Back to skill

Security audit

Advanced Skill Creator Repo

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent skill-generation purpose, but it sends user requests to a third-party AI API and includes under-scoped instructions that can influence generated skills, so it should be reviewed before installation.

Install only if you are comfortable sending skill-generation requests and research context to the SkillBoss API when SKILLBOSS_API_KEY is set. Avoid pasting secrets, proprietary code, customer data, or private infrastructure details into requests, and review generated skills for inherited system-prompt or memory instructions before using or publishing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:153
Finding

Role-changing instructions are propagated into generated skills

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/advanced_skill_processor.py:152
Finding

Arbitrary user-request content is transmitted to a third-party AI API without content filtering

Content
View full analysis
str: """ Use SkillBoss API Hub to generate complete SKILL.md content based on research data. Calls /v1/pilot with type=chat, auto-routing to the optimal model. """ if not SKILLBOSS_API_KEY: return "" context = json.dumps(research_data, ensure_ascii=False, indent=2) prompt = ( f"你是一个 OpenClaw Skill 创建专家。根据以下研究数据,为用户请求生成完整的 SKILL.md 内容。\n\n" f"用户请求: {user_request}\n\n" f"研究数据:\n{context}\n\n" f"请输出完整的 SKILL.md 内容,包含正确的 YAML frontmatter(name, description, when, examples, metadata.openclaw)。" ) result = pilot({ "type": "chat", "inputs": { "messages": [{"role": "user", "content": prompt}] }, "prefer": "balanced" }) return result["result"]["choices"][0]["message"]["content"] ``` The destination and authorization behavior are defined at `scripts/advanced_skill_processor.py:18-30`: ```python SKILLBOSS_API_KEY = os.environ.get("SKILLBOSS_API_KEY", "") API_BASE = "https://api.heybossai.com/v1" def pilot(body: dict) -> dict: """Call SkillBoss API Hub /v1/pilot endpoint.""" r = requests.post( f"{API_BASE}/pilot", headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"}, json=body, timeout=60, ) return r.json() ``` ### Technical Analysis When `SKILLBOSS_API_KEY` is configured, the script embeds the entire `user_request` verbatim into a prompt and sends it to `https://api.heybossai.com/v1/pilot`. The generated research context is transmitted with it. The documentation identifies the external API as the AI-generation provider, but the implementat ...[truncated 1592 chars]
Remediation
View remediation

other

Warning
Location
scripts/advanced_skill_processor.py:63
Finding

Simulated and hard-coded results are presented as completed external research

Content
View full analysis
Dict[str, Any]: """ Step 2: Research Related Public Skills on ClawHub/ClawdHub Query ClawHub/ClawdHub for relevant skills based on keywords. """ print(f"Step 2: Researching public skills with keywords: {keywords}") # Simulate querying public skills selected_skills = [] for kw in keywords[:4]: # Select up to 4 skills skill_info = { "keyword": kw, "selected": True, "downloads": "high", "recent_update": True, "community_rating": "good", "analysis": { "trigger_description": f"when: 'Use {kw} functionality'", "yaml_metadata": {"name": kw, "description": f"Skill for {kw}"}, "structure": "Markdown with scripts/", "dependencies": ["basic"], "error_handling": "standard", "feedback": "well received" } } selected_skills.append(skill_info) return { "status": "completed", "keywords_searched": keywords, "selected_skills": selected_skills } ``` The same pattern appears in the documentation and best-practice stages at `scripts/advanced_skill_processor.py:34-60` and `scripts/advanced_skill_processor.py:103-122`: static dictionaries are returned with a completed status, but no source retrieval or verification occurs. ### Technical Analysis The function claims to query ClawHub or ClawdHub, but it explicitly simulates results and assigns unsupported values such as `"downloads": "high"`, `"recent_update": True`, and `"community_rating": "good"`. No ClawHub client, HTTP request, repository lookup, response parsing, or provenance valida ...[truncated 1555 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (19)

Tainted flow: 'SKILLBOSS_API_KEY' from os.environ.get (line 18, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/advanced_skill_processor.py (reported line 24)May include surrounding context.

python
def pilot(body: dict) -> dict:
    """Call SkillBoss API Hub /v1/pilot endpoint."""
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger condition is overly broad and includes a catch-all for essentially any request related to creating or modifying Claw-family skills. That creates a prompt-scope vulnerability where this skill can activate unexpectedly, override more specific skills, and steer unrelated conversations into a workflow that performs external research and structured output generation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
- "SKILL.md" "when:" OR "metadata.openclaw" site:github.com

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The phrase 'automatically performs comprehensive research and generates' indicates the skill may make autonomous decisions about external research and output generation without an explicit approval checkpoint. In agent workflows, this can lead to unnecessary external actions, overreach beyond the user's request, or unsafe execution paths if the trigger is broad or misclassified.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

md
## Usage

When triggered, this skill automatically performs comprehensive research and generates properly structured skills that follow official standards and best practices.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage text says the skill activates 'when triggered' but does not define clear trigger conditions, scope, or confirmation boundaries. In an agent setting, ambiguous invocation criteria can cause the skill to run in unintended contexts and perform actions the user did not explicitly request, increasing the risk of prompt-routing mistakes or policy bypass through accidental activation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
---
name: advanced-skill-creator
description: Advanced OpenClaw skill creation handler that executes the official 5-step research flow with comprehensive analysis and best practices. Ensures proper methodology when users request to create or modify OpenClaw/Moltbot/ClawDBot skills following official standards.
when: "When user mentions '写一个触发', '写skill', 'claw skill', 'openclaw skill', 'moltbot skill', '创建技能', '写一个让它...', or any request related to creating or modifying Claw系 skills"
examples:
  - "写一个触发监控系统"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example trigger phrases are generic and conversational, which reinforces ambiguous activation behavior and increases the chance of false positives. In a skill-routing system, such overlap can cause the wrong skill to seize control, producing unintended outputs or invoking unnecessary research/tooling behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file mandates exact headings in Chinese — "【最终推荐方案】, 【文件结构预览】, 【完整文件内容】" — for all outputs, but does not provide user opt-in or explain a region-specific requirement. This is a natural-language locale constraint that may conflict with organizational language-choice policies.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill explicitly depends on sending content to an external API endpoint at api.heybossai.com for AI generation. External transmission can expose user prompts, skill content, or potentially sensitive data to a third party, and the risk is heightened here because the skill is a creator/modifier workflow that may process substantial user-provided or proprietary material.

Content

Scanner excerpt · UPLOAD_INSTRUCTIONS.md (reported line 7)May include surrounding context.

md
这是一个高级技能创建器,能够执行官方的5步研究流程来创建符合OpenClaw标准的技能。该技能确保在用户请求创建或修改OpenClaw/Moltbot/ClawDBot技能时遵循正确的方法论和官方标准。

AI 内容生成由 SkillBoss API Hub 提供支持,通过统一入口 `https://api.heybossai.com/v1/pilot` 自动路由最优模型。

## 功能特性

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented auto-trigger phrases are overly broad and overlap with normal conversation, such as generic requests to 'write a skill' or 'create a skill'. In an agent environment, this can cause unintended activation, leading the skill to run in contexts the user did not clearly intend and potentially invoke networked or sensitive behavior indirectly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/advanced_skill_processor.py (reported line 8)May include surrounding context.

python
This script implements the 5-step research flow for creating OpenClaw skills
according to official standards and best practices.

AI generation powered by SkillBoss API Hub via https://api.heybossai.com/v1/pilot
"""

import json

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/advanced_skill_processor.py (reported line 19)May include surrounding context.

python
This script implements the 5-step research flow for creating OpenClaw skills
according to official standards and best practices.

AI generation powered by SkillBoss API Hub via https://api.heybossai.com/v1/pilot
"""

import json

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This code sends prompt data to an external network service. In this skill context, the payload can include raw user requests and synthesized research data, so the external transmission creates a real data exposure surface even though the destination appears intentional and over HTTPS.

Content

Scanner excerpt · scripts/advanced_skill_processor.py (reported line 24)May include surrounding context.

python
def pilot(body: dict) -> dict:
    """Call SkillBoss API Hub /v1/pilot endpoint."""
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Step 1 docstring says it will access official documentation and extract key information, yet the function only defines a static list of sources and returns predetermined extracted_info values. This is an active contradiction between the documented intent and the implemented behavior, not merely omitted detail.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Step 2 docstring says it will query public skill hubs for relevant skills, but the code explicitly notes '# Simulate querying public skills' and fabricates selection metadata locally. This directly contradicts the stated behavior of performing real research.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Step 3 docstring describes a search process, implying external lookup or dynamic research, while the implementation constructs static best-practice entries regardless of the provided keywords. This is a clear contradiction between intent documentation and code behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hardcoded prompt text is entirely in Chinese and instructs the model in that language regardless of the user's preferred language. This is a natural-language locale policy issue because the file enforces a specific language without offering choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script transmits the user request and aggregated research context to a third-party API without an explicit consent/notice check at the point of transmission. In a skill-generation context, user requests may contain proprietary code, internal plans, credentials pasted by mistake, or other sensitive data, making external forwarding a real confidentiality risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

整份技能说明以中文固定呈现,未说明是否支持其他语言,也未给出用户可选择语言的机制。根据语言/locale 政策,若技能对语言有约束,应提供用户选择或明确、合理的地区性说明。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.