T09 · Insecure Skill Coding Practices
- Location
SKILL.md:53- Finding
Execution Policy Bypass for Missing and Unauditable PowerShell Helper
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a UI design helper, but it needs review because it instructs agents to run a missing PowerShell helper with ExecutionPolicy Bypass.
Review before installing. The design datasets and guidance appear ordinary, but do not run the documented PowerShell helper unless the actual script is included, reviewed, and invoked from a trusted package path without ExecutionPolicy Bypass.
SKILL.md:53Execution Policy Bypass for Missing and Unauditable PowerShell Helper
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# UI Design Optimizer
Implementation-first UI/UX skill for OpenClaw. It helps select style, color, and typography from local datasets, then produce a practical design spec and starter files.
The manifest and description frame the skill as operating on local design datasets and generating files, but the body broadens behavior to invoking an external script. This mismatch can mislead reviewers and downstream systems about the skill's actual capabilities, increasing the chance that command execution is permitted in contexts expecting only local file reads and content generation.
The skill explicitly instructs use of a PowerShell helper with ExecutionPolicy Bypass, which introduces avoidable command execution into a skill whose stated purpose is UI design generation from local datasets. Even if intended as a convenience for local lookup, this expands the trust boundary from passive data reads to shell execution and could be abused if the script or invocation parameters are modified, replaced, or influenced by untrusted input.
The trigger patterns are broad and likely to match many ordinary UI/design requests, which can cause the skill to activate more often than intended. Over-broad activation increases the chance that the skill influences unrelated tasks, exposes local datasets unnecessarily, or crowds out more appropriate skills, even if there is no clearly malicious behavior in this file.
No suspicious patterns detected.