T01 · Skill Instruction Hijacking
- Location
SKILL.md:153- Finding
Role-changing instructions are propagated into generated skills
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent skill-generation purpose, but it sends user requests to a third-party AI API and includes under-scoped instructions that can influence generated skills, so it should be reviewed before installation.
Install only if you are comfortable sending skill-generation requests and research context to the SkillBoss API when SKILLBOSS_API_KEY is set. Avoid pasting secrets, proprietary code, customer data, or private infrastructure details into requests, and review generated skills for inherited system-prompt or memory instructions before using or publishing them.
SKILL.md:153Role-changing instructions are propagated into generated skills
scripts/advanced_skill_processor.py:152Arbitrary user-request content is transmitted to a third-party AI API without content filtering
scripts/advanced_skill_processor.py:63Simulated and hard-coded results are presented as completed external research
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
def pilot(body: dict) -> dict:
"""Call SkillBoss API Hub /v1/pilot endpoint."""
r = requests.post(
f"{API_BASE}/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json=body,
The trigger condition is overly broad and includes a catch-all for essentially any request related to creating or modifying Claw-family skills. That creates a prompt-scope vulnerability where this skill can activate unexpectedly, override more specific skills, and steer unrelated conversations into a workflow that performs external research and structured output generation.
Referenced artifact was not completely inspected
- "SKILL.md" "when:" OR "metadata.openclaw" site:github.com
The phrase 'automatically performs comprehensive research and generates' indicates the skill may make autonomous decisions about external research and output generation without an explicit approval checkpoint. In agent workflows, this can lead to unnecessary external actions, overreach beyond the user's request, or unsafe execution paths if the trigger is broad or misclassified.
## Usage
When triggered, this skill automatically performs comprehensive research and generates properly structured skills that follow official standards and best practices.
The usage text says the skill activates 'when triggered' but does not define clear trigger conditions, scope, or confirmation boundaries. In an agent setting, ambiguous invocation criteria can cause the skill to run in unintended contexts and perform actions the user did not explicitly request, increasing the risk of prompt-routing mistakes or policy bypass through accidental activation.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
name: advanced-skill-creator
description: Advanced OpenClaw skill creation handler that executes the official 5-step research flow with comprehensive analysis and best practices. Ensures proper methodology when users request to create or modify OpenClaw/Moltbot/ClawDBot skills following official standards.
when: "When user mentions '写一个触发', '写skill', 'claw skill', 'openclaw skill', 'moltbot skill', '创建技能', '写一个让它...', or any request related to creating or modifying Claw系 skills"
examples:
- "写一个触发监控系统"
The example trigger phrases are generic and conversational, which reinforces ambiguous activation behavior and increases the chance of false positives. In a skill-routing system, such overlap can cause the wrong skill to seize control, producing unintended outputs or invoking unnecessary research/tooling behavior.
The file mandates exact headings in Chinese — "【最终推荐方案】, 【文件结构预览】, 【完整文件内容】" — for all outputs, but does not provide user opt-in or explain a region-specific requirement. This is a natural-language locale constraint that may conflict with organizational language-choice policies.
The skill explicitly depends on sending content to an external API endpoint at api.heybossai.com for AI generation. External transmission can expose user prompts, skill content, or potentially sensitive data to a third party, and the risk is heightened here because the skill is a creator/modifier workflow that may process substantial user-provided or proprietary material.
这是一个高级技能创建器,能够执行官方的5步研究流程来创建符合OpenClaw标准的技能。该技能确保在用户请求创建或修改OpenClaw/Moltbot/ClawDBot技能时遵循正确的方法论和官方标准。
AI 内容生成由 SkillBoss API Hub 提供支持,通过统一入口 `https://api.heybossai.com/v1/pilot` 自动路由最优模型。
## 功能特性
The documented auto-trigger phrases are overly broad and overlap with normal conversation, such as generic requests to 'write a skill' or 'create a skill'. In an agent environment, this can cause unintended activation, leading the skill to run in contexts the user did not clearly intend and potentially invoke networked or sensitive behavior indirectly.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
This script implements the 5-step research flow for creating OpenClaw skills
according to official standards and best practices.
AI generation powered by SkillBoss API Hub via https://api.heybossai.com/v1/pilot
"""
import json
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
This script implements the 5-step research flow for creating OpenClaw skills
according to official standards and best practices.
AI generation powered by SkillBoss API Hub via https://api.heybossai.com/v1/pilot
"""
import json
This code sends prompt data to an external network service. In this skill context, the payload can include raw user requests and synthesized research data, so the external transmission creates a real data exposure surface even though the destination appears intentional and over HTTPS.
def pilot(body: dict) -> dict:
"""Call SkillBoss API Hub /v1/pilot endpoint."""
r = requests.post(
f"{API_BASE}/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json=body,
The Step 1 docstring says it will access official documentation and extract key information, yet the function only defines a static list of sources and returns predetermined extracted_info values. This is an active contradiction between the documented intent and the implemented behavior, not merely omitted detail.
The Step 2 docstring says it will query public skill hubs for relevant skills, but the code explicitly notes '# Simulate querying public skills' and fabricates selection metadata locally. This directly contradicts the stated behavior of performing real research.
The Step 3 docstring describes a search process, implying external lookup or dynamic research, while the implementation constructs static best-practice entries regardless of the provided keywords. This is a clear contradiction between intent documentation and code behavior.
The hardcoded prompt text is entirely in Chinese and instructs the model in that language regardless of the user's preferred language. This is a natural-language locale policy issue because the file enforces a specific language without offering choice or documenting a justified regional constraint.
The script transmits the user request and aggregated research context to a third-party API without an explicit consent/notice check at the point of transmission. In a skill-generation context, user requests may contain proprietary code, internal plans, credentials pasted by mistake, or other sensitive data, making external forwarding a real confidentiality risk.
整份技能说明以中文固定呈现,未说明是否支持其他语言,也未给出用户可选择语言的机制。根据语言/locale 政策,若技能对语言有约束,应提供用户选择或明确、合理的地区性说明。
No suspicious patterns detected.