Back to skill

Security audit

Content Pilot

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language content-generation skill with sloppy documentation and broad activation examples, but no hidden execution, persistence, destructive behavior, or exfiltration was found.

Before installing, treat this as a Chinese-language marketing/content assistant and avoid sending confidential drafts or customer data to third-party APIs unless you have verified the configured provider and data policy. The publisher should narrow the activation triggers and align metadata with the documented long-form writing feature.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill’s declared purpose and dependency list describe five content-generation functions, but the body adds a sixth long-form article-writing capability and references khazix-writer behavior that is not reflected in the metadata. This hidden scope expansion matters because users, routing systems, and reviewers may grant the skill trust or permissions based on incomplete documentation, increasing the chance of unintended activation or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation rule includes the generic trigger “相关业务需求,” which can match a wide range of ordinary user requests unrelated to this skill. Overly broad activation can cause the skill to intercept conversations unexpectedly, leading to unauthorized handling of user content, accidental data exposure to connected services, or execution of behavior outside user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples show the assistant enabling the skill for generic prompts like ‘帮我处理一下业务需求’ and ‘需要批量处理,’ normalizing ambiguous activation behavior. In practice, this can train integrators or downstream agents to invoke the skill on broad operational requests, increasing the risk of unintended scope capture and misuse of any connected APIs or external processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill states that network access, API calls, and third-party service keys may be used, but it does not disclose what user data may be transmitted, when transmission occurs, or what privacy risks result. In a content-processing skill, users may paste drafts, business plans, customer information, or unpublished announcements, so silent external transfer can create confidentiality and compliance issues.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/test.sh (reported line 3)May include surrounding context.

sh
#!/bin/bash
echo "🧪 测试 content-pilot..."
echo "  SKILL.md: ✅ $(wc -c < /root/.openclaw/workspace/skills/content-pilot/SKILL.md) bytes"
echo "    caption: ✅"
echo "    hashtag: ✅"
echo "    quote: ✅"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest includes a non-English author value ("智美人团队") with no accompanying indication of language choice or locale context. This can reflect an implicit language preference in user-visible metadata, which may conflict with a language/locale neutrality policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's user-facing echo messages are written in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy requirements when a skill imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

All user-facing messages in this shell script are hardcoded in Chinese, which imposes a specific language on users without any visible opt-in or indication that the skill is intended only for a Chinese-speaking or region-specific context. This matches the policy category for language or locale constraints that are not optional or justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.