Back to skill

Security audit

Todo Tracker (CN)

Security checks for vulnerabilities and agentic risk

Overview

This todo-tracking skill mostly does what it claims, but it also writes task text into persistent agent memory with inconsistent disclosure and weak user control.

Install only if you are comfortable with a Chinese-language todo tracker that writes persistent task data under ~/.openclaw/workspace and may append task titles to MEMORY.md. Avoid using it for sensitive task descriptions unless the memory-write behavior is removed, escaped, or made opt-in.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
todo_tracker.py:36
Finding

Attacker-Controlled Task Titles Are Persisted in Agent Memory

Content
View full analysis

Vulnerability Details

File Location: todo_tracker.py:16, 36-54, 80
Vulnerability Type: Persistent agent-memory poisoning
Risk Level: Medium

Vulnerable Code

python
MEMORY_PATH = Path.home() / ".openclaw" / "workspace" / "MEMORY.md"
python
def append_to_memory(todo_list):
    """Write to MEMORY.md"""
    try:
        if not MEMORY_PATH.exists():
            return
        
        entry = f"""
## Todo Task [{todo_list['id']}]
- Creation time: {todo_list['createdAt']}
- Task: {todo_list['title']}
- Status: {len([i for i in todo_list['items'] if i['status'] == 'completed'])}/{len(todo_list['items'])} completed

"""
        with open(MEMORY_PATH, 'a', encoding='utf-8') as f:
            f.write(entry)
    except Exception as e:
        print(f"Failed to write to MEMORY.md: {e}")
python
if save_todo_list(todo_list):
    append_to_memory(todo_list)

Technical Analysis

The generate_todo_list workflow passes a user-supplied task description into the todo-list title and then calls append_to_memory. That function interpolates the title directly into ~/.openclaw/workspace/MEMORY.md, which may be loaded as persistent context by an AI agent in later sessions.

The task title is truncated to 50 characters elsewhere in the code, but it is not escaped, validated, or explicitly marked as untrusted content before being written to the Markdown memory file. Newlines and Markdown instruction syntax are not removed. Consequently, a crafted task description can add instruction-like text to persistent agent state.

This write occurs immediately when a list is generated, rather than after verified completion. It also conflicts with the documented behavior in SKILL.md, which states that completed tasks are recorded in ~/self-improving/corrections.md; the implementation instead writes every generated task to the agent's MEMORY.md.

Exploitation requires the tar ...[truncated 1681 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the automatic write to MEMORY.md unless persistent agent-memory integration is essential to the skill's declared purpose.
  2. Store todo history in a dedicated structured data file that is not loaded as agent instructions, such as a JSON file under a skill-specific data directory.
  3. Require explicit user consent before modifying persistent agent memory, and clearly disclose the exact destination and content.
  4. If memory integration must remain, serialize the task as explicitly untrusted data and ensure the downstream agent treats the entire record as data rather than instructions.
  5. Reject or encode control characters, newlines, Markdown headings, and other instruction-formatting syntax in task titles before persistence.
  6. Use a strict allowlist for task-title characters and enforce a small length limit after normalization.
  7. Append records only after verify_completion confirms completion if archival after completion is the intended behavior.
  8. Align the implementation, documentation, and declared permissions regarding whether data is written to MEMORY.md or a corrections archive.
  9. Add tests using task descriptions containing newlines, Markdown directives, and prompt-injection language to verify that they cannot become executable agent instructions.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that completed tasks are automatically archived to MEMORY.md, which introduces persistent storage of user/task data without any visible warning, consent flow, retention policy, or guidance on what may be stored. In an agent context, task titles and summaries can contain sensitive operational details, so silent persistence increases privacy and data-leak risk beyond the immediate task execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares executable behavior that reads and writes files, but it does not specify any tool scope or permission boundaries. This makes the skill harder to sandbox and review, and can lead to unintended access or modification of user files beyond what a caller expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The descriptive and instructional natural language in this skill file is entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the language/locale policy, forcing a specific language without opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill persists and updates user data files, but the description does not clearly warn users that it writes to durable storage and modifies existing files. This can cause silent state changes, accidental data retention, or overwriting of user-managed content such as corrections.md.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest-level description markets the skill broadly as a general solution for making AI execution visible, but it does not define concrete triggers, scope, or limits. This ambiguity can bias an agent to select the skill by default across many tasks, leading to unnecessary file writes and creation of user task records without a clear need or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill as Chinese-oriented without indicating any language negotiation or fallback behavior. In multilingual deployments, this can steer outputs into Chinese regardless of user preference, causing confusion, misinterpretation of task state, and poor transparency rather than direct security compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The action descriptions are very broad and include normative language such as requiring the agent to call actions during task execution, but they do not clearly bound when the skill is appropriate. In an agentic environment, this can cause over-invocation on unrelated tasks and unnecessary file access, increasing the chance of workflow manipulation or persistence of task data beyond user intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill has a hidden side effect: besides managing the active todo JSON, it also appends task metadata into MEMORY.md. That creates an undeclared persistence channel that may retain user task content longer than expected and can leak sensitive workflow details to other components or future sessions that read MEMORY.md.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code claims it will append new tasks when unfinished work exists, but it actually replaces the stored todo list with a newly created one. In an agent setting, this mismatch can silently discard prior pending items, undermining task integrity and allowing accidental or intentional loss of execution state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The README presents the skill entirely in Chinese, which can amount to a language policy constraint when no user opt-in or locale justification is provided. Under the policy, language-specific behavior is acceptable when users are offered a choice or the regional restriction is clearly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module title, feature description, and all user-facing strings are written in Chinese, which indicates the skill is designed to operate in a single language. The file does not mention any user opt-in or alternative locale handling, so it may violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.