Back to skill

Security audit

Brain Proactive

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for vault maintenance, but it needs review because it can broadly inspect private notes and contains unsafe shell-search and web-enrichment instructions.

Install only if you are comfortable with the skill reading broad areas of your Obsidian vault, including health and therapy metadata. Use explicit review commands, require confirmation before enrichment or vault-push, and fix the keyword search instruction to avoid shell interpolation before relying on it with untrusted note names or topics.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:84
Finding

Potential Shell Command Injection Through Unsanitized Search Keyword

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 84–90
Vulnerability Type: Shell command injection caused by unsafe interpolation of user-derived input
Risk Level: High

Vulnerable Code

markdown
Trigger: "find connections for [note]", "what connects to [topic]", "link suggestions for [note]"

1. Read the target note
2. Extract key themes, names, entities
3. Search vault for related notes:
```bash
grep -r "[keyword]" /home/node/.openclaw/workspace/Files/HumanVault/ --include="*.md" -l 2>/dev/null | head -20
text

### Technical Analysis

The skill instructs the agent to derive keywords from a user-selected note or topic and insert them into a shell command. The placeholder `[keyword]` appears inside a double-quoted shell argument, but the instructions do not require shell-safe argument handling, validation, or escaping.

If an implementation performs direct textual substitution, a crafted keyword containing a double quote can terminate the intended argument. Shell metacharacters can then introduce an additional command. Merely surrounding interpolated input with double quotes is insufficient when the input itself may contain quote characters and is used to construct shell source.

The vulnerability depends on the agent or runtime implementing the documented placeholder through direct shell-string interpolation. A process-execution API that passes the keyword as a distinct argument would prevent this exploitation path.

### Attack Path

1. An attacker invokes the connection-finder workflow with a crafted note name, topic, or keyword.
2. The agent extracts or accepts attacker-controlled text as `[keyword]`.
3. The agent directly substitutes that value into the documented `grep -r "[keyword]" ...` command.
4. A quote in the supplied value terminates the intended `grep` argument.
5. Injected shell syntax causes an additional command to be parsed and executed.
6. The injected command runs w
...[truncated 1192 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not build shell source by interpolating user-controlled or model-derived text.

  2. Use a process-execution API that accepts the executable and arguments separately, passing the keyword as one literal argument to grep.

  3. Use fixed-string matching with grep -F when regular-expression behavior is unnecessary.

  4. Add -- before the keyword so values beginning with a hyphen cannot be interpreted as options.

  5. If a shell wrapper is unavoidable, pass the keyword as a positional parameter rather than embedding it in the command text:

    bash
    sh -c 'grep -r -F -l --include="*.md" -- "$1" /home/node/.openclaw/workspace/Files/HumanVault/ 2>/dev/null | head -20' sh "$keyword"
    
  6. Validate the target path against the expected HumanVault root and reject attempts to select files outside that directory.

  7. Update the skill instructions to explicitly prohibit direct substitution into shell commands and require structured argument passing for every user-derived value.

  8. Run the skill under a least-privileged account with read-only HumanVault access for review and connection-finder operations.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad natural-language phrases like 'check my notes' and 'what needs attention' that could match ordinary conversation and invoke the skill unintentionally. Because the skill performs broad vault inspection, accidental activation can cause unnecessary access to sensitive local data and unexpected autonomous review behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
---

Active second-brain caretaking. Read vault, surface what needs attention, suggest what to connect or enrich. Never write to HumanVault without approval — use vault-push.

---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The 'FULL VAULT REVIEW' section uses ambiguous activation phrases without guardrails, which can cause broad scans to run in contexts where the user did not intend a full audit. Given the sensitive nature of personal vault content, accidental invocation raises privacy and overreach risks.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Check 2 — Pending Staged Files

bash
ls -la /home/node/.openclaw/workspace/Files/Books/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Receipts/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Medications/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Species/ 2>/dev/null

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

Check 2 — Pending Staged Files

bash
ls -la /home/node/.openclaw/workspace/Files/Books/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Receipts/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Medications/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Species/ 2>/dev/null

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Check 2 — Pending Staged Files

bash
ls -la /home/node/.openclaw/workspace/Files/Books/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Receipts/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Medications/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Species/ 2>/dev/null

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

Check 2 — Pending Staged Files

bash
ls -la /home/node/.openclaw/workspace/Files/Books/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Receipts/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Medications/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Species/ 2>/dev/null

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

Check 2 — Pending Staged Files

bash
ls -la /home/node/.openclaw/workspace/Files/Books/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Receipts/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Medications/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Species/ 2>/dev/null

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

Check 2 — Pending Staged Files

bash
ls -la /home/node/.openclaw/workspace/Files/Books/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Receipts/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Medications/ 2>/dev/null
ls -la /home/node/.openclaw/workspace/Files/Species/ 2>/dev/null

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s documented NOTE ENRICHMENT workflow expands from local vault review into external web search and content augmentation, which is outside the declared maintenance/review scope. This introduces unnecessary external data flow and broadens the trust boundary, increasing the chance of privacy leakage, prompt-injection via web content, or unapproved synthesis being staged into the user’s vault.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Web search is not necessary for reviewing local Obsidian vault hygiene, so granting or encouraging it violates least privilege. Unneeded external access can expose note-derived queries, pull in malicious or low-quality content, and create a path for indirect data exfiltration or contamination of staged notes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.