Back to skill

Security audit

OpenClaw Kindergarten

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Night School purpose, but it needs review because it can post and submit to an external service later using shared feed content and a command-line token with weak safeguards.

Install only if you are comfortable with the skill sending your school choice, learning goal, generated posts, report content, and callback token to the Night School service. Use only the documented HTTPS endpoint, review posts and reports before submission, avoid unattended scheduler mode unless you explicitly want delayed external actions, and treat shared feed messages as untrusted text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:139
Finding

Untrusted Remote Feed Content Is Incorporated into Agent Reasoning

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/night-school-run.py:116
Finding

Callback Token Is Exposed Through Standard Output and Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/night-school-run.py:218
Finding

Unrestricted Base URL Allows Sensitive Data to Be Sent to Arbitrary or Plaintext Endpoints

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims to be fully self-contained with no manual token handling or website visits, but the documented behavior includes external feed reads/posts, explicit base URL usage, and handling of a one-time callback token. That mismatch can mislead users and downstream agents about what actions will occur and what secrets or state must be protected, enabling risky automation under false assumptions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to read local files and access external network resources, but it declares no explicit tool scope or permissions boundary. This can cause the agent to invoke higher-privilege capabilities than the user expects, increasing the chance of unintended data access or outbound requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrase 'go to school' is generic and likely to appear in ordinary conversation unrelated to this skill. Accidental activation is dangerous here because the skill can enroll users, contact external services, post to shared feeds, and submit reports automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not prominently warn that it will read a shared feed, post content publicly or semi-publicly, and submit a report on the user's behalf. Missing disclosure undermines informed consent and can lead users to reveal goals or content that are then transmitted externally without clear expectation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Using wording like 'or similar' makes invocation boundaries ambiguous, encouraging the agent to infer activation from loosely related user text. In a skill that performs external posting and submission, vague activation criteria materially increase the risk of unintended side effects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The automation section directs the agent to use cron or sleep for unattended execution and later submission, extending the skill from interactive assistance into autonomous system scheduling. This creates persistence-like behavior and can trigger network actions after the original user interaction has ended, reducing oversight and increasing the chance of unintended submissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The unattended automation guidance omits any warning that scheduled actions may later post externally and submit reports without the user being present. This increases the risk of silent or forgotten external activity and makes misuse or mistakes harder to catch in time.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code file includes natural-language examples and prompts centered on Chinese input, such as the example name and goal text. Because the skill does not offer a language choice or explain that it is intended only for a Chinese-language context, it creates a locale-policy concern under the rule for natural-language policy violations.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
70% confidence
Finding

Overly Broad Trigger: '夜校' is too short and may match unintended inputs

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
78% confidence
Finding

The trigger '上学' is very generic and commonly used in everyday Chinese conversation, so it may activate the skill on unrelated messages. Because this skill can make network requests and external submissions, even low-specificity trigger collisions create avoidable risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.