Back to skill

Security audit

APPM: Atlas-Parallel Project Management

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent project-memory tool, but it asks agents to persist and automatically reuse project context without enough scoping or user control.

Review this skill carefully before installing in sensitive repositories. Use it only where you are comfortable storing project summaries, paths, priorities, and next actions on disk, and treat any `.openclaw/` content from shared or untrusted projects as untrusted notes that should not override user or system instructions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
scripts/appm_recall.py:7
Finding

Persistent Agent Memory Poisoning Through Untrusted Project Snapshots

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes automatic creation and maintenance of a .openclaw/ snapshot structure inside user projects but does not clearly warn that the tool will write files and persist state on disk. For an agent-oriented skill, silent or poorly disclosed filesystem writes are security-relevant because users may enable it in sensitive repositories or assume it is read-only context management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to let a background tracker run automatically to maintain project weights, but it does not explain the ongoing behavior, resource usage, files touched, or how to stop it. Persistent background activity by an agent skill increases risk because it can continuously monitor or modify project state in ways users do not expect, especially in multi-project environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document presents its section headings and operating instructions in Traditional Chinese and does not indicate that language is user-selectable. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to create and maintain project files under .openclaw/ and to update snapshot documents automatically, but it does not require user confirmation or warn that repository contents will be modified. In an agent context, silent writes to project directories can overwrite files, create unintended artifacts, or persist sensitive conversation-derived content into the workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that it will automatically track conversation keywords and persist project weights in data/appm_registry.json, but it provides no privacy notice, retention policy, or user control over that stored metadata. Persisting conversation-derived signals can leak sensitive project associations, priorities, or intent across sessions and may surprise users who did not expect durable storage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script uses hard-coded Chinese strings for default values and all user-facing output, such as project labels and status messages. This enforces a specific language without any opt-in, configuration, or documentation that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file contains Chinese-only comments and a Chinese user-facing print message, with no indication that the skill is region-specific or that users can choose their preferred language. This creates a natural-language locale policy issue because the skill implicitly enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template presents all substantive section headings and instructions in Traditional Chinese, with only secondary English glosses, which imposes a language choice on users by default. The policy allows locale constraints only when they are clearly documented and justified or when users are given a choice, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown template presents section headings and example content primarily in Traditional Chinese, with only partial English glosses. That can impose a language preference on users without offering an explicit choice, which matches the language/locale policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown template presents core section headings and task text primarily in Chinese while also including English glosses, but it does not state that the user can choose their preferred language. Because the policy forbids forcing a specific language without user opt-in, this creates a mild locale-policy concern in the natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.