Back to skill

Security audit

Photo Calorie Tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill's calorie-tracking purpose is coherent, but it stores and reads private meal data in shared workspace locations with weak scoping and file-handling safeguards.

Review this before installing if you use shared OpenClaw memory for other private work. The skill should ideally store records and temporary images in a skill-private directory, use unique temporary filenames, delete raw images after processing, validate script arguments, and clearly document what meal data is retained and how to remove it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:21
Finding

Calorie Records Use the Agent's Shared Persistent Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:18
Finding

Predictable Shared Filename Used for Private Meal Images

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/report.sh:7
Finding

Unvalidated Year Argument Permits Path Traversal

Content
View full analysis
=1)> [year]" exit 1 fi echo "📊 Calorie tracking for the last ${DAYS} days" echo "═══════════════════════════════" echo "Target: ${TARGET} kcal/day" echo "" for i in $(seq 0 $((DAYS - 1))); do DATE=$(date -d "$i days ago" +"%m-%d") FILE="${MEMORY_DIR}/${YEAR}-${DATE}.md" ``` The subsequent file-processing logic is: ```bash if [ -f "$FILE" ]; then # Extract lunch and dinner data LUNCH=$(grep -A20 "午餐" "$FILE" | grep "小计" | awk '{print $3}' | tr -d '~' | tr -d 'kcal') DINNER=$(grep -A10 "晚餐" "$FILE" | grep -E "^[|]" | tail -1 | awk -F'|' '{print $4}' | tr -d ' ') ``` ### Technical Analysis The script validates `DAYS` but accepts `YEAR` without validation. `YEAR` is inserted directly into a filesystem path between the fixed memory directory and the generated `-MM-DD.md` suffix. Shell quoting prevents command injection, but it does not prevent path traversal. A value containing `../` can cause the resolved path to leave `MEMORY_DIR`. The script then tests the resulting path and passes it to `grep`, allowing it to inspect any readable file whose final pathname matches the generated date suffix. The fixed suffix limits which filenames are directly targetable, but it does not restore the intended directory boundary. ### Attack Path 1. An attacker gains the ability to invoke `scripts/report.sh` or control its second argument. 2. The attacker supplies a traversal-containing year value, for example: ```bash ./scripts/report.sh 1 "../../../../tmp/record" ``` 3. The script constructs a path equivalent to: ```text /root/.openclaw/workspace/memory/../../../../tmp/record- ...[truncated 672 chars]
Remediation
View remediation
=1)> [year]" exit 1 fi ``` 2. Canonicalize both the base directory and generated file path with `realpath`. 3. Verify that the canonical file path begins with the canonical memory-directory path followed by `/`. 4. Reject arguments containing `/`, `\`, `..`, control characters, or leading option characters. 5. Consider removing the `YEAR` argument if arbitrary historical years are not required. 6. Add automated tests covering absolute paths, `../` traversal, repeated separators, symbolic links, malformed years, and valid four-digit years. ]]>
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description promises photo-based calorie tracking, but the documented workflow also reads and writes persistent local files under workspace memory and temp image directories without clearly declaring that data access behavior. This mismatch can cause the agent or user to authorize broader filesystem access and retention than expected, increasing privacy and data-handling risk for user images and meal logs.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
- **Incomplete**: lunch or dinner is missing (breakfast does not count)
- **{percent}%**: difference between total calories and target; positive means over, negative means under

### Meal Display Rules
- Show only lunch, dinner, and snack (breakfast not counted)
- Omit meals that are not recorded
- Calorie unit: kcal

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the system to copy user food images and update daily persistent records, but it provides no notice, consent flow, retention policy, or privacy warning. Because food photos and eating-history logs are personal behavioral data, silent persistence can expose sensitive information to later unintended access or reuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a calorie tracker that logs daily calorie intake and analyzes date ranges, which implies reporting whole-day calorie totals. This script's implemented analysis extracts only lunch and dinner values and omits breakfast or full-day aggregation, so its behavior does not match the stated daily-intake analysis scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The inline documentation labels this as a "Weekly report script" and gives usage as ./weekly_report.sh, suggesting fixed 7-day behavior. However, the code accepts a DAYS argument and processes any positive number of days, so the comment and usage text actively misdescribe what the script does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.