Back to skill

Security audit

Intervention Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent collaboration-memory skill, but users should know it may save preference and correction history persistently.

Install only if you are comfortable with the agent remembering collaboration preferences, corrections, and friction patterns across sessions. Avoid putting sensitive personal, business, or credential details into correction examples unless you understand where your OpenClaw memory is stored and how to delete it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README states that the skill 'automatically learns user preferences' but does not clearly warn users that this may create persistent records derived from their interactions. In an AI assistant context, preference memory can capture sensitive behavioral, workflow, or potentially personal data, so lack of explicit disclosure creates privacy and consent risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'Memory Sync' feature explicitly says learnings are saved to persistent storage, but the README does not explain what information is stored, where it is stored, or the privacy implications. Because the skill is designed to record corrections and friction points over time, persistent storage could accumulate sensitive user data without informed consent or clear retention controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly describes saving collaboration preferences, correction history, and friction patterns via a memory tool, but it does not clearly warn users that this data may be persistently stored or explain retention/consent boundaries. This creates a privacy and trust risk because users may disclose behavioral preferences or interaction history without realizing it will be remembered beyond the current session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The prominent tagline is written in Chinese, which may imply a language preference or locale assumption, but the file does not state whether multilingual use is supported or whether Chinese is intentional for a region-specific audience. Under the language/locale policy, forcing or implying a specific language without user opt-in can be problematic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and operating instructions are written exclusively in Chinese, which can amount to a language policy violation when no language selection or user opt-in is provided. There is no indication that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.