Back to skill

Security audit

Scrask

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated screenshot-to-calendar/task purpose, but it can send screenshots to external vision models and trigger calendar or task writes without a final user approval.

Install only if you are comfortable with screenshots being processed by configured vision providers and with clear extracted items being added to your calendar or task app without a final preview approval. Prefer narrowing the trigger aliases, enabling a confirmation-before-write policy, redacting sensitive screenshots, and pinning dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:193
Finding

Untrusted vision-model output can trigger downstream writes without explicit user approval

Content
View full analysis
dict: cleaned = raw.removeprefix("```json").removeprefix("```").removesuffix("```").strip() return json.loads(cleaned) ``` The model controls the item type, confidence values, destination selection, fields, and whether clarification is required: ```python item_type = item.get("type", "task") destination = "calendar" if item_type == "event" else "task" confidences = item.get("confidences") or {} if "confidence" in item and isinstance(item["confidence"], (int, float)): confidence = float(item["confidence"]) elif confidences: confidence = min(confidences.values()) else: confidence = 0.0 type_confidence = float(item.get("type_confidence", confidence)) title = item.get("title") or "this item" clarifications: list[dict] = [] if type_confidence < type_threshold: clarifications.append({ "field": "type", "question": CLARIFICATION_QUESTIONS["type"].format(title=title), "reason": "low_type_confidence", }) mandatory = MANDATORY_FIELDS_BY_TYPE.get(item_type, MANDATORY_FIELDS_BY_TYPE["task"]) for field in mandatory: value = item.get(f ...[truncated 4088 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Unbounded dependency versions make installations non-reproducible

Content
View full analysis
=0.40.0 google-generativeai>=0.8.0 ``` The documented installation process uses this file: ```bash pip install -r ~/.openclaw/skills/scrask-bot/scripts/requirements.txt ``` ### Technical Analysis Both dependencies use open-ended lower bounds. Consequently, an installation may resolve to any later release available from the configured package index rather than the versions reviewed with this project. No lock file or package hashes are supplied. The installed dependency graph can therefore change over time without any modification to the audited project. This weakens build reproducibility and makes it impossible to verify that the runtime dependency code matches the audited environment. This finding does not establish that the named packages are malicious. The risk is that future compromised, vulnerable, or incompatible releases can be installed automatically under the existing constraints. ### Attack Path 1. A user follows the documented `pip install -r` command. 2. The package resolver queries the configured Python package index. 3. Because only minimum versions are specified, it selects the newest compatible releases and their transitive dependencies. 4. A future compromised or vulnerable release can be downloaded without a corresponding review of this Skill. 5. Dependency installation or subsequent imports execute code outside the version set originally audited. 6. That code runs with the permissions of the user or service account installing or invoking the Skill. A related configuration risk exists if the installation environment uses an untrusted package index or mirror, because no hashes are present to detect substituted artifacts. ### Impact Assessment The maxi ...[truncated 640 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The explicit alias "screenshot" is so generic that ordinary user messages are likely to match it unintentionally, causing Scrask to be force-invoked outside the narrower implicit routing conditions. In this skill, that can lead to screenshots being sent to vision parsing and downstream calendar/task delegation when the user may have only been discussing a screenshot, increasing the risk of unintended data processing and accidental action creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README encourages users to send screenshots through chat surfaces and have them parsed by external vision providers, but it does not present a prominent privacy warning about potentially sensitive content in screenshots or third-party processing. This is dangerous because screenshots often contain personal messages, emails, invite links, phone numbers, or account data, and users may not realize that image contents can be transmitted beyond the local chat surface to OpenClaw-configured or optional vendor LLMs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The alias list includes very generic trigger phrases such as "screenshot" and "screenshot to calendar," which can collide with ordinary user conversation and cause unintended invocation. In this skill, unintended invocation is more sensitive because it can automatically parse screenshots and route extracted tasks/events to downstream calendar or task skills, potentially leading to privacy exposure or unwanted writes via delegated skills.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill executes a shell command and reads environment-backed credentials, but it does not declare a formal tool scope or allowed-tools boundary. That mismatch weakens least-privilege enforcement and makes it harder for the platform to constrain what the skill can access at runtime, especially given it handles screenshots and can reach external LLM providers.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The alias list includes the everyday word "screenshot," which is broad enough to match ordinary user messages and force-route them to this skill. Because explicit aliases override implicit routing, this can cause unintended activation, sending user images to a vision parser and downstream calendar/task workflows when the user may have meant something else.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs that non-English screenshot content be converted so title and description are "already in English" without user opt-in. This can expose sensitive content to translation/normalization, alter meaning, and create privacy or integrity issues for users who expected the original language to be preserved.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented flow allows the bot to 'save the item silently' when the parse appears clear, which can lead to unauthorized or mistaken calendar/task modifications from ambiguous screenshots, maliciously crafted images, or model hallucinations. In a cross-chat ingestion skill handling screenshots from multiple surfaces, automatic writes without explicit user confirmation increase the risk of integrity loss, privacy exposure, and social-engineering-triggered actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Lines L271-L273 explicitly say the shaped output fills optional defaults such as recurrence -> "none", priority -> "medium", and already_in_calendar_hint -> False. Later, lines L384-L385 state the opposite design principle: 'Defaults belong downstream' and 'The parser reports what it saw, not what to assume.' That is a direct documentation-to-documentation contradiction about what the code does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented flow permits 'silent' dispatch of extracted screenshot contents to calendar/task skills without an explicit final user approval or prominent disclosure that data will be transmitted to other services. Because screenshots can contain sensitive personal information, automatic forwarding to downstream integrations increases privacy and consent risk, especially across chat surfaces and third-party skills.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

This documents autonomous action: if confidence thresholds pass, the bot sends data to external destination skills 'without asking.' In this skill's context, the source is an image from arbitrary chat platforms and the sink is an external calendar/task system, so incorrect extraction, prompt misunderstanding, or sensitive content misclassification could cause unauthorized data disclosure or unintended record creation.

Content

Scanner excerpt · docs/decision-flow.html (reported line 624)May include surrounding context.

html
silent_dispatch: {
        tag: 'step',
        title: 'Silent dispatch to destination skill',
        body: '<p>When <code>needs_confirmation: false</code> AND the actionable gate is clear, the bot invokes the destination skill without asking. Item fields go in, a confirmation reply comes out.</p>',
        ref: 'SKILL.md &middot; "For each item &mdash; if <code>needs_confirmation: false</code>" section.'
      },
      destination: {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented bot flow explicitly allows items with needs_confirmation: false to be routed silently to calendar or task destination skills, which can create real external-side effects from an OCR/LLM parse without a final explicit user approval step. In this skill context, screenshots are noisy and model extraction can be wrong, so silent dispatch increases the risk of unintended event/task creation, especially when downstream skills write to user-owned systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language prompt explicitly instructs the model to always write the title and description in English, even when the screenshot text is in another language. This imposes a language choice on users without offering an opt-in or alternative, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the model to extract named attendees from screenshots, including chat senders when attendance is implied, and then forwards those names in structured output and user-visible summaries. Because screenshots may come from private chats, invites, or group threads, this can disclose third-party personal data to downstream calendar/task skills or broader agent logs without minimization or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The sample configuration sets timezone to Asia/Kolkata with no indication that this is only an example or that users should choose their own locale. This can violate language/locale policy expectations by implicitly forcing a region-specific setting without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Lines L021-L025 describe Scrask as only parsing screenshots and telling the assistant what it found, while later sections describe shape_intent generating exact clarification questions and format_summary producing chat-ready preview text. Those are still bot-interaction artifacts rather than pure parsing output, so the documentation's strict 'just a parser' framing is somewhat contradicted by the documented code responsibilities.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The overview text says the parser side is stateless and only emits JSON intent for the bot to route, matching the manifest's constrained scope. However, the same document frames the overall behavior as proceeding from screenshot ingestion to an item being saved in calendar/task systems and later describes silent dispatch to destination skills, which can blur the boundary between parser-only behavior and bot-side side effects.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a lower bound only, which allows future installs to resolve to different versions over time. This creates a supply-chain risk and makes builds non-reproducible, especially relevant here because the package is used to process user-provided screenshots through an external AI SDK path.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
anthropic>=0.40.0
google-generativeai>=0.8.0

Unverifiable Dependency: anthropic has 4 known advisory(ies) (CVE-2026-34450 (Claude SDK for Python has Insecure Default File Permissions in Local Filesystem ); CVE-2026-34452 (Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox); CVE-2026-34450 (The Claude SDK for Python provides access to the Claude API from Python applicat) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The manifest references a package with known advisories but does not pin a version, so it is impossible to determine from this file whether the resolved installation includes a vulnerable release. Because this skill uses the SDK to handle user-originated content and likely API credentials, leaving the affected version range unspecified weakens assurance and could expose the environment if a vulnerable version is installed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The package version is not pinned, so installations may pull newer releases with different behavior or undisclosed security issues. In a skill that sends parsed screenshot content through third-party model SDKs, this increases supply-chain and operational risk even if the manifest itself contains no code.

Content

Scanner excerpt · scripts/requirements.txt (reported line 2)May include surrounding context.

text
anthropic>=0.40.0
google-generativeai>=0.8.0

Static analysis

No suspicious patterns detected.