安全决策报告

zulip-bridge

Legitimate Zulip messaging bridge plugin with no malicious behavior, proper credential handling, and strong security controls including SSRF protection, path traversal mitigation, and local file exfiltration prevention.

安装决策优先 来源: 手动上传 扫描时间: 2026/4/3
文件 46
IOC 15
越权项 0
发现 1

为什么得出这个结论

1/4 个维度触发
通过
声明与实际能力

声明资源与推断能力基本一致。

阻止
隐藏执行与外联

提取到 1 个高危 IOC 或外联信号。

通过
攻击链与高危发现

没有形成明确的恶意路径。

通过
依赖与供应链卫生

依赖结构存在,但暂未看到明显高危告警。

风险分是怎么被拉高的

No shell execution detected +0

No subprocess, exec, or spawn calls found

No obfuscation or suspicious encoding +0

Clean codebase with no base64/eval patterns

Credential access is legitimate +0

ZULIP_* env vars read only for Zulip API auth, not exfiltrated

Network calls restricted to configured Zulip server +0

All HTTP requests go to the user's own Zulip instance

Proactive security hardening present +-5

SSRF protection in uploads.ts, path traversal sanitization, local file exfiltration prevention

最关键的证据

低危 敏感访问

Filesystem read access for config loading

The skill reads configuration from ~/.openclaw/openclaw.json. This is necessary for the core messaging functionality and documented in SKILL.md.

src/zulip/accounts.ts:84
No action needed. This is legitimate access for credential retrieval.

声明能力 vs 实际能力

网络访问 通过
声明 READ
→
推断 READ
HTTP requests only to configured Zulip server
环境变量 通过
声明 READ
→
推断 READ
Only reads ZULIP_API_KEY, ZULIP_EMAIL, ZULIP_URL (legitimate)
文件系统 通过
声明 NONE
→
推断 READ
Reads ~/.openclaw/openclaw.json; temp files for uploads (both documented and necessary)
命令执行 通过
声明 NONE
→
推断 NONE
No subprocess/exec calls found
技能调用 通过
声明 NONE
→
推断 NONE
No skill invocation
剪贴板 通过
声明 NONE
→
推断 NONE
No clipboard access
浏览器 通过
声明 NONE
→
推断 NONE
No browser access
数据库 通过
声明 NONE
→
推断 NONE
No database access

可疑产物与外联

高危 API 密钥
apiKey: "other-config-api-key"

test/accounts.test.ts:74

中危 外部 URL
https://chat.example.com

docs/config.md:14

中危 外部 URL
https://staging.example.com

docs/config.md:142

中危 外部 URL
https://chat.example.com.

src/config-ui-hints.ts:18

中危 外部 URL
https://docs.openclaw.ai/channels/zulip

src/onboarding.ts:27

中危 外部 URL
https://env.zulipchat.com

test/accounts.test.ts:20

中危 外部 URL
https://config.zulipchat.com

test/accounts.test.ts:47

中危 外部 URL
https://other.zulipchat.com

test/accounts.test.ts:76

中危 外部 URL
https://zulip.example.com

test/client.test.ts:16

中危 外部 URL
https://zulip.example.com/user_uploads/1/abc/test.png

test/path-traversal.test.ts:7

中危 外部 URL
https://zulip.example.com/user_uploads/3/hash789/full.pdf

test/smoke.test.ts:14

中危 外部 URL
https://zulip.example.com/user_uploads/1/abc-123/file.png

test/smoke.test.ts:20

依赖与供应链

包名版本来源漏洞备注
openclaw >=2026.3.23 <2027 peerDependency 否 Peer dependency, platform-provided
zod indirect via overrides npm 否 Override to prevent unused dependency bloat

文件构成

46 个文件 · 6956 行
TypeScript 34 个文件 · 6178 行Markdown 7 个文件 · 602 行JSON 4 个文件 · 158 行JavaScript 1 个文件 · 18 行
需关注文件 · 3
src/onboarding.ts TypeScript · 377 行
https://docs.openclaw.ai/channels/zulip
docs/config.md Markdown · 154 行
https://chat.example.com · https://staging.example.com
src/zulip/accounts.ts TypeScript · 170 行
Filesystem read access for config loading
其他文件 · monitor.ts · actions.ts · client.ts · channel.ts · policy.test.ts · send.ts +3

安全亮点

SSRF protection: upload downloads restricted to configured Zulip server origin (src/zulip/uploads.ts:100-101)
Path traversal sanitization: Content-Disposition filenames sanitized with path.basename() (src/zulip/uploads.ts:70)
Local file exfiltration prevention: mediaUrl rejects non-HTTP protocols with security warning logging (src/zulip/send.ts:146-150)
Realm setting allowlist: Only safe settings like 'name', 'description' can be updated (src/actions.ts:36)
String length validation: All user inputs capped at 10000 chars to prevent DoS
No external network calls outside of the configured Zulip server
No obfuscation, no base64-encoded payloads, no eval() calls
Comprehensive security test suite including path-traversal and send-security tests
Credential access limited to ZULIP_* prefixed env vars only for the default account
Minimal dependencies with no untrusted external packages