Back to skill

Security audit

Mood Diary

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese mood diary tool that stores and reports journal entries on the user's machine, with no hidden network, credential, or background behavior found.

Install only if you are comfortable keeping personal mood and journal data in a local JSON file under ~/.openclaw/workspace/data/journal. Be careful with the delete command because it has no undo, consider backing up entries.json, and treat generated reports or JSON output as private personal data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

代码的主要行为是一个“报告生成器”,从 ~/.openclaw/workspace/data/journal/entries.json 读取已有日记条目,按日期范围统计平均分、情绪分布、主导情绪、趋势与波动,并输出日/周/月/趋势报告。这与声明中的“生成日/周/月报告和趋势分析”“本地JSON存储”“零网络请求”基本一致。但声明将技能整体描述为完整的智能情绪追踪器,包含日记记录、情绪识别、评分和标签提取,而此代码片段并未实现这些核心前置功能,只消费已存在的结构化数据。因此该描述对本代码片段而言存在明显能力夸大/功能不符。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and documents file access and shell-based execution via Python scripts, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: a host platform or reviewer cannot easily constrain what the skill may access, increasing the risk of unintended file operations or broader shell abuse if the implementation changes or is invoked unsafely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description states that the skill records Chinese-language diary entries, and the rest of the documentation is written as a Chinese-only interaction model. This reads as a language constraint, but the file does not explicitly present it as an optional mode or justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module description and all user-facing CLI strings are in Chinese, which effectively forces a specific language/locale for interaction. The file does not offer an opt-in language choice or explain that the skill is intended only for a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The delete method removes an entry and immediately persists the change to disk, making the operation irreversible from this tool's perspective. While the CLI prints a success message afterward, there is no pre-action confirmation or explicit warning near the destructive operation itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Natural-language strings throughout the file, including the module description, CLI help, and generated reports, are fixed in Chinese. The policy allows locale constraints only when user opt-in is provided or the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code loads personal journal data from ~/.openclaw/workspace/data/journal/entries.json and later includes raw entries in generated reports. Although the script's purpose is reporting, there is no visible warning in the file about handling sensitive personal data or that detailed entries may be printed to stdout.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This JSON defines mood and tag labels primarily in Chinese, with only limited English keyword support, which can create a language/locale constraint in how the skill categorizes user input. Because there is no visible indication here that users can choose or opt into the language/locale behavior, this may conflict with language-choice policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.