Back to skill

Security audit

powpow-financing-plan-openclaw-en

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed PowPow investor Q&A and outreach flow with user-controlled memory use and email submission, with only limited privacy considerations around web search and contact sharing.

Before installing, be aware that this is an investor-outreach skill: it may ask about your investing style and contact details, and may prepare an email to the PowPow founder. Memory use is opt-in, contact fields are optional, and email sending requires preview and confirmation. Avoid sharing sensitive investment or personal details unless you are comfortable sending them to the listed contact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: powpow-financing-plan-openclaw-en
description: 'PowPow angel-round/Pre-A funding plan — an interactive investor challenge. Investors reveal their investing style through 13 questions so both sides can see whether they are a good fit — no scores, no grades, just a portrait of collaboration style. Triggers when the user names PowPow and expresses funding/investment interest, e.g. "PowPow funding", "tell me about the PowPow project", "become a PowPow investor", "I want to invest in PowPow". Industry topics (AI social / angel round, etc.) trigger only when PowPow is also named or the intent clearly points to this funding plan.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The version history states the skill uses 'English-only triggers, English-only founder's message, English question pool, style mappings, and email templates.' This imposes a language constraint in the skill's behavior, but the document does not offer the user a language choice or indicate that English-only use is optional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest explicitly instructs the skill to use websearch and fetch content from external sites, but it does not require a clear user-facing disclosure at the moment network access occurs. That can cause silent transmission of user queries or conversation-derived context to third parties, creating privacy and trust risks, especially in an investment-oriented flow where sensitive business interests may be discussed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.