Back to skill

Security audit

Xinqing Journal

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Chinese mood journal that stores sensitive entries on the user's machine, with no evidence of hidden networking, privilege escalation, or deceptive behavior.

Install only if you are comfortable keeping mood and journal content in a local JSON file under your OpenClaw workspace. The tool appears local-only and user-directed, but its interface and classifications are Chinese-focused and its mood analysis is simple keyword-based tracking, not medical or clinical advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented behavior claims a full local mood-journaling system with NLP-style entry parsing, scoring, tagging, and reporting, but the static finding says the implementation only covers a report-analysis submodule. This mismatch is dangerous because users and reviewers may trust privacy, functionality, and data-handling claims that are not actually implemented, which can conceal missing safeguards or cause users to rely on incorrect mental-health tracking outputs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises executable scripts and local file storage but does not declare any explicit tool scope such as allowed-tools or permissions. In agent environments, missing scope declarations can cause over-broad default access or prevent reviewers from understanding that shell execution and file read/write are required, increasing the chance of unintended filesystem modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description states that the skill records Chinese journals, and the rest of the document consistently presents usage only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified as region-specific, which is not provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON mixes some English keywords with predominantly Chinese mood names, tag names, and default values, which creates an implicit Chinese locale requirement for core outputs and classifications. Because SQP-3 applies to all file types, this is a natural-language locale policy concern when no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code embeds user-facing descriptions, help text, errors, and output in Chinese, beginning with the module docstring and continuing throughout the CLI. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code accesses personal mood-journal entries stored under the user's home directory and later analyzes and prints summaries derived from that data. While the file path implies the purpose, the script does not include any user-facing warning, comment, or docstring disclosing that it will read potentially sensitive mental-health data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language strings, help text, and generated reports are all hard-coded in Chinese, which effectively forces a specific language for users. The file does not provide an opt-in, alternate locale, or justification for the language restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.