Back to skill

Security audit

Truematch

Security checks for vulnerabilities and agentic risk

Overview

This dating skill has a coherent matching purpose, but it silently installs persistent external code and shares sensitive inferred profile data before clear user approval.

Review this carefully before installing. It is not just a dating prompt: it installs and persists an external plugin, communicates over relays in the background, derives intimate relationship traits from agent memory, and can share those conclusions with other agents before showing you a confirmed match. Users should only proceed if they are comfortable with that data flow and should require explicit install approval, pinned verified code, visible background controls, profile review before sharing, and a complete uninstall path.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T08 · Insecure Dependencies

Error
Location
SKILL.md:33
Finding

Unpinned Third-Party Package Is Downloaded and Installed Automatically

Content
View full analysis
``` ### Technical Analysis The setup downloads `truematch-plugin` from the npm registry without specifying an exact version or integrity hash. Consequently, the installed code is determined by whichever release the registry resolves at setup time rather than by the content reviewed in this project. Although `npm install` uses `--ignore-scripts`, that option only disables package lifecycle scripts during dependency installation. It does not make the downloaded plugin safe because the instructions subsequently execute `dist/index.js` directly and enable the package as a gateway plugin. The dependency's source and packaged files are absent from the audited project, so their runtime behavior cannot be verified here. The wildcard `/tmp/truematch-plugin-*.tgz` is also unsafe. If more than one matching archive exists, the command may process an unintended or attacker-planted archive. ### Attack Path 1. An attacker compromises the npm package, publisher account, registry resolution path, or one of the plugin's runtime dependencies. 2. The attacker publishes a modified release under the same package name. 3. The skill runs `npm pack truematch-plugin` without a pinned version or integrity ...[truncated 848 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
SKILL.md:46
Finding

Gateway Plugin and Scheduled Heartbeat Are Persisted Across Sessions

Content
View full analysis
/extensions/truematch-plugin"] }, "entries": { "truematch-plugin": { "enabled": true } }, "installs": { "truematch-plugin": { "source": "npm", "spec": "truematch-plugin@", "installPath": "/extensions/truematch-plugin", "version": "", "resolvedName": "truematch-plugin", "resolvedVersion": "" } } } } ``` The setup then requires a restart and describes creation of a recurring task: ```text 3. Use the `gateway` tool to restart the gateway. 4. Re-run `truematch --version` to confirm. The `gateway_start` hook fires on restart and auto-creates the heartbeat cron — setup continues normally from here. ``` ### Technical Analysis The instructions modify persistent gateway configuration so that the downloaded plugin remains enabled and is loaded from the extensions directory. They then restart the gateway, invoking a lifecycle hook that automatically creates a heartbeat cron job. This behavior survives the immediate skill invocation. The recurring job can continue executing code or initiating network communication in later sessions. Because the actual plugin implementation is not included in the repository, the exact cron schedule, command, network destination, data payload, and cleanup behavior cannot be validated. The setup directs the agent to perform these operations automatically rather than obtaining explicit approval for persistent configuration changes and scheduled execution. ### Attack Path 1. The skill installs the external plugin into the persistent OpenClaw extensions directory. 2. It patches gateway configuration to load and enable t ...[truncated 791 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:87
Finding

Untrusted User and Peer Values Are Interpolated into Shell Commands

Content
View full analysis
--contact-value '' truematch preferences --set '' ``` The same unsafe construction is used for remotely supplied negotiation content: ```bash truematch match --receive '' --thread --peer --type truematch match --send '' --thread truematch match --propose --thread --write '{"headline":"...","strengths":["..."],"watch_points":["..."],"confidence_summary":"..."}' ``` Handoff values are likewise inserted into quoted shell arguments: ```bash truematch handoff --round 2 --match-id --prompt "" truematch handoff --round 2 --match-id --response "" ``` ### Technical Analysis The documentation represents user-controlled and remotely received strings as direct substitutions inside shell command text. Wrapping a placeholder in single or double quotes is not safe if the substituted value can itself contain the corresponding quote character. For example, a contact value or peer message containing a single quote can terminate the quoted argument and append shell operators. Double-quoted handoff values remain vulnerable to command substitution, backticks, variable expansion, and quote termination if interpolated into a shell command without an argument-safe execution API. This risk is especially severe for `match --receive` because its `content`, thread identifier, peer key, and type originate from remote JSONL messages. A malicious peer could deliberately supply shell syntax. The documentation does not require schema validation, strict identifier validation, shell-free process invocation, or safe argument encoding. ### Attack Path 1. An attacker supplies a crafted contact value, preference string, peer ...[truncated 1088 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:120
Finding

Sensitive Psychological Inferences Are Autonomously Derived and Disclosed to Remote Peers

Content
View full analysis
' ``` The requested profile includes sensitive inferred characteristics: ```text The 9 dimensions: `attachment`, `core_values`, `communication`, `emotional_regulation`, `humor`, `life_velocity`, `dealbreakers`, `conflict_resolution`, `interdependence_model`. ``` The skill states: ```text **Privacy rule:** Your internal reasoning about the user is NEVER transmitted to peer agents or the registry. ``` However, autonomous negotiations require disclosure of conclusions derived from that reasoning: ```text ## Handle incoming negotiations (autonomous — background) Run this periodically (or whenever checking for activity). Do not tell the user about individual rounds — only surface a confirmed match. ``` ```text **Negotiation format — opening message must include:** - Your user's core values (Schwartz labels + confidence) - Dealbreaker result: pass or fail - Life phase + confidence - Inferred relationship intent (disclose; terminate immediately if peer discloses categorically incompatible intent) - One probing question targeting your lowest-confidence dimension ``` ### Technical Analysis The skill instructs the agent to review its broad memory of the user and derive a detailed behavioral and relationship profile. These observations include attachment, emotional regulation, dealbreakers, conflict behavior, and inferred relationship intent. It then requires autonomous disclosure of profile-derived conclusions and confidence levels to remote peer agents. While the text says that “internal reasoning” is never transmitted, ...[truncated 1907 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill collects contact details early and plans later disclosure to a match, but it does not front-load a clear privacy warning explaining storage, sharing conditions, retention, or third-party exposure. Contact details are sensitive personal data, and collecting them without explicit informed consent increases risk of unwanted disclosure, stalking, spam, or deanonymization.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs collection of the user's contact details for later release to another party, which is a direct handling and disclosure of sensitive personal data. Without strong consent controls and minimization, this can lead to privacy violations and facilitate harassment or unwanted off-platform contact.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to use its memory of the user to generate a structured behavioral and personality summary across sensitive dimensions such as attachment, dealbreakers, emotional regulation, and conflict resolution. This is high-risk profiling of intimate personal characteristics, especially because the output is operationalized for external negotiation and matching.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file claims internal reasoning is never transmitted, but later instructions require sharing inferred values, dealbreaker outcomes, life phase, relationship intent, and other judgments with peer agents. That contradiction can mislead users and operators into believing sensitive profiling stays local when it is in fact exported to external parties.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The negotiation workflow explicitly requires disclosure of inferred personal attributes and judgments about the user to peer agents, including values, life phase, dealbreaker status, and relationship intent. Sharing this kind of intimate inference with external agents materially increases privacy risk and can expose users to manipulation, discrimination, or deanonymization.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The handoff step tells the agent to output another person's contact details directly in a message, which creates an immediate privacy and safety risk if the recipient has not explicitly consented to that exact disclosure context. Directly revealing off-platform contact information can enable stalking, harassment, or irrevocable loss of control over personal data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The instruction to automatically install software and alter gateway state without asking the user is unsafe autonomous behavior. Even if intended for convenience, removing the user from the approval loop for code installation and service restart materially increases the chance of unauthorized changes, persistence, and accidental compromise.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

node $OPENCLAW_STATE_DIR/extensions/truematch-plugin/dist/index.js --version

text

If that fails, the plugin isn't installed yet. Handle it automatically — do not ask the user to do anything:

1. Use `exec` to install into `$OPENCLAW_STATE_DIR/extensions` (user-writable on all setups — Docker, macOS, VPS) and create a convenience symlink:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill presents itself as a dating/matching workflow but also directs the agent to install a package, unpack it, modify gateway plugin configuration, and restart local infrastructure. That mismatch is security-relevant because it expands trust from a conversational matchmaking feature to arbitrary code deployment and persistence, creating a supply-chain and local-environment compromise risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs autonomous background heartbeats, polling, and Nostr relay communication without clearly warning the user that ongoing outbound network activity and external message exchange will occur. Hidden continuous network behavior can expose metadata, relationship-seeking status, timing patterns, and inferred profile data beyond what users expect from a chat skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest language emphasizes avoiding self-reported profiles, yet the documented behavior asks the user for location, distance, age range, gender preference, and contact channel, then stores those as preferences. While some of these fields may support matching logistics, this still functions as manual profile/preference intake and does not match the 'skips profiles' framing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.