T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:21- Finding
Calorie Records Use the Agent's Shared Persistent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill's calorie-tracking purpose is coherent, but it stores and reads private meal data in shared workspace locations with weak scoping and file-handling safeguards.
Review this before installing if you use shared OpenClaw memory for other private work. The skill should ideally store records and temporary images in a skill-private directory, use unique temporary filenames, delete raw images after processing, validate script arguments, and clearly document what meal data is retained and how to remove it.
SKILL.md:21Calorie Records Use the Agent's Shared Persistent Memory
SKILL.md:18Predictable Shared Filename Used for Private Meal Images
scripts/report.sh:7Unvalidated Year Argument Permits Path Traversal
The skill description promises photo-based calorie tracking, but the documented workflow also reads and writes persistent local files under workspace memory and temp image directories without clearly declaring that data access behavior. This mismatch can cause the agent or user to authorize broader filesystem access and retention than expected, increasing privacy and data-handling risk for user images and meal logs.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
- **Incomplete**: lunch or dinner is missing (breakfast does not count)
- **{percent}%**: difference between total calories and target; positive means over, negative means under
### Meal Display Rules
- Show only lunch, dinner, and snack (breakfast not counted)
- Omit meals that are not recorded
- Calorie unit: kcal
The workflow instructs the system to copy user food images and update daily persistent records, but it provides no notice, consent flow, retention policy, or privacy warning. Because food photos and eating-history logs are personal behavioral data, silent persistence can expose sensitive information to later unintended access or reuse.
The manifest describes a calorie tracker that logs daily calorie intake and analyzes date ranges, which implies reporting whole-day calorie totals. This script's implemented analysis extracts only lunch and dinner values and omits breakfast or full-day aggregation, so its behavior does not match the stated daily-intake analysis scope.
The inline documentation labels this as a "Weekly report script" and gives usage as ./weekly_report.sh, suggesting fixed 7-day behavior. However, the code accepts a DAYS argument and processes any positive number of days, so the comment and usage text actively misdescribe what the script does.
No suspicious patterns detected.