Back to skill

Security audit

Movie Manager

Security checks for vulnerabilities and agentic risk

Overview

This movie-organizer skill is mostly coherent, but it can create cron reminders and may read unspecified recent logs without enough user control or scoping.

Install only if you are comfortable with the skill creating and moving files in your Obsidian Movies folder, doing online movie lookups, and potentially setting release reminders. Before relying on it, require confirmation for any cron reminder and avoid allowing it to read general recent logs or files outside the configured movie directory.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:43
Finding

Unscoped Access to Recent Logs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43-44
Vulnerability Type: Unbounded access to potentially sensitive contextual records
Risk Level: Medium

Vulnerable Code Snippet:

markdown
1. **Profile Analysis**: Consults `PROFILE_FILE` for preferred actors, genres, and themes.
2. **Context Check**: May check recent logs or mood to suggest a matching "vibe".

Technical Analysis

The instruction permits the agent to inspect unspecified “recent logs” while generating movie recommendations. It does not identify an approved log source, define a path boundary, require user consent, or limit collected information to movie-related data.

Consequently, an agent with filesystem, conversation-history, or application-log access could interpret this instruction broadly and read records outside MOVIES_ROOT or PROFILE_FILE. Such records may contain private conversations, activity history, operational metadata, or other information unrelated to movie recommendations. This violates least-privilege and data-minimization principles.

No instruction to transmit the accessed information to an external party was identified, and the actual accessible scope remains dependent on the permissions granted to the hosting agent.

Attack Path

  1. A user invokes the skill and requests a movie recommendation.
  2. The recommendation workflow reaches the optional context-check step.
  3. The agent interprets “recent logs” as authorization to inspect available chat, application, agent, or filesystem logs.
  4. The agent reads records unrelated to the movie-management task.
  5. Sensitive details from those records may influence or appear in the generated recommendation, exposing information without explicit user approval.

Impact Assessment

The issue may permit unauthorized read access to any recent logs already reachable through the agent's granted tools and operating-system permissions. Potentially exposed info ...[truncated 413 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the generic authorization to inspect “recent logs.”
  2. Restrict contextual analysis to explicitly named, movie-related files under MOVIES_ROOT, such as PROFILE_FILE.
  3. Require informed user consent before reading any additional context source.
  4. Explicitly prohibit access to general chat histories, system logs, agent logs, application logs, and files outside the configured movie directory.
  5. Apply path canonicalization and verify that approved files remain within MOVIES_ROOT before reading them.
  6. Minimize retained data and avoid copying sensitive contextual details into recommendations or persistent profile files.
  7. Replace the affected instruction with a bounded version, for example:
markdown
2. **Context Check**: With explicit user consent, consult only the configured
   `PROFILE_FILE` or a user-selected movie journal located under `MOVIES_ROOT`.
   Do not access chat histories, system logs, agent logs, application logs, or
   unrelated files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states it is integrated with cron and later says unreleased movies may cause creation of an openclaw cron reminder, but it does not clearly warn that this can schedule persistent tasks on the user's system. Creating scheduled jobs is more sensitive than ordinary note editing because it introduces long-lived automation that can execute later without the user's immediate awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises fetching trailers, poster URLs, and streaming availability, which implies external network access and possible disclosure of user interests or prompts to third-party services. Without an explicit warning, users may unknowingly trigger outbound requests that affect privacy, leak metadata, or introduce untrusted remote content into their notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly describes automatic creation, movement, and modification of files in an Obsidian vault, but does not warn the user that invoking the skill can change local notes and directory structure. This can lead to unintended data modification, clutter, or overwriting conflicts, especially because the actions occur during initialization, watchlist saving, and archiving workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The line Language: en imposes a specific language in the skill's natural-language metadata. Under the policy, forcing a specific language without user opt-in or a documented justification is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly sets the skill language to "en", which is a natural-language locale constraint. There is no indication elsewhere in the file that users can opt into this language setting or that the skill is intentionally limited to an English-only region or compliance context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.