Back to skill

Security audit

Ping Me

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed reminder helper, but its cancellation command can remove unrelated OpenClaw scheduled jobs if given their IDs.

Review before installing if your OpenClaw account has important scheduled jobs. The reminder creation flow is understandable, but cancellation should be fixed or used carefully because an ID from another scheduled job could be removed. Prefer the ClawHub install path or a pinned installer over the unpinned `npx` command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/ping-me-cancel.sh:16
Finding

Cancellation Script Can Delete Unrelated OpenClaw Cron Jobs

Content
View full analysis
/dev/null | python3 -c ' import json, sys partial = sys.argv[1] try: data = json.load(sys.stdin) jobs = data.get("jobs", data) if isinstance(data, dict) else data if isinstance(jobs, list): for j in jobs: if isinstance(j, dict) and j.get("id", "").startswith(partial): print(j["id"]) sys.exit(0) except Exception: pass print("") ' "$JOB_ID" 2>/dev/null) || FULL_ID="" if [ -n "$FULL_ID" ]; then JOB_ID="$FULL_ID" fi fi RESULT=$("$OPENCLAW" cron rm "$JOB_ID" 2>&1) ``` ### Technical Analysis The cancellation script resolves a partial identifier against every cron job returned by `openclaw cron list --json`. It does not verify that the matched job belongs to this Skill or that its `name` is `ping-me`. The script also accepts a full identifier and passes it directly to `openclaw cron rm` without retrieving and validating the corresponding job first. Consequently, the cancellation operation is not restricted to reminders created by this project. Partial identifiers introduce an additional ambiguity problem: the script selects the first matching job without checking whether multiple jobs share that prefix. Although the listing script filters displayed jobs by name, that protection is not applied in the cancellation script. ### Attack Path 1. An attacker or user obtains, guesses, or is given the full ID or a unique prefix of an unrelated OpenClaw cron job. 2. The identifier is supplied to `ping-me-cancel.sh`. 3. For a partial identifier, the script searches all visible cron jobs and resolves the first matching ID without checking its job name ...[truncated 799 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:8
Finding

Installation Documentation Uses an Unpinned npx Installer

Content
View full analysis
Remediation
View remediation
skills add -g ``` The placeholder version and source reference must be replaced with verified, immutable values maintained by the project. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description emphasizes natural-language creation of one-shot reminders with auto-detected channel/timezone and universal channel support. The provided code does not create reminders at all; it deletes them by ID using cron list/rm commands. While cancellation could be part of a reminder system, this specific chunk’s primary behavior is materially different from the declared purpose and omits the headline capabilities in the description. Therefore this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents an end-user reminder skill whose main behavior is to parse reminder requests in any language, auto-detect channel/timezone, and ping the user at the appropriate time. The supplied code does not implement reminder creation, scheduling, parsing, or notification delivery. Instead, it is a CLI config-management script for viewing and changing settings in config.json. While some fields relate to the declared domain (tz, channel, lang), the primary purpose is materially different: configuration management rather than reminder execution. The code also performs file writes to persistent config storage, which is an undeclared capability relative to the empty permissions list.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a user-facing skill for creating one-shot reminders from natural language and automatically handling channel/timezone selection and later pinging the user. The actual code does not parse reminder requests, schedule reminders, detect language, detect timezone, or send notifications. Instead, it only lists active reminder-related cron jobs and formats them for display. While listing reminders may be a supporting feature of a reminder system, this code chunk’s actual behavior is materially narrower than the declared primary purpose, so the description does not accurately represent what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The core purpose is broadly aligned: the script does create one-shot reminders and does auto-resolve timezone/channel information. However, the description materially overstates capabilities in several ways. First, 'Say "remind me..." in any language' is not supported by this code; it only parses command-line arguments in fixed formats (30m, 2h, 1d, or ISO 8601 timestamps) and has no natural-language or multilingual parsing logic. Second, 'Works with every channel' is inaccurate because the script itself documents and handles failure cases where some channels require explicit --to delivery targets or default channel configuration. Third, the declared permissions are empty, but the code relies on environment/session context, local config, and invokes the openclaw scheduler to create outbound reminders, which is relevant resource access not reflected in the declaration. So this is a description/behavior mismatch, mainly due to overstated natural-language and universal-channel support.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
5. Call `ping-me.sh` with the parsed arguments

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs the agent to invoke scripts that can modify local state, including writing settings to config.json, but it declares no explicit tool scope or permissions. This creates a capability-transparency gap: reviewers and runtime policy layers cannot reliably constrain or audit file-writing behavior, increasing the chance of unintended persistence or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger language is broad enough that the skill may activate on vague reminder-like text across many contexts and languages, causing unintended command execution or state changes. Overbroad activation boundaries are risky for any skill that can schedule jobs, modify config, or enumerate/cancel reminders because benign conversation can be misinterpreted as an instruction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to run channel-targeted scripts silently before telling the user what happened. Silent execution reduces user awareness and consent, making it easier to trigger message delivery, channel routing, configuration-dependent targeting, or other side effects without meaningful notice or verification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description is very broad ('One-shot reminders via natural language' and 'Works with every channel'), which can cause the skill to trigger on common conversational phrasing far outside explicit reminder requests. In an agent environment, overbroad matching can lead to unintended activation, message interception, or execution in the wrong channel/context, especially because reminder language is common in everyday chat.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
0% confidence
Finding

No actionable finding: the file supports any language and tells the agent to confirm in the user's language rather than forcing a specific language or locale. This does not meet the stated criteria for a language or locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.