T08 · Insecure Dependencies
- Location
README.md:27- Finding
Unverified External Installation Source
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple personal planner, but it needs review because it broadly activates while reading and editing a persistent personal plans file and its install source is not well verified.
Install only if you trust the publisher and obtain the package from a verified source. Before using it, narrow the activation terms if possible, confirm where the plans file lives, and treat delete or completion commands carefully because the skill can persistently change your local planning data.
README.md:27Unverified External Installation Source
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
| Show tasks | `что у меня на сегодня?` |
| Weekly plan | `план на эту неделю` |
| Show overdue | `что просрочено?` |
| Show instructions | `инструкция` |
## Installation
The activation description includes very broad everyday terms like 'do', 'finish', 'complete', and 'planning', which can cause the skill to trigger in many unrelated conversations. In a personal-planning skill that reads and updates a personal memory file, over-triggering increases the chance of unnecessary access to private data and unintended modification of stored plans.
The skill advertises task deletion without warning whether the action is destructive, logged, or reversible. For a planning assistant handling reminders and deadlines, accidental or ambiguous deletion can lead to loss of important personal planning data and missed obligations.
The README documents activation through broad natural-language examples but does not clearly define when the skill should or should not trigger. In a personal planning assistant, this can cause overbroad activation, misclassification of ordinary conversation as task-management commands, and unintended modification or disclosure of task data.
All example commands are presented in Russian, and the README does not indicate that other languages are supported or that Russian is an intentional region-specific requirement. This can amount to a language-policy issue because the skill appears to require a specific language without user opt-in.
The natural-language instructions and role text are written entirely in Russian, and the tone guidance does not offer any language choice or user opt-in. This can violate language or locale policy when the user has not explicitly requested Russian or a Russian-only experience.
The skill instructs the agent to update /data/.openclaw/workspace/knowledge/personal/plans.md whenever the user adds or completes a task, but it provides no notice, consent flow, or confirmation that persistent personal data will be modified. This can lead to silent storage changes, accidental overwrites, and privacy surprises, especially if the skill is triggered broadly.