Back to skill

Security audit

Likes Training Planner

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its training-planner purpose, but its installer and API-key handling create review-worthy security risk.

Install only if you trust the publisher and source repository. Avoid the curl | bash path; prefer downloading artifacts separately and verifying them. Do not configure a custom Base URL unless you fully control it, protect and rotate the Likes API key if exposed, and use preview or dry-run before pushing plans or coach comments, especially from coach accounts.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:308
Finding

Mutable Remote Installer Is Executed Directly Through Bash

Content
View full analysis
Remediation
View remediation
install.sh' | sha256sum -c - ``` 5. Prefer signed releases and verify the publisher's signature before execution. 6. Require users to inspect the downloaded script and execute it in a separate command. 7. Standardize all documentation on one verified repository and publisher identity. 8. Avoid instructing users to run the installer with `sudo` or another elevated account. ]]>

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:8
Finding

Installer Replaces the Active Skill with an Unverified Latest Release Archive

Content
View full analysis
/dev/null; then curl -fsSL -o "$SKILL_NAME.skill" "$SKILL_URL" elif command -v wget &> /dev/null; then wget -q -O "$SKILL_NAME.skill" "$SKILL_URL" else echo "❌ Error: curl or wget required" exit 1 fi ``` ```bash # Remove old version if exists if [ -d "$SKILLS_DIR/$SKILL_NAME" ]; then echo "🔄 Removing old version..." rm -rf "$SKILLS_DIR/$SKILL_NAME" fi # Extract skill to correct location echo "📂 Extracting to $SKILLS_DIR/..." unzip -q "$SKILL_NAME.skill" -d "$SKILLS_DIR/" ``` ### Technical Analysis The installer follows a mutable `latest` release URL and performs no cryptographic checksum or signature verification before installing the archive. It deletes the currently installed version before validating the contents or confirming that extraction produced an expected and safe file set. The installer also does not independently inspect archive members for absolute paths, parent-directory traversal sequences, or unexpected symbolic links before invoking `unzip`. Although some `unzip` implementations include partial traversal protections, those protections should not be treated as a complete trust boundary. Because OpenClaw subsequently loads scripts and instructions from the destination directory, replacing the active Skill with an unverified archive creates a supply-chain code and instruction execution channel. ### Attack Path 1. An attacker compromises the release account, mutable `latest` release, hosting platform, or release publication process. 2. The attacker replaces `likes-training-planner.skill` with a ma ...[truncated 1028 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/configure.cjs:69
Finding

Configurable API Host Can Redirect the Likes API Key to an Arbitrary Server

Content
View full analysis
{ ``` The plan submission path has the same behavior: ```javascript const requestOptions = { hostname: baseUrl, path: '/api/open/plans/push', method: 'POST', headers: { 'X-API-Key': apiKey, 'Content-Type': 'application/json', 'Content-Length': Buffer.byteLength(postData) } }; ``` ### Technical Analysis The Skill legitimately needs to transmit the Likes API key to the Likes service. However, it permits the service hostname to be replaced with any configured value while still attaching the production credential. The code does not allowlist `my.likes.com.cn`, confirm that the configured URL belongs to the expected service, or require explicit approval before sending the key to a nonstandard endpoint. It also removes only a leading scheme rather than parsing and validating the value as a URL. The pattern is repeated across activity, feedback, game, plan, ability ...[truncated 1602 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/configure.cjs:31
Finding

API Key Is Persisted in Plaintext Without Explicit Restrictive File Permissions

Content
View full analysis
'); console.log(' or: API_KEY=xxx node set-config.cjs'); process.exit(1); } const config = loadConfig(); config.apiKey = apiKey; if (!config.baseUrl) { config.baseUrl = 'https://my.likes.com.cn'; } saveConfig(config); ``` ### Technical Analysis The API key is stored as plaintext JSON. `fs.writeFileSync()` is called without `mode: 0o600`, and the code does not verify or repair permissions on an existing configuration file. As a result, confidentiality depends on the user's ambient umask and pre-existing directory or file permissions. The documented positional argument form also exposes the key through shell history and may expose it through process-inspection interfaces while the command is running. Environment variables are generally preferable to arguments but can still be observable under some local threat models; a credential store or protected standard input is safer. Plaintext stor ...[truncated 1184 chars]
Remediation
View remediation
` interfaces from normal documentation and usage. 5. Accept secrets through protected standard input or the platform's secret injection mechanism. 6. Avoid generic `API_KEY` environment fallback because it may unintentionally consume a credential intended for another service; use only `LIKES_API_KEY`. 7. Document the storage location, protection model, rotation procedure, and revocation procedure. 8. Rotate existing API keys if there is evidence that configuration permissions or shell history were exposed. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (100)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching and immediately executing an external install script delegates full code execution to mutable remote content. In the context of a skill installation path, exploitation would compromise the local user environment and potentially the broader OpenClaw workspace.

Content

Scanner excerpt · README.en.md (reported line 35)May include surrounding context.

Method 1: One-line install (Recommended)

bash
curl -fsSL https://gitee.com/chenyinshu/likes-training-planner/raw/main/install.sh | bash

Method 2: Manual install

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The shell pipe into bash is a classic dangerous command chain because it removes any inspection boundary between download and execution. If the remote source is altered or intercepted, arbitrary commands run immediately with the user's privileges.

Content

Scanner excerpt · README.en.md (reported line 35)May include surrounding context.

Method 1: One-line install (Recommended)

bash
curl -fsSL https://gitee.com/chenyinshu/likes-training-planner/raw/main/install.sh | bash

Method 2: Manual install

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The README recommends executing a remote installer directly with curl ... | bash, which hands full code-execution control to whatever content is served at that URL at install time. If the hosting account, repository, release pipeline, DNS/TLS trust chain, or referenced script is compromised, users can be silently infected with arbitrary commands on their local machine.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

方式 1:一键安装(推荐)

bash
curl -fsSL https://gitee.com/chenyinshu/likes-training-planner/raw/main/install.sh | bash

方式 2:手动安装

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash construct is a command-chaining anti-pattern that removes any opportunity for the user or tooling to inspect the fetched script before execution. In the context of a skill README aimed at installation, this materially increases exploitation risk because it normalizes immediate execution of network-delivered code with the user's privileges.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

方式 1:一键安装(推荐)

bash
curl -fsSL https://gitee.com/chenyinshu/likes-training-planner/raw/main/install.sh | bash

方式 2:手动安装

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The documented installation command fetches an external script from Gitee and executes it immediately, creating a classic arbitrary-code-execution risk. In the context of a local skill install, the command runs with the user's shell privileges and could modify files, steal tokens, or install persistence if the remote content is malicious or tampered with.

Content

Scanner excerpt · README.zh.md (reported line 35)May include surrounding context.

方式 1:一键安装(推荐)

bash
curl -fsSL https://gitee.com/chenyinshu/likes-training-planner/raw/main/install.sh | bash

方式 2:手动安装

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash chain removes any review boundary between download and execution, making it easy for a compromised or swapped response to run instantly. This pattern is especially dangerous for skills because users may trust setup instructions and execute them in environments containing API keys or other local secrets.

Content

Scanner excerpt · README.zh.md (reported line 35)May include surrounding context.

方式 1:一键安装(推荐)

bash
curl -fsSL https://gitee.com/chenyinshu/likes-training-planner/raw/main/install.sh | bash

方式 2:手动安装

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Introducing Telegram/OpenClaw bot identity detection and mode switching without declaring it in the skill purpose adds hidden behavior pathways. Undisclosed context-based routing can change how data is handled or which actions are offered, which is risky in a skill that also interfaces with user accounts and training data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Introducing Telegram/OpenClaw bot identity detection and mode switching without declaring it in the skill purpose adds hidden behavior pathways. Undisclosed context-based routing can change how data is handled or which actions are offered, which is risky in a skill that also interfaces with user accounts and training data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Introducing Telegram/OpenClaw bot identity detection and mode switching without declaring it in the skill purpose adds hidden behavior pathways. Undisclosed context-based routing can change how data is handled or which actions are offered, which is risky in a skill that also interfaces with user accounts and training data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Introducing Telegram/OpenClaw bot identity detection and mode switching without declaring it in the skill purpose adds hidden behavior pathways. Undisclosed context-based routing can change how data is handled or which actions are offered, which is risky in a skill that also interfaces with user accounts and training data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Introducing Telegram/OpenClaw bot identity detection and mode switching without declaring it in the skill purpose adds hidden behavior pathways. Undisclosed context-based routing can change how data is handled or which actions are offered, which is risky in a skill that also interfaces with user accounts and training data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Introducing Telegram/OpenClaw bot identity detection and mode switching without declaring it in the skill purpose adds hidden behavior pathways. Undisclosed context-based routing can change how data is handled or which actions are offered, which is risky in a skill that also interfaces with user accounts and training data.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
node scripts/fetch_activities.cjs --days 7 --output data.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
node scripts/fetch_activities.cjs --days 7 --output data.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
node scripts/fetch_activities.cjs --days 7 --output data.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
node scripts/fetch_plans.cjs --start 2026-03-01 --output plans.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
node scripts/fetch_feedback.cjs --start 2026-03-01 --end 2026-03-07

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
node scripts/fetch_games.cjs --output camps.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 271)May include surrounding context.

md
node scripts/fetch_games.cjs --output camps.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
node scripts/analyze_data.cjs data.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
node scripts/analyze_data.cjs data.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
node scripts/push_plans.cjs plans.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
node scripts/push_plans.cjs plans.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
node scripts/push_plans.cjs plans.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
node scripts/push_plans.cjs plans.json

Static analysis

No suspicious patterns detected.