ai-redaction-beta
该Skill声称本地独立处理但实际依赖外部API,存在数据外泄风险但无直接恶意代码执行证据
Why this conclusion was reached
2/4 dimensions flagged1 undeclared or violating capabilities were inferred.
1 lower-risk artifacts were extracted and still need context.
The report includes 3 attack-chain steps and 1 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
Attack Chain
Entry · SKILL.md:96
Escalation · dist/index.d.ts:20
Impact · SKILL.md:98
What drove the risk score up
声称'个人独立模式'、'纯本地',但实际所有文件上传到外部API
文件内容发送到https://apiconsole.bestcoffer.com.cn,用户无法控制数据流向
仅有TypeScript声明文件和Shell包装脚本,无法验证实际行为
Most important evidence
文件数据发送到外部API
Skill声称'数据全程在BestCoffer加密环境处理,绝不离开安全边界',但实际将用户文件上传到apiconsole.bestcoffer.com.cn。用户文件内容无法在本地验证是否被存储或转发。
dist/index.d.ts:20 声称本地独立模式但依赖外部API
SKILL.md多次强调'纯个人独立模式'、'完全在OpenClaw内完成',但所有文件处理都通过外部API完成。用户上传文件后必须等待外部服务处理。
SKILL.md:68 缺少源代码验证
该Skill仅提供TypeScript声明文件(dist/index.d.ts)和Shell包装脚本(scripts/run.sh),没有可执行的JavaScript源代码。用户无法验证实际行为是否与声明一致。
dist/ Declared capability vs actual capability
SKILL.md声明'接收单个文件' 实际将文件POST到外部API,但文档未声明 SKILL.md声明检查apiKey环境变量 Suspicious artifacts and egress
https://apiconsole.bestcoffer.com.cn SKILL.md:98
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md dist/index.d.ts