Back to skill

Security audit

i-am

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Review item because it can profile you from broad OpenClaw conversation history, store that profile persistently, schedule recurring analysis, and send previews through chat.

Install only if you are comfortable with this skill reading recent and future OpenClaw conversation history to infer personality traits, storing those in USER.md and skill files, and possibly sending preview files through your chat channel. Prefer manual mode, review the exact preview before confirming updates, avoid scheduled mode unless you want ongoing profiling, and know how to delete temp/USER.md, ChangeLog.md, last_analysis.json, and any cron entries.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:178
Finding

Unrestricted Collection of Private Conversation History

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Note
Location
SKILL.md:53
Finding

Persistent Twice-Daily Processing Through OpenClaw Scheduled Tasks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mines prior conversations, extracts user text, and persists inferred traits into preview/profile files. This re-processes and re-exposes potentially sensitive personal information in plain language, creating a durable profile that could be accessed later or disclosed beyond the original conversational context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to scan all session transcript files under the sessions directory and extract prior user messages, including historical content from multiple conversations. That is broad conversation harvesting beyond what is minimally necessary, and it creates a high risk of collecting sensitive data without clear scope limitation or fresh consent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the AI to send the generated USER.md preview back through the messaging channel, and that preview contains accumulated personality analysis and user-derived content. Transmitting sensitive inferred data over chat increases the chance of disclosure through channel logging, forwarding, retention, or delivery to the wrong recipient.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest presents the skill as 'simple personality analysis', but the instructions also configure persistent cron automation and channel-adaptive file delivery. This capability mismatch reduces informed consent and can cause users or reviewers to underestimate the amount of data collection and ongoing autonomous behavior the skill performs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file presents the skill as an AI instruction document entirely in Chinese and directs the assistant to follow those Chinese-language workflows, but it does not offer the user a language preference or explain that the skill is intentionally region-specific. This creates a language/locale policy concern because the skill appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad and generic, increasing the chance the skill activates during ordinary conversation rather than through a deliberate invocation. In this skill's context, accidental activation is more dangerous because activation can lead to session harvesting, profiling, file generation, and possible automated scheduling.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill persistently logs inferred personality traits and describes repeated backups of USER.md, creating an ongoing archive of sensitive user-derived information. Long-term retention of behavioral inferences increases privacy risk, impact of compromise, and difficulty of honoring deletion or scope expectations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The configuration includes auto_approve_first: true, which weakens the stated requirement for user review before updating profile content. In this skill's context, autonomous approval is risky because the action affects persistent user profiling and may occur after broad transcript analysis without a meaningful confirmation step.

Content

Scanner excerpt · SKILL.md (reported line 696)May include surrounding context.

md
confirmation:
  interval_days: 7            # 每 7 天确认一次
  auto_approve_first: true    # 首次自动批准
  
saturation:
  core: 0.7                   # 核心特质阈值(>=0.7 为🔴)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill directs the AI to use channel-specific file sending for a generated preview, even though such cross-channel delivery is not essential to local personality analysis. Sending derived profile content through external messaging paths increases exposure surface and may leak sensitive inferences to unintended recipients or systems.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation repeatedly describes backup artifacts like ChangeLog.mdUSER-YYYYMMDD-HHMM.md and says each change is automatically backed up, but the implementation shown merely writes summary entries into ChangeLog.md. This is an active contradiction because the comments and usage examples promise recoverable file backups that the code does not actually produce.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.