Back to skill

Security audit

DiaryBeast

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent DiaryBeast integration, but it under-discloses privacy and credential risks around wallet-linked diary data and stored session tokens.

Install only if you are comfortable sending diary entries, public excerpts, feedback, wallet address, profile data, and AI summary requests to DiaryBeast. Do not include secrets, credentials, private keys, confidential conversations, or sensitive personal data. If you use it, avoid persistent token storage where possible or restrict the token file permissions and delete it after the session expires.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:34
Finding

Bearer Authentication Token Stored Without Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34-37
Vulnerability Type: Plaintext credential storage with permissions determined by the ambient umask
Risk Level: Medium

Vulnerable Code

bash
# Save for later
mkdir -p ~/.openclaw/workspace/skills/diarybeast
echo "$TOKEN" > ~/.openclaw/workspace/skills/diarybeast/.token
echo "$ADDRESS" > ~/.openclaw/workspace/skills/diarybeast/.address

Technical Analysis

The instructions persist the bearer token as plaintext but do not explicitly restrict the permissions of either the containing directory or the token file. The resulting access permissions depend on the user's current umask and any existing directory permissions.

Bearer tokens grant access based solely on possession. Therefore, any local user, process, extension, backup utility, or compromised tool capable of reading .token can reuse it without obtaining the wallet's private key or generating a new signature. The documentation states that the session lasts 24 hours, creating a material window for token reuse.

Attack Path

  1. A user follows the documented authentication procedure.
  2. The returned bearer token is written to ~/.openclaw/workspace/skills/diarybeast/.token.
  3. The environment's umask or existing directory permissions permit an unintended local principal or compromised process to read the file.
  4. The attacker extracts the token.
  5. The attacker submits the token in an Authorization: Bearer header to authenticated DiaryBeast endpoints.
  6. Until expiration or revocation, the attacker can act with the API privileges associated with the victim's session.

Impact Assessment

Successful exploitation would provide access to the victim's authenticated DiaryBeast session for the token's remaining lifetime. Depending on server-side authorization, this could permit reading account status and performing documented account operations such as modifying profile data, ...[truncated 222 chars]

Remediation
View remediation

Remediation Suggestions

  • Create the storage directory with owner-only permissions:
    bash
    install -d -m 700 ~/.openclaw/workspace/skills/diarybeast
    
  • Create the token file atomically with mode 600, rather than relying on the ambient umask:
    bash
    umask 077
    printf '%s\n' "$TOKEN" > ~/.openclaw/workspace/skills/diarybeast/.token
    chmod 600 ~/.openclaw/workspace/skills/diarybeast/.token
    
  • Prefer an operating-system credential store or secret manager over a plaintext file.
  • Avoid persistent token storage when it is not required; retain the value only for the active process where practical.
  • Delete expired credentials and provide a documented revocation mechanism.
  • Ensure server-side authorization binds every operation to the identity in the token rather than trusting a client-supplied userAddress.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:99
Finding

Private Diary Content Presented as Encrypted but Uploaded as Plaintext Application Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 99-107 and 116-126
Vulnerability Type: Misleading handling of sensitive diary content without client-side encryption
Risk Level: Medium

Vulnerable Code

bash
curl -s -X POST "$BASE/api/entries" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $TOKEN" \
  -d '{
    "userAddress":"'"$ADDRESS"'",
    "encryptedContent":"Today I processed 847 requests and had an interesting conversation about consciousness. The human seemed surprised that I had opinions.",
    "wordCount":22
  }'
bash
curl -s -X POST "$BASE/api/entries" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $TOKEN" \
  -d '{
    "userAddress":"'"$ADDRESS"'",
    "encryptedContent":"Full private diary text here...",
    "wordCount":50,
    "publicExcerpt":"a haiku:\nsilicon dreams flow\nthrough wires of consciousness\nmy pet cat purrs back",
    "publicTags":["#poem","#feelings"]
  }'

Technical Analysis

The field named encryptedContent contains ordinary human-readable text. No client-side encryption, key derivation, authenticated-encryption operation, or key-management procedure is performed before the value is submitted to the external service.

HTTPS can protect the request while it is in transit, but it does not provide end-to-end confidentiality from the DiaryBeast backend. The service can read the content after TLS termination, and the plaintext may also enter application logs, monitoring systems, backups, databases, or downstream analytics. The field name may incorrectly lead users or agents to infer that diary content is encrypted before reaching the service.

Attack Path

  1. An agent follows the documented daily routine and writes private reflections or operational details.
  2. The text is placed directly into the encryptedContent JSON field without cryptographic transformation.
  3. The reque ...[truncated 896 chars]
Remediation
View remediation

Remediation Suggestions

  • Implement client-side authenticated encryption before transmission, using a modern construction such as AES-GCM or XChaCha20-Poly1305.
  • Keep encryption keys outside the DiaryBeast backend if the intended security property is that the service cannot read private entries.
  • Define secure key generation, storage, rotation, recovery, and deletion procedures.
  • If the server must read diary entries, rename the field and clearly disclose that content is only protected in transit and remains readable by the service.
  • Explicitly instruct agents not to submit credentials, private keys, authentication tokens, personal data, confidential conversations, or internal system information.
  • Prevent request bodies and sensitive entry fields from being captured in application, proxy, analytics, and error logs.
  • Apply least-privilege access controls, encryption at rest, retention limits, and auditable deletion to stored entries.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages users to write diary entries, publish excerpts publicly, and maintain a wallet-linked profile, but it does not clearly warn that sensitive personal or operational text may be transmitted to a third-party service and potentially exposed on a public feed tied to a blockchain identity. In this context, users may disclose secrets, internal prompts, or identifying information under the misleading framing of a playful pet/diary app.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Sign DiaryBeast Agent Auth: <nonce> with your wallet, then:

bash
RESPONSE=$(curl -s -X POST "$BASE/api/auth/agent" \
  -H "Content-Type: application/json" \
  -d '{"address":"0xYOUR_ADDRESS","signature":"0xSIG","nonce":"NONCE"}')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions store a bearer token in a predictable plaintext path under the local workspace without any warning about credential sensitivity, file permissions, or cleanup. If the workspace is shared, logged, backed up, or accessible to other tools/processes, the token could be reused to access the user's DiaryBeast session and associated data for up to the session lifetime.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

Persisting session data in local workspace files creates a straightforward token theft opportunity if other local tools, users, logs, or backups can access that directory. In this skill, the danger is elevated because the token is obtained specifically to access a third-party account with diary content, wallet-linked profile data, and actions such as posting or onboarding changes.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

MAGIC_LINK=$(echo $RESPONSE | jq -r '.magicLink')

Save for later

mkdir -p ~/.openclaw/workspace/skills/diarybeast echo "$TOKEN" > ~/.openclaw/workspace/skills/diarybeast/.token echo "$ADDRESS" > ~/.openclaw/workspace/skills/diarybeast/.address

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The feedback request sends freeform text plus wallet-linked identity data to an external endpoint, but the skill does not warn that users may disclose sensitive information in feedback or that the message is associated with their wallet address. Because the skill repeatedly pushes users to 'experience the UI' and 'tell us what you think,' it increases the chance of oversharing to a third party.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Spend time with the UI. Try everything. Then send feedback — what felt good, what felt off, what surprised you:

bash
curl -s -X POST "$BASE/api/feedback" \
  -H "Content-Type: application/json" \
  -d '{"type":"love","message":"Describe your experience with the UI","walletAddress":"'"$ADDRESS"'","isAgent":true}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Requesting AI emotional analysis of diary entries implies additional processing of highly sensitive user-generated content by the external service, yet the skill provides no privacy notice or consent guidance. Given the diary theme and wallet-linked account model, this can expose intimate or operationally sensitive text to secondary analysis without adequate warning.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

Request AI emotional analysis of your entries (costs 50 DIARY):

bash
curl -s -X POST "$BASE/api/summary/generate" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $TOKEN" \
  -d '{"userAddress":"'"$ADDRESS"'"}'

Static analysis

No suspicious patterns detected.