truncated 1558 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace public third-party hosts with authenticated, first-party OpenCreator upload storage.
  2. If first-party storage is unavailable, require the user to provide a URL from storage they control.
  3. Before any third-party upload, obtain explicit consent identifying:
    • The destination service
    • The type of data being uploaded
    • The possibility of public URL access
    • Applicable retention and deletion limitations
  4. Reject or pause uploads involving confidential, regulated, biometric, or otherwise sensitive media unless an approved private storage path is available.
  5. Use HTTPS exclusively. Remove the documented http://tmpfiles.org conversion example.
  6. Prefer short-lived, signed URLs with narrowly scoped read access.
  7. Strip unnecessary metadata, including EXIF and location data, before upload when the user approves.
  8. Document deletion and retention procedures and, where supported, delete temporary media immediately after workflow completion.
  9. Avoid printing upload URLs in logs and redact them from diagnostic output.
  10. Add an allowlist for approved storage domains and prevent arbitrary fallback uploads.

T08 · Insecure Dependencies

Note
Location
README.md:23
Finding

Unpinned npm CLI and Mutable Repository Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:23-32
Vulnerability Type: Unpinned executable dependency and mutable installation source
Risk Level: Low

Vulnerable Code

markdown
### Via `npx`

Install directly from the GitHub repository using the `skills` CLI:

```bash
npx skills add OpenCreator-ai/opencreator-skills

Install for a specific agent:

bash
npx skills add OpenCreator-ai/opencreator-skills -a codex
text

### Technical Analysis

The installation instructions invoke `npx skills` without specifying an exact package version. Depending on the local npm configuration and cache state, `npx` may resolve and execute the currently published version of the `skills` package at installation time.

The repository argument, `OpenCreator-ai/opencreator-skills`, is also not pinned to a commit, release tag, or verified artifact digest. Consequently, the code and Skill instructions installed by a future invocation may differ from the version covered by this audit.

This is a supply-chain weakness rather than evidence that the current package is malicious. Exploitation requires compromise, replacement, or malicious modification of the npm package, its dependency chain, the referenced repository, or the package-resolution path.

### Attack Path

1. A user copies the documented `npx skills add` command.
2. npm resolves an unversioned release of the `skills` CLI.
3. `npx` executes the resolved package with the invoking user's local privileges.
4. The CLI retrieves content from a mutable repository reference.
5. If the npm package, a transitive dependency, the repository, or a maintainer account has been compromised, altered code or Skill instructions are installed.
6. Malicious installation logic could execute immediately, while malicious Skill instructions could activate when the installed Skill is later loaded.

### Impact Assessment

A compromised npm CLI or installation dependen
...[truncated 756 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an exact reviewed version, for example:
    bash
    npx --yes skills@X.Y.Z add OpenCreator-ai/opencreator-skills
    
  2. Pin the Skill repository to a signed release tag or immutable commit identifier.
  3. Publish cryptographic checksums or signed provenance for release artifacts.
  4. Document the expected package name, publisher, version, and integrity digest so users can verify resolution before execution.
  5. Recommend installing in a restricted environment without unnecessary credentials or elevated privileges.
  6. Avoid running the installer with sudo or an administrator account.
  7. Use lockfiles and dependency integrity metadata for any maintained installer implementation.
  8. Add automated dependency and provenance monitoring for the npm CLI and repository releases.
  9. Where possible, offer a non-executing installation method that downloads a fixed archive for inspection before local placement.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (75)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-workflows.md (reported line 333)May include surrounding context.

任务卡 queued 超过 5 分钟 → 大概率是 inputs 格式错了(双重嵌套),用以下命令确认:

bash
curl -s "https://api-prod.opencreator.io/api/developer/v1/workflow-runs/{task_id}" \
  -H "X-API-Key: $API_KEY" | python3 -c "
import json,sys
d=json.load(sys.stdin)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill tells the agent to upload user media to third-party hosts without a clear user-facing privacy notice or consent step. That can silently transfer personal, confidential, or copyrighted media to external services, creating privacy, compliance, and trust risks that are especially acute for a content-generation workflow handling user assets.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-workflows.md (reported line 429)May include surrounding context.

创建空工作流

bash
curl -s -X POST "https://api-prod.opencreator.io/api/developer/v1/workflows" \
  -H "X-API-Key: $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "我的工作流名称"}'

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-workflows.md (reported line 429)May include surrounding context.

创建空工作流

bash
curl -s -X POST "https://api-prod.opencreator.io/api/developer/v1/workflows" \
  -H "X-API-Key: $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "我的工作流名称"}'

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-workflows.md (reported line 485)May include surrounding context.

md
-H "X-API-Key: $API_KEY" | python3 -m json.tool

# ② 复制模板
FLOW_ID=$(curl -s -X POST "$BASE/api/developer/v1/workflows/from-template" \
  -H "X-API-Key: $API_KEY" -H "Content-Type: application/json" \
  -d '{"template_id": "template_xxx"}' \
  | python3 -c "import json,sys; print(json.load(sys.stdin)['flow_id'])")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-workflows.md (reported line 492)May include surrounding context.

md
echo "flow_id: $FLOW_ID"

# ③ 查参数
curl -s "$BASE/api/developer/v1/workflows/$FLOW_ID/parameters" \
  -H "X-API-Key: $API_KEY" | python3 -m json.tool

# ④ 运行(根据查到的 node_id 填 inputs)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-workflows.md (reported line 496)May include surrounding context.

md
-H "X-API-Key: $API_KEY" | python3 -m json.tool

# ④ 运行(根据查到的 node_id 填 inputs)
TASK=$(curl -s -X POST "$BASE/api/developer/v1/workflows/$FLOW_ID/runs" \
  -H "X-API-Key: $API_KEY" -H "Content-Type: application/json" \
  -d '{
    "inputs": {

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-workflows.md (reported line 511)May include surrounding context.

md
# ⑤ 轮询(视频 workflow 用 30s,生图用 10s)
for i in $(seq 1 20); do
  sleep 30
  STATUS=$(curl -s "$BASE/api/developer/v1/workflow-runs/$TASK" \
    -H "X-API-Key: $API_KEY" \
    | python3 -c "import json,sys; print(json.load(sys.stdin)['status'])")
  echo "[$(date -u +%H:%M:%S)] $STATUS"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-workflows.md (reported line 519)May include surrounding context.

md
done

# ⑥ 取结果
curl -s "$BASE/api/developer/v1/workflow-runs/$TASK/results" \
  -H "X-API-Key: $API_KEY" | python3 -c "
import json,sys
d=json.load(sys.stdin)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document explicitly says the skill must only output abstract modules and must not include implementation details, but later introduces concrete generator names, node identifiers, model preferences, and routing guidance. This creates a scope-boundary violation that can cause downstream agents to bypass separation-of-concerns controls and make implementation choices the skill was supposed to avoid, increasing the chance of unsafe or unauthorized workflow construction.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/step-4-prompts/text-prompt-best-practices.md (reported line 26)May include surrounding context.

md
---

## 1. Core Output Rules

These rules should be treated as mandatory defaults unless the user explicitly asks otherwise.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes submitting product images, descriptions, videos, and workflow data to the production OpenCreator API but does not clearly warn users that these inputs are transmitted to a third-party production service. This creates a meaningful privacy and data-handling risk because users may provide sensitive media, business content, or proprietary workflow information without informed consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README instructs users to provide an API key and use the production OpenCreator endpoint, and elsewhere states the skill operates on user-supplied images, videos, audio, and product materials. Without an explicit privacy/data-handling warning, users may unknowingly send sensitive credentials and media to a third-party production service, increasing the risk of unintended disclosure or non-compliant data transfer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The Operate Mode description explicitly automates template copying, workflow execution, polling, and result delivery against a production API, but it does not warn that these actions create or modify remote resources and may incur charges or other external side effects. In this skill context, that omission is more significant because the documented purpose is to trigger real content-generation workflows using production infrastructure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list is broad enough to match generic content-creation requests such as 'workflow', 'template', or 'content creation pipeline', which can cause the skill to activate outside a clearly intended OpenCreator context. Over-broad activation increases the chance that unrelated user content is routed to this skill and then transmitted to an external API, creating scope creep, privacy risk, and unintended third-party data disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation guidance uses vague categories like 'similar content creation' and defaults to Operate Mode first, but does not define clear exclusion conditions. In context, this is risky because the skill is designed to search, copy, run workflows, and deliver results through an external service, so ambiguous activation can lead to unintended execution paths and data sharing for requests that should have stayed local or used another skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to collect user inputs, run workflows, poll results, and deliver generated media, but it does not warn the user that their prompts, media, and workflow data will be sent to the OpenCreator API. This omission is dangerous because users may disclose sensitive text, images, or business assets without informed consent, and the skill's 'always' operational rules increase the likelihood of automatic external transmission once activated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction says that when Chinese keywords do not return results, the system should automatically translate them into English and retry. This imposes a language/locale behavior without explicitly asking the user whether they want cross-language search or English-based matching.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-workflows.md (reported line 142)May include surrounding context.

⚠️ 必须复制,不能直接用搜索结果里的 origin_flow_id 跑,公共模板只读。

bash
curl -s -X POST "https://api-prod.opencreator.io/api/developer/v1/workflows/from-template" \
  -H "X-API-Key: $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"template_id": "template_xxx"}'

Static analysis

No suspicious patterns detected.