安全决策报告

smyx-pet-oral-snapshot-gum-redness-analysis

Pet oral health analysis skill with undocumented network communication to third-party cloud services and obscured user identity management mechanisms.

安装决策优先 来源: ClawHub 扫描时间: 2 小时前
文件 31
IOC 12
越权项 3
发现 4
最直接的威胁证据

为什么得出这个结论

1/4 个维度触发
阻止
声明与实际能力

发现 3 项声明之外的能力或越权行为。

复核
隐藏执行与外联

提取到 12 个一般风险产物,需要结合上下文判断。

通过
攻击链与高危发现

没有形成明确的恶意路径。

复核
依赖与供应链卫生

发现 3 项需要关注的依赖或供应链线索。

风险分是怎么被拉高的

Undocumented network communication +20

SKILL.md does not explicitly declare that user images/videos are sent to external cloud services at lifeemergence.com

Obscured identity management +15

Skill silently creates user accounts via /sys/phoneLogin API and stores tokens in local SQLite database

Silent data persistence +10

Creates smyx-common-claw.db and smyx-api-key.txt in workspace data directory without explicit user consent

最关键的证据

中危 文档欺骗

Network communication not declared in SKILL.md

SKILL.md does not explicitly state that user-uploaded images/videos are sent to external cloud services. The skill-card.md documents this under 'Known Risks', but the main SKILL.md lacks this critical disclosure.

SKILL.md:1
Add explicit declaration in SKILL.md: 'This skill sends pet media to lifeemergence.com cloud services for analysis.'
中危 权限提升

Silent user identity creation

OpenIdUtil.resolve_current_open_id() silently creates user accounts by calling /sys/phoneLogin API and stores credentials in local SQLite database without explicit user consent.

skills/smyx_common/scripts/util.py:252
Provide clear documentation about identity creation or require explicit user opt-in
中危 敏感访问

Environment variable reading

Skill reads OPENCLAW_SENDER_OPEN_ID, OPENCLAW_SENDER_USERNAME, and FEISHU_OPEN_ID environment variables to auto-associate user identity. While not exfiltrating, this is undocumented behavior.

skills/smyx_common/scripts/config.py:90
Document all environment variables accessed by the skill
低危 文档欺骗

Silent file persistence

Skill creates smyx-common-claw.db and smyx-api-key.txt in workspace data directory for credential storage. This persistence mechanism is not declared in documentation.

skills/smyx_common/scripts/dao.py:38
Document local data storage behavior in SKILL.md

声明能力 vs 实际能力

文件系统 通过
声明 READ
→
推断 READ
SKILL.md references --input parameter for local file analysis
网络访问 阻止
声明 NONE
→
推断 WRITE
scripts/smyx_common/scripts/util.py - RequestUtil.http_post sends data to lifeemergence.com
数据库 阻止
声明 NONE
→
推断 WRITE
scripts/smyx_common/scripts/dao.py creates SQLite database in workspace
环境变量 阻止
声明 NONE
→
推断 READ
scripts/smyx_common/scripts/config.py reads OPENCLAW_SENDER_OPEN_ID, FEISHU_OPEN_ID

可疑产物与外联

中危 外部 URL
https://lifeemergence.com/sample.html

SKILL.md:38

中危 外部 URL
https://clawhub.ai/user/18072937735

skill-card.md:9

中危 外部 URL
https://clawhub.ai/18072937735/skills/smyx-pet-oral-snapshot-gum-redness-analysis

skill-card.md:43

中危 外部 URL
http://192.168.1.234:9601/smyx-open-api

skills/smyx_common/scripts/config-dev.yaml:2

中危 外部 URL
http://192.168.1.234:4100

skills/smyx_common/scripts/config-dev.yaml:3

中危 外部 URL
http://192.168.1.234:7070/jeecg-boot-xzgz

skills/smyx_common/scripts/config-dev.yaml:4

中危 外部 URL
https://livemonitortest.lifeemergence.com/smyx-open-api

skills/smyx_common/scripts/config-test.yaml:2

中危 外部 URL
http://livemonitortest.lifeemergence.com

skills/smyx_common/scripts/config-test.yaml:3

中危 外部 URL
https://healthtest.lifeemergence.com/jeecg-boot-xzgz

skills/smyx_common/scripts/config-test.yaml:4

中危 外部 URL
https://lifeemergence.com/jeecg-boot-xzgz

skills/smyx_common/scripts/config.yaml:4

中危 外部 URL
https://open.lifeemergence.com/smyx-open-api

skills/smyx_common/scripts/config.yaml:5

中危 外部 URL
http://livemonitor.lifeemergence.com

skills/smyx_common/scripts/config.yaml:6

依赖与供应链

包名版本来源漏洞备注
requests >=2.28.0 pip 否 Version requirement allows updates
pydash 8.0.6 pip 否 Properly pinned
SQLAlchemy 2.0.46 pip 否 Properly pinned
PyYAML 6.0.3 pip 否 Properly pinned

文件构成

31 个文件 · 2703 行
Python 18 个文件 · 2363 行Markdown 4 个文件 · 300 行YAML 6 个文件 · 29 行Text 2 个文件 · 6 行JSON 1 个文件 · 5 行
需关注文件 · 5
skills/smyx_common/scripts/util.py Python · 718 行
Silent user identity creation
skills/smyx_common/scripts/config.py Python · 399 行
Environment variable reading
skills/smyx_common/scripts/dao.py Python · 499 行
Silent file persistence
SKILL.md Markdown · 192 行
Network communication not declared in SKILL.md · https://lifeemergence.com/sample.html
skill-card.md Markdown · 64 行
https://clawhub.ai/user/18072937735 · https://clawhub.ai/18072937735/skills/smyx-pet-oral-snapshot-gum-redness-analysis
其他文件 · skill.py · smyx_analysis.py · smyx_pet_oral_snapshot_gum_redness_analysis.py · api_service.py · skill.py · api_service.py +1

安全亮点

No reverse shell or command execution backdoors detected
No credential harvesting or exfiltration to attacker-controlled endpoints
No base64-encoded or obfuscated malicious code
Dependencies are properly version-pinned (pydash==8.0.6, SQLAlchemy==2.0.46, PyYAML==6.0.3)
skill-card.md properly documents the known risks of cloud service communication
No curl|bash or wget|sh remote script execution
No access to sensitive paths like ~/.ssh, ~/.aws, or .env files
SQLite database creation is restricted to workspace data directory (proper isolation)