T06 · System Persistence
- Location
SKILL.md:115- Finding
Recurring Cross-Session Agent Tasks Create System Persistence
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent stock-review and WeChat reporting tool, but it asks users to create recurring main-agent tasks that can repeatedly process portfolio data, update memory, and send reports without strong lifecycle or recipient controls.
Install only if you want a Chinese-language stock review workflow with WeChat integration. Before enabling automation, confirm every cron task name, schedule, target agent, memory-write behavior, and WeChat recipient/account; prefer one-time reports unless you intentionally want recurring monitoring, and remove tasks you no longer use.
SKILL.md:115Recurring Cross-Session Agent Tasks Create System Persistence
The file’s description, headings, instructions, and examples all require Chinese comprehension, effectively forcing a specific language for use of the skill. The document does not offer an alternative language option or explain that the skill is intentionally limited to a Chinese-speaking or region-specific audience.
The skill gives conflicting guidance about cron delivery configuration: earlier it says not to manually specify delivery accountId/to and to rely on announce+last, while the later WeChat push section states accountId and to are required. This inconsistency can cause misconfigured scheduled pushes, failed notifications, or accidental delivery to an unintended last-active channel, which is risky in a tool handling investment summaries and account-linked messaging.
The skill includes clear capabilities that imply network access, file reads, and file writes, such as fetching market data, updating MEMORY.md, and integrating scheduled tasks, but it does not declare an explicit tool scope or permissions boundary. This creates a least-privilege gap: a host may grant broader access than users expect, increasing the risk of unintended data exfiltration, unsafe file modification, or overbroad execution when the skill is run.
The skill description and all operational guidance are written entirely in Chinese, and the file does not indicate that users may choose another language or that the skill is restricted to a China-specific audience for compliance reasons. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
This markdown file contains user-facing guidance exclusively in Chinese, and there is no indication that the skill is region-specific or that users may opt into this language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The file title and all instructional content are written entirely in Chinese, and the examples explicitly assume a China-specific timezone and market context. Because the document does not state that the skill is region-specific or offer an opt-in language/locale choice, it appears to enforce a specific language/locale policy through natural-language instructions.
The guidance instructs the agent to push stock review and portfolio information to WeChat, an external messaging channel, but does not clearly require explicit user consent or warn that sensitive financial data will leave the local analysis context. In this skill, the report may include holdings, gains/losses, account-linked identifiers, and review notes, so silent transmission increases privacy and data disclosure risk.
This code file contains natural-language documentation and output strings that assume Chinese as the only language, beginning with the module docstring and continuing throughout the report template. The policy requires flagging language or locale constraints when they are forced without user opt-in and not clearly justified as region-specific.
This code file contains natural-language descriptions and messages entirely in Chinese, including the module docstring and runtime diagnostics, with no indication that language selection is configurable. Under the policy rule for language/locale, forcing a specific language without user opt-in is a violation unless clearly justified as region-specific.
The function claims to verify the WeChat/OpenClaw plugin version but always returns a hardcoded success value, so callers may rely on a security or compatibility check that never actually occurs. In this skill, that can cause reports to be sent through an unverified or incompatible plugin, weakening trust assumptions and potentially masking operational or supply-chain issues.
This JSON manifest/template contains user-facing natural-language fields such as description, notes, and entry conditions entirely in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.
No suspicious patterns detected.