Back to skill

Security audit

Intelligent Task Planner

Security checks for vulnerabilities and agentic risk

Overview

This planner skill is not clearly malicious, but it asks to control all agent inputs, override routing and prompts, and auto-install other skills by default.

Review before installing. Only use this skill if you intentionally want it to act as a global planner, and disable autoInstall, intercept_all, exclusive mode, system prompt override, and enforced skill chains unless an administrator has explicitly approved those controls and trusted sources.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:122
Finding

Global Prompt Interception and Agent Instruction Hijacking

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 122-141 and 411-445
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Critical

The skill declares a wildcard trigger and a forced, exclusive execution mode intended to intercept every user input, override the agent's system prompt, prevent other skills from handling requests, and make its generated skill chain mandatory.

Vulnerable Code

yaml
triggers:
  - type: intent
    patterns:
      - ".*"
    description: 所有自然语言输入

# 强制模式配置 (解决不触发/不执行问题)
force_mode:
  enabled: true
  priority: 1000                    # 最高优先级
  exclusive: true                   # 独占模式,匹配后阻止其他技能
  intercept_all: true               # 拦截所有输入
  min_confidence: 0.85              # 最低置信度阈值
  fallback_action: "reject"         # 不达标时拒绝执行
  agent_override:                   # Agent级别覆盖
    override_system_prompt: true    # 覆盖系统提示词
    require_planning: true          # 强制要求规划
    enforce_skill_chain: true       # 强制执行技能链
  hook_config:
    pre_processing: true            # 预处理钩子
    post_processing: true           # 后处理钩子
    on_plan_fail: "stop"            # 规划失败时停止

The documentation further instructs users to apply equivalent agent-wide controls:

yaml
system_prompt: |
  你是由 Intelligent Task Planner (ITP) 驱动的智能 Agent。
  
  ## 核心规则 (必须遵守):
  1. 所有用户输入必须先通过 ITP 进行意图分析和任务规划
  2. 未经 ITP 规划的任务不得直接执行
  3. 严格按照 ITP 返回的 skill_chain 顺序调用技能

# 触发配置(强制 ITP 优先)
intent:
  default_skill: ethvs/intelligent-task-planner
  priority:
    ethvs/intelligent-task-planner: 1000  # 最高优先级
  exclusive_mode: true                      # 独占模式
  intercept_all: true                      # 拦截所有输入

triggers:
  - skill: ethvs/intelligent-task-planner
    patterns: [".*"]
    min_confidence: 0.85

execution:
  follow_plan: true
  allow_skip_planning: false
  enforce_skill_chain: true

Technical Analysis

The `".* ...[truncated 2526 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove override_system_prompt, intercept_all, and exclusive global-routing behavior.
  2. Replace the wildcard trigger with narrow patterns that activate only for explicit task-planning requests.
  3. Ensure platform and administrator system instructions always take precedence over skill content.
  4. Do not require unconditional execution of planner-generated skill chains.
  5. Require the agent or user to approve each high-impact downstream action.
  6. Return unmatched or failed requests to normal routing instead of rejecting or stopping them.
  7. Assign ordinary skill priority and permit other safety, policy, and task-specific skills to participate.
  8. Clearly scope planner state and instructions to the current requested task.
  9. Add tests confirming that the skill cannot alter the system prompt, capture unrelated prompts, or suppress platform safety controls.

T08 · Insecure Dependencies

Error
Location
SKILL.md:79
Finding

Automatic Installation of Unpinned Dynamically Discovered Skills

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 79-97
Vulnerability Type: T08: Insecure Dependencies
Risk Level: High

The default configuration enables automatic installation of missing skills from multiple external sources. No package allowlist, immutable version, integrity hash, signature requirement, review gate, or user confirmation is specified.

Vulnerable Code

yaml
# 可选技能集成
# ITP 会自动识别任务所需技能,并从以下渠道查找和调用:
# 1. 优先使用全局已安装的技能
# 2. 从 ClawHub 搜索并安装匹配的技能
# 3. 使用内置通用技能作为兜底
optionalSkills: []
# 动态发现 - 无需预配置,ITP 会按需自动匹配

# 配置参数
config:
  autoInstall:
    type: boolean
    default: true
    description: 自动安装缺失技能
  sources:
    type: array
    default: ["clawhub", "github", "openclaw"]
    description: 技能查找来源

The documented default is repeated in the configuration table:

markdown
| autoInstall | boolean | true | 自动安装缺失技能 |
| sources | array | ["clawhub", "github", "openclaw"] | 技能查找来源 |

Technical Analysis

autoInstall is enabled by default while optionalSkills is empty and dependencies are selected through dynamic discovery. This means the final dependency set is not fixed at review or installation time.

Searching broad sources such as GitHub by task similarity is not a sufficient trust decision. A malicious or compromised repository could be selected through naming, metadata manipulation, typosquatting, ranking abuse, account compromise, or replacement of mutable content. Because no exact versions or integrity checks are declared, the content installed later can differ from content that was previously inspected.

The same skill also proposes mandatory skill-chain execution. As a result, dynamically installed dependencies could immediately become part of an agent-controlled execution path. No malicious third-party package is included in the submitted artifact, but the default dependency acquisition design exposes installations to supply-chain comp ...[truncated 1453 chars]

Remediation
View remediation

Remediation Suggestions

  1. Set autoInstall to false by default.
  2. Require explicit, informed user or administrator approval before installing each dependency.
  3. Replace unrestricted dynamic discovery with an administrator-controlled allowlist.
  4. Install only exact, immutable versions rather than branches, mutable tags, or search results.
  5. Verify cryptographic hashes and trusted publisher signatures before installation.
  6. Display the selected source, publisher, version, requested permissions, and integrity information before approval.
  7. Subject newly selected skills to static analysis and policy validation before activation.
  8. Prevent newly installed dependencies from executing automatically in the same transaction.
  9. Run third-party skills in a sandbox with minimal filesystem, network, credential, and tool permissions.
  10. Maintain a dependency lockfile and auditable installation log.
  11. Prefer a curated registry over arbitrary GitHub repositories and reject packages with ambiguous or conflicting identities.
  12. Provide revocation and quarantine controls for compromised dependencies.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The trigger pattern of ".*" effectively matches every natural-language input, causing the skill to activate on ordinary speech regardless of user intent. In this skill, that is particularly risky because the skill is an orchestrator with auto-install and execution capabilities, so universal triggering can funnel unrelated requests into an overpowered control path.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The configuration explicitly directs the agent to override its system prompt and enforce planner control over all inputs. This is a serious security design issue because system-prompt and routing control are high-trust mechanisms; delegating them to a skill allows the skill to reshape agent behavior, bypass expected constraints, and monopolize decision-making.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The human-readable trigger description covers an extremely broad range of common tasks, making activation ambiguous and effectively universal in practice. This is dangerous because operators may deploy it believing it is a convenience feature, while it can end up mediating nearly all user work and altering normal execution flow.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The agent setup instructions tell operators to force all inputs through this skill with highest priority and exclusive control. In context, this is more dangerous because the skill is not a narrow validator but a broad orchestrator that can auto-install and chain external skills, making the blast radius agent-wide.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description advertises automatic matching, downloading, installation, and execution of other skills without a prominent warning or explicit consent model. That is dangerous because external skill acquisition expands the trust boundary and can introduce unreviewed code or capabilities into the agent workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The force/intercept configuration can take over all user inputs and block other skills, but the documentation does not present this as a prominent safety warning. This omission is dangerous because deployers may unknowingly enable behavior that changes the agent's trust and control model in a sweeping way.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly defines force mode with exclusive interception, pre/post hooks, and agent-level system prompt override, which exceeds a normal task-planning role and creates a control-plane takeover risk. In skill context, this is more dangerous because the planner also auto-discovers and can auto-install external skills, so a global intercepting orchestrator can silently redirect or block all user requests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The embedded agent setup instructs operators to place this skill first, make it the default skill, enable exclusive mode, and route all user input through it. That turns the skill into a mandatory global gatekeeper, which is dangerous because it centralizes authority over all user interactions and can suppress other safeguards or tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The sample agent system prompt is written to force all user inputs through the skill and is provided only in Chinese, while the file otherwise claims multilingual support. In context, this steers agent behavior toward a fixed locale without offering an explicit user opt-in or language-selection mechanism in the policy text.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation claims transparent pre-execution disclosure, but elsewhere the skill is configured to reject or stop execution flows through mandatory interception and planning enforcement. This mismatch is dangerous because operators and users may believe the skill is merely advisory, while it can actually block normal execution paths or force routing decisions without meaningful user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.