Back to skill

Security audit

Personal Plans

Security checks for vulnerabilities and agentic risk

Overview

This is a simple personal planner, but it needs review because it broadly activates while reading and editing a persistent personal plans file and its install source is not well verified.

Install only if you trust the publisher and obtain the package from a verified source. Before using it, narrow the activation terms if possible, confirm where the plans file lives, and treat delete or completion commands carefully because the skill can persistently change your local planning data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:27
Finding

Unverified External Installation Source

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

md
| Show tasks | `что у меня на сегодня?` |
| Weekly plan | `план на эту неделю` |
| Show overdue | `что просрочено?` |
| Show instructions | `инструкция` |

## Installation

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation description includes very broad everyday terms like 'do', 'finish', 'complete', and 'planning', which can cause the skill to trigger in many unrelated conversations. In a personal-planning skill that reads and updates a personal memory file, over-triggering increases the chance of unnecessary access to private data and unintended modification of stored plans.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises task deletion without warning whether the action is destructive, logged, or reversible. For a planning assistant handling reminders and deadlines, accidental or ambiguous deletion can lead to loss of important personal planning data and missed obligations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README documents activation through broad natural-language examples but does not clearly define when the skill should or should not trigger. In a personal planning assistant, this can cause overbroad activation, misclassification of ordinary conversation as task-management commands, and unintended modification or disclosure of task data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

All example commands are presented in Russian, and the README does not indicate that other languages are supported or that Russian is an intentional region-specific requirement. This can amount to a language-policy issue because the skill appears to require a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language instructions and role text are written entirely in Russian, and the tone guidance does not offer any language choice or user opt-in. This can violate language or locale policy when the user has not explicitly requested Russian or a Russian-only experience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to update /data/.openclaw/workspace/knowledge/personal/plans.md whenever the user adds or completes a task, but it provides no notice, consent flow, or confirmation that persistent personal data will be modified. This can lead to silent storage changes, accidental overwrites, and privacy surprises, especially if the skill is triggered broadly.

Content

No source excerpt is available for this finding.