T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:178- Finding
Unrestricted Collection of Private Conversation History
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a Review item because it can profile you from broad OpenClaw conversation history, store that profile persistently, schedule recurring analysis, and send previews through chat.
Install only if you are comfortable with this skill reading recent and future OpenClaw conversation history to infer personality traits, storing those in USER.md and skill files, and possibly sending preview files through your chat channel. Prefer manual mode, review the exact preview before confirming updates, avoid scheduled mode unless you want ongoing profiling, and know how to delete temp/USER.md, ChangeLog.md, last_analysis.json, and any cron entries.
SKILL.md:178Unrestricted Collection of Private Conversation History
SKILL.md:53Persistent Twice-Daily Processing Through OpenClaw Scheduled Tasks
The skill mines prior conversations, extracts user text, and persists inferred traits into preview/profile files. This re-processes and re-exposes potentially sensitive personal information in plain language, creating a durable profile that could be accessed later or disclosed beyond the original conversational context.
The skill instructs the agent to scan all session transcript files under the sessions directory and extract prior user messages, including historical content from multiple conversations. That is broad conversation harvesting beyond what is minimally necessary, and it creates a high risk of collecting sensitive data without clear scope limitation or fresh consent.
The skill tells the AI to send the generated USER.md preview back through the messaging channel, and that preview contains accumulated personality analysis and user-derived content. Transmitting sensitive inferred data over chat increases the chance of disclosure through channel logging, forwarding, retention, or delivery to the wrong recipient.
The manifest presents the skill as 'simple personality analysis', but the instructions also configure persistent cron automation and channel-adaptive file delivery. This capability mismatch reduces informed consent and can cause users or reviewers to underestimate the amount of data collection and ongoing autonomous behavior the skill performs.
The file presents the skill as an AI instruction document entirely in Chinese and directs the assistant to follow those Chinese-language workflows, but it does not offer the user a language preference or explain that the skill is intentionally region-specific. This creates a language/locale policy concern because the skill appears to impose a specific language by default.
The trigger phrases are broad and generic, increasing the chance the skill activates during ordinary conversation rather than through a deliberate invocation. In this skill's context, accidental activation is more dangerous because activation can lead to session harvesting, profiling, file generation, and possible automated scheduling.
The skill persistently logs inferred personality traits and describes repeated backups of USER.md, creating an ongoing archive of sensitive user-derived information. Long-term retention of behavioral inferences increases privacy risk, impact of compromise, and difficulty of honoring deletion or scope expectations.
The configuration includes auto_approve_first: true, which weakens the stated requirement for user review before updating profile content. In this skill's context, autonomous approval is risky because the action affects persistent user profiling and may occur after broad transcript analysis without a meaningful confirmation step.
confirmation:
interval_days: 7 # 每 7 天确认一次
auto_approve_first: true # 首次自动批准
saturation:
core: 0.7 # 核心特质阈值(>=0.7 为🔴)
The skill directs the AI to use channel-specific file sending for a generated preview, even though such cross-channel delivery is not essential to local personality analysis. Sending derived profile content through external messaging paths increases exposure surface and may leak sensitive inferences to unintended recipients or systems.
The documentation repeatedly describes backup artifacts like ChangeLog.mdUSER-YYYYMMDD-HHMM.md and says each change is automatically backed up, but the implementation shown merely writes summary entries into ChangeLog.md. This is an active contradiction because the comments and usage examples promise recoverable file backups that the code does not actually produce.
No suspicious patterns detected.