Back to skill

Security audit

基于艾宾浩斯遗忘曲线的英语六级词汇记忆系统

Security checks for vulnerabilities and agentic risk

Overview

This is a vocabulary study skill, but its reminder setup can create persistent cron jobs and send automated messages without enough confirmation, cleanup guidance, or script provenance.

Install only if you want local progress tracking and scheduled reminders. Before enabling reminders, confirm the exact cron entries, the script they run, the OpenClaw account and recipient target, and how to remove the cron job and delete the CSV schedule/progress files later. Static scan was clean and VirusTotal was pending, so this Review verdict is based on the artifact’s own persistence and messaging instructions, not malware telemetry.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to persist user schedule data to a CSV file and create timed tasks, but it does not require clear user notice, consent confirmation, or disclosure that data and reminders will persist beyond the current session. This can lead to unexpected retention of personal routine data and unintended system-side changes, which is a real security/privacy issue even though the skill’s educational purpose appears benign.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document instructs the agent to write persistent schedule data and install crontab entries without explicitly requiring informed user consent or warning about system-level persistence. This is dangerous because it allows the skill to make lasting changes to the host environment that may continue running after the session, surprising users and expanding the skill's operational footprint.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The reminder script sends messages to a target account using a local messaging tool, but the skill description does not mention that automated outbound messages will be sent or how the recipient identity is selected and protected. This creates privacy and misuse risk because the skill could message the wrong account, send repeated unsolicited notifications, or expose user identifiers through automation.

Static analysis

No suspicious patterns detected.