Back to skill

Security audit

Looking for Someone

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate local missing-person case tool, but it stores highly sensitive case records in plaintext without strong local file protections or working deletion controls.

Review before installing if you may enter real missing-person details. The tool appears local and purpose-aligned, but it keeps sensitive records in plaintext and does not enforce private file permissions or provide the deletion controls its documentation describes. Avoid storing ID numbers, exact addresses, family contact details, financial information, or sensitive medical details unless you have a separate secure handling plan; treat China-specific emergency and platform guidance as jurisdiction-specific rather than universal.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cli.js:15
Finding

Plaintext Sensitive Case Records Stored Without Explicitly Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/cli.js, lines 15–25 and 44–53
Vulnerability Type: Plaintext sensitive-data storage with unsafe reliance on inherited filesystem permissions
Risk Level: Medium

Vulnerable Code

js
const DATA_DIR = path.join(process.env.HOME || process.env.USERPROFILE, '.openclaw', 'skills-data', 'looking-for-someone');
const CASES_FILE = path.join(DATA_DIR, 'cases.json');

// Ensure data directory exists
if (!fs.existsSync(DATA_DIR)) {
  fs.mkdirSync(DATA_DIR, { recursive: true });
}

// Initialize cases file if it doesn't exist
if (!fs.existsSync(CASES_FILE)) {
  fs.writeFileSync(CASES_FILE, JSON.stringify([], null, 2));
}

// Save cases
function saveCases(cases) {
  try {
    fs.writeFileSync(CASES_FILE, JSON.stringify(cases, null, 2));
    return true;
  } catch (error) {
    console.error('Error saving cases:', error.message);
    return false;
  }
}

Technical Analysis

The application handles sensitive missing-person information, including names, dates of birth, phone numbers, identification numbers, family contacts, locations, distinguishing features, circumstances, and investigative clues. All case records are serialized directly into a single unencrypted JSON file.

The data directory and file are created without explicit modes. Consequently, their effective permissions depend on the process umask and the permissions of parent directories. A permissive or misconfigured environment may create a file that other local users can read. The implementation neither verifies ownership and permissions of an existing file nor rejects symbolic links at the expected data path.

Although the documentation acknowledges that encryption is not implemented, disclosure does not mitigate the confidentiality risk. The particularly sensitive nature of missing-person records warrants restrictive permissions independent of the ambient umask.

Attack Path

  1. A user invokes the create or clue command and suppl ...[truncated 1280 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create the private data directory with owner-only permissions:
js
fs.mkdirSync(DATA_DIR, {
  recursive: true,
  mode: 0o700
});
fs.chmodSync(DATA_DIR, 0o700);
  1. Create and maintain the case file with mode 0600:
js
fs.writeFileSync(CASES_FILE, JSON.stringify([], null, 2), {
  encoding: 'utf8',
  mode: 0o600,
  flag: 'wx'
});

For later writes, verify ownership and file type first, write to an owner-only temporary file in the same directory, flush it, and atomically rename it over the destination. Reapply mode 0600 after replacement.

  1. Use lstat and platform-appropriate secure-open flags to reject symbolic links and non-regular files. Verify that the directory and existing case file are owned by the current user before reading or writing.

  2. Add schema-based data minimization. Do not persist unknown fields, and warn users before storing high-risk fields such as identification numbers, exact addresses, medical details, or financial information.

  3. Consider authenticated encryption for especially sensitive fields or the complete case database. Keep encryption keys outside the data file and use an operating-system credential store where available.

  4. Add automated tests that run under permissive umask settings and verify that the directory remains 0700 and the case file remains 0600.

  5. Provide implemented deletion, retention, and export controls so sensitive records can be removed when no longer required.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (17)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
node scripts/cli.js create '<case JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
node scripts/cli.js create '<case JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
node scripts/cli.js create '<case JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
node scripts/cli.js create '<case JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
node scripts/cli.js create '<case JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
node scripts/cli.js create '<case JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
node scripts/cli.js create '<case JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
node scripts/cli.js create '<case JSON>'

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though static analysis detected capabilities related to environment access and networking. In an agent setting, undocumented access can lead to over-privileged execution, unexpected data exposure from local case files or environment variables, and possible outbound transmission of sensitive missing-person information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guidance specifies China-specific platforms and emergency instructions such as WeChat, Weibo, Douyin, and 'dial 110 in China' without clearly stating that the skill is limited to China or offering alternative locale handling. This can violate language/locale policy because it implicitly forces a regional context on all users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The document states data should be used only for missing person case management and not repurposed for other uses. Later sections instruct users on posting case details to public and semi-public social media platforms, which is a materially different disclosure context than local case management and weakens the stated limitation. This is an intent-level contradiction within the documentation itself.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document forbids public disclosure of exact coordinates, but platform guidance to use location tags can prompt users to reveal overly precise last-seen locations. In a missing-person context, that can expose sensitive movement patterns, homes, shelters, or search activity to malicious actors, stalkers, or scammers.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/privacy-and-boundaries.md (reported line 57)May include surrounding context.

md
- Identification numbers
- Financial information
- Sensitive medical conditions
- Family contact details (without consent)
- Exact coordinates of last seen location

#### Conditional Disclosure:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Hard-coding China-specific platforms and PRC legal compliance without clearly limiting the skill to China can mislead users in other jurisdictions into following inappropriate disclosure practices or assuming incorrect legal compliance. In a privacy-sensitive missing-person workflow, that confusion can result in unlawful or unsafe data sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code forces all displayed dates to use the 'en-US' locale via toLocaleDateString('en-US'). This is a natural-language/locale policy concern because the skill does not offer users any language or locale choice, despite also containing China-specific guidance and Chinese-language notice formats.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill presents emergency instructions and contact numbers specifically for China, including 'dial 110 in China' and other China-only emergency numbers, without asking the user for region or clarifying that the guidance is jurisdiction-specific. This forces a locale-specific operational context on all users rather than offering a choice or documenting a justified regional limitation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/cli.js (reported line 331)May include surrounding context.

js
console.log('3. Requests for ID cards, bank cards, or verification codes');
    console.log('4. Claims of being police without verifiable identification');
    console.log('5. Requests to download unknown apps or enable screen sharing');
    console.log('6. Pressure to act quickly without verification\n');
    
    console.log('✅ Safe Practices:');
    console.log('• Verify all information through official channels');

Static analysis

No suspicious patterns detected.