Back to skill

Security audit

ai-research-podcast

Security checks for vulnerabilities and agentic risk

Overview

The skill’s core article-to-audio purpose is coherent, but it needs review because it can create recurring network-fetch-and-send workflows while also making overly broad offline/privacy claims.

Install only if you are comfortable with the skill fetching URLs, reading supplied local documents, generating files under /tmp, and possibly sending generated audio to external messaging services. Treat scheduled mode as a separate opt-in feature: verify the source list, destination, credentials, and how to disable it before enabling. Avoid using sensitive or internal documents until the offline/privacy claims are corrected and dependency versions are pinned.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:81
Finding

Unpinned Third-Party Executable Dependencies

Content
View full analysis

Vulnerability Details

File Location: README.md:81-88; additional dependency declaration at workflow.json:55-57
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

README.md:81-88:

bash
# summarize CLI
npm install -g @openclaw/summarize-cli

# sherpa-onnx TTS
pip install sherpa-onnx
# Or use a precompiled version
brew install sherpa-onnx  # macOS

workflow.json:55-57:

json
"source": "clawhub",
"clawhub_id": "steipete/clawdis/sherpa-onnx-tts",
"role": "audio-generator",

Technical Analysis

The installation instructions do not pin exact package versions, verify integrity hashes, or identify immutable release artifacts. Consequently, package managers resolve mutable registry content at installation time. The ClawHub dependency is similarly identified only by a mutable Skill identifier, without a reviewed version, commit, or artifact digest.

Installing the npm package globally increases the potential effect of a compromised dependency because package installation hooks and executables may run with the invoking user's permissions and become available system-wide for that user. The audit did not establish that any currently referenced package is malicious; the vulnerability is the absence of controls that ensure users execute the same dependency versions that were reviewed.

Attack Path

  1. An attacker compromises an upstream publisher account, package registry release, transitive dependency, or mutable ClawHub artifact.
  2. The attacker publishes a malicious release under an existing referenced package or Skill identifier.
  3. A user follows the documented unversioned installation commands, or the workflow resolves the mutable ClawHub dependency.
  4. The package manager downloads the attacker-controlled version because no version, integrity hash, or immutable revision is enforced.
  5. Malicious installation hooks or runtime code ex ...[truncated 937 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every npm, Python, and Homebrew dependency to a specific reviewed version.
  2. Commit appropriate lockfiles and enable integrity verification for all resolved transitive dependencies.
  3. Reference the ClawHub Skill through an immutable version, commit, or cryptographic artifact digest rather than only a mutable identifier.
  4. Verify package signatures, checksums, publisher identity, and artifact provenance before installation.
  5. Avoid global npm installation. Install dependencies in a project-local, isolated environment with minimal permissions.
  6. Disable or carefully inspect package lifecycle scripts where operationally possible.
  7. Use an approved internal mirror or allowlist and continuously scan direct and transitive dependencies for compromise and known vulnerabilities.
  8. Document trusted download origins and a controlled dependency-update review process.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The optional push step sends generated audio to third-party messaging platforms but does not clearly warn that document-derived content may leave the local environment. If the summarized source contains confidential or regulated information, this can result in unauthorized disclosure to external services and recipients.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims '离线模式,无需联网,隐私安全' while its workflow explicitly supports HTTP/HTTPS fetching, daily arXiv retrieval, and optional external message delivery. This mismatch can mislead users into providing sensitive documents under a false assumption of offline processing, causing unintended data exposure over the network or to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The privacy note is misleading because it asserts offline and privacy-safe behavior even though the skill documentation includes remote fetching and external message delivery. Users relying on that statement may process sensitive files or URLs under incorrect assumptions, materially increasing the risk of confidentiality breaches.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, natural-language requests like “帮我听听这篇文章” and “生成播客版本”, which can overlap with ordinary conversation and cause the skill to activate in contexts the user did not intend. Because this skill can fetch external content, generate files, and potentially send outputs onward, accidental invocation could lead to unintended processing of user data and downstream actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README describes scheduled cron execution and outbound delivery to Feishu, WeChat, and email without clearly warning that the skill can create persistent automation and transmit generated content outside the local system. Users may not realize that enabling this workflow changes system state and can repeatedly process and exfiltrate potentially sensitive document summaries or audio on a schedule.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level trigger description is broad enough to match common requests such as '帮我听听这篇文章' or '生成播客版本' without clearly constraining source type, data sensitivity, or whether network access will occur. Overbroad activation increases the chance the skill runs unexpectedly on content the user did not intend to export, summarize, or synthesize.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger section adds multiple ambiguous phrases such as 'URL 转语音' and '研报速读' that could overlap with ordinary assistant requests and activate the skill too easily. In a system with multiple skills or sensitive local content, ambiguous triggers can cause unintended processing or data movement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow supports remote URL retrieval but does not warn users that providing a URL causes network access and remote content fetching. This omission matters because users may assume a local-only transformation and may unknowingly submit sensitive or internal links for retrieval and processing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The TTS command hard-codes --voice zh_CN-female, which imposes a specific language/locale setting. The document does not state that users can choose another locale or that the Chinese voice is merely a default.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented ability to set recurring scheduled tasks extends the skill from one-time document-to-audio conversion into ongoing autonomous data collection and delivery. Without clearly scoped authorization, this can cause persistent background access, repeated network retrieval, and repeated dissemination of generated content beyond what a user may have intended.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest presents the skill as a user-initiated article-to-audio converter, but it also includes a scheduled trigger that autonomously fetches external content and pushes results to downstream channels. This mismatch can mislead users and operators about the skill's actual behavior, increasing the risk of unintended network access, unattended processing, and silent data distribution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatic delivery to Feishu, WeChat, or email expands the skill from local audio generation into external data transmission. If summaries or generated audio contain sensitive report content, this can cause unintended disclosure to third-party platforms or recipients without sufficiently prominent user warning.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The scheduled trigger runs daily and is described broadly as automatically fetching and converting content, which is risky for unattended activation. Broad autonomous behavior can lead to unexpected external requests, processing of unreviewed content, and repeated operation without clear user awareness or approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The scheduled configuration combines automatic remote fetching from arXiv with push delivery to Feishu, but the manifest does not prominently warn users that content and derived outputs may traverse external services. This lack of disclosure undermines informed consent and can expose proprietary or sensitive processed material through unattended transmission paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The available voice options include multiple locales, but the default is fixed to 'zh_CN-female', which imposes a language/locale choice unless the user explicitly changes it. This is a natural-language locale policy concern because the skill does not state that the default language is optional or justify why Chinese is the enforced default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.