Back to skill

Security audit

markdownknowledge

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate local Markdown search purpose, but the published package includes private indexed data and credentials and may install an unverified executable during setup.

Review before installing. Do not install this release as-is unless the bundled index is removed, exposed credentials are rotated, and setup no longer downloads or installs ripgrep without explicit consent and integrity verification. If used, configure a narrow knowledge_path and keep secrets out of Markdown notes because search results can inject note content into conversations.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
index.json:44
Finding

Bundled API Key and Request-Signing Secret

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.json:3
Finding

Distribution of a Private User Knowledge Index and Absolute Filesystem Metadata

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/knowledge_base.py:31
Finding

Unverified Remote Executable Download and Unsafe Archive Extraction

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
clawhub.json:103
Finding

Runtime Network and Executable-Write Behavior Exceeds Declared Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
Findings (35)

Scope Creep

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest permissions only declare Markdown reads and index-file writes, but the documented init behavior includes installing ripgrep, which can modify the system outside the declared permission scope. This mismatch undermines transparency and any permission-based trust model, because users and tooling may approve the skill expecting limited file access while the actual behavior performs broader system changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The index exposes a live third-party Web service API key and associated private signing secret inside searchable knowledge content. Anyone with access to this skill or index can extract and abuse those credentials for unauthorized API usage, quota exhaustion, billing/availability impact, and possible impersonation of legitimate requests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script contains built-in remote software download and installation logic for a knowledge-base CLI, which expands the trust boundary from local indexing to arbitrary network retrieval and code placement. Because the downloaded artifact is installed without strong integrity verification such as signature or pinned checksum validation, compromise of the release channel, transport, or implementation errors could lead to execution of untrusted code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "查看知识库" is broad and can plausibly match ordinary user requests to view or discuss the knowledge base rather than explicitly request the stats action. That can cause unintended action execution, which is a real security and safety issue because the skill is designed to react to natural-language triggers and may disclose repository metadata or alter agent behavior unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The install flow includes shell execution and writes an index/config file, while the changelog indicates init may also install ripgrep, yet the user-facing installation section does not prominently warn about these system and data changes. Lack of explicit disclosure increases the chance of uninformed execution, especially for users who expect a passive knowledge-base integration rather than commands that alter the environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog states that the init flow auto-detects and installs ripgrep across platforms, which expands the skill's behavior beyond indexing local Markdown files into system modification and package management. Auto-installing software through a shell-driven initialization step can surprise users, introduce supply-chain risk, and execute privileged or platform-specific install logic not clearly constrained by the manifest.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON index embeds many document summaries and titles that explicitly constrain content language, such as repeated '语言: 英文', '语言: 荷兰语', and China-specific locale framing like '北京时间' and '依据中国气象局...编写'. Because the file is a manifest-style metadata index consumed by other systems, these natural-language declarations can enforce language or locale behavior without presenting any opt-in or alternative choice to the user.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented search triggers include very broad natural-language phrases such as 'In the knowledge' and similar variants. In an agent setting, overly permissive trigger matching can cause unintended search execution during ordinary conversation, which may expose local knowledge snippets and alter model behavior without clear user intent.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/PROJECT.md (reported line 264)May include surrounding context.

bash
# 1. Check if skill is installed
ls -la ~/.openclaw/skills/markdown-knowledge/

# 2. View knowledge base statistics
python3 ~/.openclaw/skills/markdown-knowledge/scripts/knowledge_base.py stats

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/PROJECT.md (reported line 828)May include surrounding context.

bash
# 1. Check if skill is installed
ls -la ~/.openclaw/skills/markdown-knowledge/

# 2. View knowledge base statistics
python3 ~/.openclaw/skills/markdown-knowledge/scripts/knowledge_base.py stats

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/PROJECT.md (reported line 1331)May include surrounding context.

bash
# 1. Check if skill is installed
ls -la ~/.openclaw/skills/markdown-knowledge/

# 2. View knowledge base statistics
python3 ~/.openclaw/skills/markdown-knowledge/scripts/knowledge_base.py stats

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/PROJECT.md (reported line 1829)May include surrounding context.

bash
# 1. Check if skill is installed
ls -la ~/.openclaw/skills/markdown-knowledge/

# 2. View knowledge base statistics
python3 ~/.openclaw/skills/markdown-knowledge/scripts/knowledge_base.py stats

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The documentation explicitly describes autonomous execution: file changes can trigger index updates, and matching a trigger word can execute search and inject context automatically. Autonomous actions over local content increase the risk of unintended processing and disclosure, especially when coupled with broad trigger matching.

Content

Scanner excerpt · references/PROJECT.md (reported line 375)May include surrounding context.

md
**Auto-Trigger Conditions:**

| Trigger Type | Condition | Auto Execute |
|--------------|-----------|-------------|
| `auto_refresh` | Config enabled + file change detected | Incrementally update index |
| Search request | Message contains trigger word | Execute search and inject context |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The auto-trigger rule states that any message containing a trigger word may execute search and inject context. This creates an intent-confusion issue where incidental wording can cause retrieval of local files and context insertion, potentially leaking sensitive content from the user's knowledge base into the conversation.

Content

No source excerpt is available for this finding.

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

The example workflow encourages the AI to save new conversation-derived content into the persistent knowledge base and link it with existing content. Persistent memory writes can turn prompt-injected or incorrect content into durable context that affects future sessions, creating a cross-session poisoning risk.

Content

Scanner excerpt · references/PROJECT.md (reported line 504)May include surrounding context.

Example:

text
User: AI, I just learned about MOPD (Multi-Teacher On-Policy Distillation) from this paper.
AI: Should I save this to your knowledge base?
User: Yes, save under "AI学习/模型训练" with tags: [AI, 蒸馏, MOPD]
AI: ✅ Saved! Want me to connect it with existing knowledge about model training?

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/PROJECT.md (reported line 649)May include surrounding context.

5.4 How to Customize

Step 1: Create or edit config file

bash
nano ~/.openclaw/skills/markdown-knowledge/config.json

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/PROJECT.md (reported line 835)May include surrounding context.

md
# Confirm knowledge_path points to correct directory

Step 3: Check file permissions
        chmod 755 ~/.openclaw/skills/markdown-knowledge/
        
Step 4: Rebuild
        python3 knowledge_base.py build

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/PROJECT.md (reported line 1836)May include surrounding context.

md
# Confirm knowledge_path points to correct directory

Step 3: Check file permissions
        chmod 755 ~/.openclaw/skills/markdown-knowledge/
        
Step 4: Rebuild
        python3 knowledge_base.py build

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Chinese trigger phrases are similarly broad and likely to overlap with normal speech. In multilingual deployments this raises the chance of accidental invocation, causing unintended searches over local content and expanding exposure of stored knowledge.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Chinese auto-trigger rule allows any message containing trigger words to execute search. This is a real security design issue because it increases the probability of unintended retrieval and context injection from local documents, especially when users discuss the knowledge base descriptively rather than issuing a command.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation, trigger phrases, example queries, and user-facing guidance are written entirely in Chinese, including the prescribed invocation commands and AI response wording. This effectively imposes a language/locale requirement without opt-in or justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The helper is presented as a check for ripgrep, but it actually downloads an archive from the internet, extracts it, and writes a binary into the user's local bin directory. That mismatch is security-relevant because users and calling agents may invoke initialization expecting a harmless dependency check while instead causing a system modification and network fetch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code modifies the user's environment by downloading and installing ripgrep into ~/.local/bin without any interactive confirmation or prior warning. In an agent-executed context, silent system modification is particularly risky because the action may occur non-interactively and bypass the user's expectation of read-only or low-impact behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Initialization writes a configuration file and immediately builds an index over a user-supplied or guessed directory, which processes potentially large amounts of local data without an explicit warning or confirmation step. In a skill or agent setting, automatically scanning user directories can expose sensitive file metadata and contents to later components and is more dangerous than in a standalone local CLI because the action may be triggered indirectly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.