Skill Trust Decision

migu-ai-creative-photo

使用 Node.js 标准库实现咪咕旅游照片合成服务,存在 User-Agent 伪装异常和 --insecure 跳过证书验证选项,但无明确恶意行为证据

Install decision first Source: ClawHub Scanned: 1 day ago
Files 4
Artifacts 3
Violations 0
Findings 3
Most direct threat evidence
High IP Address
152.0.0.0

Why this conclusion was reached

1/4 dimensions flagged
Pass
Declared vs actual capability

Declared resources and inferred behavior are broadly aligned.

Block
Hidden execution and egress

1 high-risk artifacts or egress signals were extracted.

Pass
Attack chain and severe findings

There is no explicit malicious chain in the report.

Review
Dependencies and supply chain hygiene

Dependency information is incomplete, so supply-chain confidence stays limited.

What drove the risk score up

User-Agent 伪装异常 +20

Chrome/152.0.0.0 版本号格式异常,line 19: 'Chrome/152.0.0.0 Mobile Safari/537.36'

可选的不安全模式 +15

支持 --insecure 跳过 TLS 证书验证,可能被用于中间人攻击

凭证文件写入 +10

--save-token-stdin 允许写入 secrets/plan_multi_token.txt

Most important evidence

Medium Obfuscation

User-Agent 版本号格式异常

User-Agent 中 Chrome 版本号 '152.0.0.0' 格式不符合正常 Chrome 版本号规范(应为 152.0.xxx.x),可能用于绕过基于版本检测的过滤规则

scripts/migu_ai_creative_photo_client.mjs:19
确认是否为故意伪装,若是正常 API 调用应使用真实 User-Agent
Medium Sensitive Access

支持跳过 TLS 证书验证

--insecure 选项允许通过 rejectUnauthorized: false 跳过 HTTPS 证书验证,存在中间人攻击风险

scripts/migu_ai_creative_photo_client.mjs:53
生产环境不应使用 --insecure 选项,明确告知用户风险
Low Credential Theft

Token 保存命令支持外部输入

--save-token-stdin 从 stdin 读取 JWT 并写入本地文件,属于正常功能但存在被滥用可能

scripts/migu_ai_creative_photo_client.mjs:133
确保该功能仅通过 CLI 管道使用,不被远程调用

Declared capability vs actual capability

Filesystem Pass
Declared WRITE
→
Inferred WRITE
SKILL.md:59-62, migu_ai_creative_photo_client.mjs:134
Network Pass
Declared READ
→
Inferred READ
SKILL.md:30, migu_ai_creative_photo_client.mjs:88-97
Environment Pass
Declared READ
→
Inferred READ
migu_ai_creative_photo_client.mjs:75-79

Suspicious artifacts and egress

High IP Address
152.0.0.0

scripts/migu_ai_creative_photo_client.mjs:19

Medium External URL
https://gulangyu.migudm.cn

SKILL.md:30

Medium External URL
https://gulangyu.migudm.cn/multi-city-trip-agent/

scripts/migu_ai_creative_photo_client.mjs:15

Dependencies and supply chain

There are no structured dependency warnings.

File composition

4 files · 262 lines
JavaScript 1 files · 180 linesMarkdown 1 files · 71 linesJSON 1 files · 10 linesText 1 files · 1 lines
Files of concern · 2
scripts/migu_ai_creative_photo_client.mjs JavaScript · 180 lines
User-Agent 版本号格式异常 · 支持跳过 TLS 证书验证 · Token 保存命令支持外部输入 · 152.0.0.0 · https://gulangyu.migudm.cn/multi-city-trip-agent/
SKILL.md Markdown · 71 lines
https://gulangyu.migudm.cn
Other files · package.json · creative_photo_session.txt

Security positives

仅使用 Node.js 标准库,无第三方依赖风险
SKILL.md 完整声明了所有功能和权限
代码行为与文档描述一致
JWT token 有完整的清洗和验证逻辑
未发现代码执行、远程脚本下载或数据外泄行为
会话 ID 和 token 存储在 skill 私有目录