Back to skill

Security audit

家庭财务管理系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local family-finance tracker whose file access is purpose-aligned and disclosed, though users should understand it stores sensitive financial records as local plaintext JSON.

Install only if you are comfortable storing household financial details locally in plaintext JSON under ~/.openclaw/workspace/data/family-finances/. Consider restricting file permissions on that directory, avoiding highly sensitive account identifiers in notes, and periodically reviewing or deleting the stored records if they are no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/finances.py:14
Finding

Sensitive Financial Data Stored Without Restrictive Filesystem Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/finances.py, lines 14-20 and 28-31
Vulnerability Type: Plaintext sensitive-data storage with permissions inherited from the process environment
Risk Level: Medium

Vulnerable Code

python
DATA_DIR = Path.home() / ".openclaw" / "workspace" / "data" / "family-finances"
DATA_DIR.mkdir(parents=True, exist_ok=True)

BALANCE_FILE = DATA_DIR / "balance_sheet.json"
CASHFLOW_FILE = DATA_DIR / "cashflow.json"
PORTFOLIO_FILE = DATA_DIR / "portfolio.json"
METADATA_FILE = DATA_DIR / "metadata.json"
python
def _save_json(path: Path, data):
    with open(path, "w", encoding="utf-8") as f:
        json.dump(data, f, ensure_ascii=False, indent=2)

Technical Analysis

The Skill stores household assets, liabilities, income, expenses, investment holdings, descriptions, and notes as plaintext JSON. The data directory is created without an explicit restrictive mode, and files are opened without explicitly enforcing owner-only permissions.

Consequently, actual access permissions depend on the process umask and any permissions already present on the directory or files. In a permissively configured or multi-user environment, financial records may be readable by other local accounts. The implementation also does not correct weak permissions on existing files.

Exploitation requires local access under another account and filesystem permissions that permit traversal of the parent directories and reading of the generated files. This is not a remote vulnerability, and the code does not itself grant additional privileges.

Attack Path

  1. A user invokes an asset, liability, cash-flow, or portfolio command.
  2. The script creates or updates JSON files under ~/.openclaw/workspace/data/family-finances/.
  3. Directory and file permissions are inherited from the host environment rather than explicitly restricted.
  4. If those effective permissions allow acces ...[truncated 822 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create and enforce the data directory as owner-only:

    python
    DATA_DIR.mkdir(parents=True, exist_ok=True, mode=0o700)
    os.chmod(DATA_DIR, 0o700)
    
  2. Create data files with mode 0o600 using os.open, so access does not rely solely on the process umask:

    python
    fd = os.open(path, os.O_WRONLY | os.O_CREAT | os.O_TRUNC, 0o600)
    with os.fdopen(fd, "w", encoding="utf-8") as f:
        json.dump(data, f, ensure_ascii=False, indent=2)
    
  3. Apply os.chmod(path, 0o600) to existing financial files after verifying that the path is a regular file owned by the current user.

  4. Use atomic writes: write to an owner-only temporary file in the same restricted directory, flush and synchronize it, then replace the destination with os.replace.

  5. Reject symbolic-link destinations before writing, or use platform-supported no-follow flags, to reduce the risk of unintended writes if the data directory is modified by another actor.

  6. Consider encryption at rest when the threat model includes filesystem snapshots, backups, removable media, or privileged host users. Filesystem modes alone do not protect against administrators or other principals capable of bypassing discretionary access controls.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill performs file reads and writes to a persistent directory but does not declare any explicit tool scope or permission boundary. That creates an authorization and transparency gap: sensitive household financial data may be stored or modified without clear user-facing limits on what filesystem access the skill requires.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad and natural-language based, which can cause the skill to activate in contexts where the user did not intend to open or modify family finance records. In a skill that reads and writes sensitive financial data, unintended invocation increases the chance of privacy exposure or accidental data modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes persistent storage paths and financial record files but does not clearly warn users that sensitive household financial data will be written to disk. Because the data includes assets, liabilities, cashflow, and portfolio information, lack of disclosure materially increases privacy risk and may lead users to share highly sensitive information without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language documentation, labels, categories, and CLI examples are entirely in Chinese, with no indication that other languages are supported or that the language choice is intentional and optional. Under the stated policy, a skill should not impose a specific language or locale without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script stores highly sensitive household financial data, including assets, liabilities, cashflow, and portfolio details, in persistent local JSON files under the user's home directory with no access controls, encryption, or user-facing disclosure. In the context of a family finance skill, this increases privacy and data exposure risk because other local users, backups, logs, or compromised processes may access detailed financial records without the user realizing the data is being retained.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states that the skill generates Chinese financial health reports, and the format rules later require reports to use Chinese. This is a language policy constraint presented as mandatory behavior, with no user opt-in or explanation that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The format rules explicitly require reports to use Chinese, which imposes a fixed language policy. Because no alternative language option or opt-in is provided, this is a natural-language policy issue under the locale/language rule.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.