Back to skill

Security audit

Reminder Guardian

Security checks for vulnerabilities and agentic risk

Overview

This skill is a manual reminder logger that stores reminders locally and prints cron blueprints, with some implementation hygiene issues but no hidden exfiltration, destructive action, or automatic scheduling.

Before installing, treat reminder text and notes as potentially private because they are saved to a local JSON file. Verify the storage path and file permissions in your environment, and expect to create any OpenClaw cron job manually from the printed blueprint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/reminder_guard.py:8
Finding

Predictable Shared Temporary Storage Enables Reminder Disclosure and Symbolic-Link Attacks

Content
View full analysis
list[dict]: LOG_PATH.parent.mkdir(parents=True, exist_ok=True) if not LOG_PATH.exists(): LOG_PATH.write_text("[]", encoding="utf-8") try: return json.loads(LOG_PATH.read_text(encoding="utf-8")) except json.JSONDecodeError as exc: raise RuntimeError(f"Corrupted reminder log: {exc}") def save_log(entries: list[dict]) -> None: LOG_PATH.write_text(json.dumps(entries, indent=2, ensure_ascii=False), encoding="utf-8") ``` ### Technical Analysis In the supplied project layout, `Path(__file__).resolve().parents[3]` resolves to `/tmp`. Consequently, the reminder log is written to the predictable shared path: ```text /tmp/memory/reminder-log.json ``` The code creates and accesses this path using `mkdir`, `Path.exists`, `read_text`, and `write_text` without validating ownership, rejecting symbolic links, enforcing private permissions, or using race-resistant file operations. On systems with a typical umask of `022`, a newly created directory and file may receive permissions equivalent to `0755` and `0644`. Reminder messages, labels, notes, and timestamps may therefore be readable by other local users. The check followed by write also creates a time-of-check/time-of-use condition. Python's ordinary path-based reads and writes follow symbolic links. A local attacker who can prepare or modify the predictable path can redirect log operations to another file writable by the victim process. The attacker can also supply malformed or manipulated JSON to co ...[truncated 2252 chars]
Remediation
View remediation
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill helps remember things by maintaining reminders, scheduling alerts, and tracking completed items. The actual code does none of those things. It only reads an optional command-line argument, parses a simple future time offset, and outputs an ISO-formatted timestamp or an error string. While time calculation could be a supporting utility for a reminder system, this code chunk by itself does not implement the stated reminder-management behavior, so the description does not accurately represent the supplied code.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/reminder_guard.py (reported line 24)May include surrounding context.

python
cmd = ["python3", str(TIME_HELPER)]
    if offset:
        cmd.append(offset)
    result = subprocess.run(cmd, capture_output=True, text=True)
    output = result.stdout.strip()
    if not output:
        raise RuntimeError("Time helper did not return anything")

Static analysis

No suspicious patterns detected.