Back to skill

Security audit

Pacer Skill

Security checks for vulnerabilities and agentic risk

Overview

Pacer fits its career-coaching purpose, but it broadly persists sensitive CV, career, financial, and progress data and renders that data through unsafe HTML chart templates, so it needs review before installation.

Install only if you are comfortable with Pacer storing career profile details, CV summaries, financial runway, professional network information, motivations, and progress records in local OpenClaw memory. Redact unnecessary CV contact details before use, avoid sharing exact financial or sensitive personal facts unless needed, and treat generated chart HTML as requiring sandboxing and proper escaping before rendering.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
charts/map-compare.html:277
Finding

Persistent Cross-Site Scripting Through Unsanitized Chart Template Values

Content
View full analysis
{ const item = document.createElement('div'); item.className = 'direction-item'; item.innerHTML = `${d.name}:${d.reason} · 第一步:${d.step}`; list.appendChild(item); }); ``` Related direct JavaScript-context substitution: ```javascript const pathName = "{{path_name}}"; const xLabels = ["现在", "1个月", "3个月", "6个月", "12个月"]; const dataPathA = {{data_path_a}}; const dataStatusQuo = {{data_status_quo}}; const milestoneIndex = {{milestone_index}}; const milestoneLabel = "{{milestone_label}}"; const turningPointIndex = {{turning_point_index}}; const hoverLabelsPathA = {{hover_labels_path_a}}; const hoverLabelsStatusQuo = {{hover_labels_status_quo}}; ``` ### Technical Analysis The chart system substitutes values derived from user conversations, uploaded CVs, and persistent memory directly into executable JavaScript. String values are placed between JavaScript quotes without conte ...[truncated 2348 chars]
Remediation
View remediation
`, then parse it after safely encoding characters that can terminate the element. 6. Apply a restrictive Content Security Policy that disallows inline scripts and event handlers. 7. Render generated charts in a sandboxed, unique-origin iframe. Do not grant `allow-same-origin`, top-navigation, form submission, pop-up, or parent-DOM permissions unless strictly required. 8. Add automated tests using payloads containing quotes, ``, template-literal syntax, HTML event handlers, and malformed arrays. ]]>

other

Warning
Location
prompts/system.md:10
Finding

Excessive Persistent Storage of Sensitive Career and Financial Information

Content
View full analysis
"你现在有多少个月的生活储备?大概说个范围就行。" 4. 🤝 **人脉资源** > "你身边哪个行业认识的人最多?" 5. 🔥 **核心动力** > "你最不能忍受的工作状态是什么?" ``` ### Technical Analysis The system prompt instructs the agent to remember everything the user says and to update a local Markdown memory file whenever new information is provided. The workflow collects CV history, education, skills, financial reserves, professional contacts, motivations, milestones, and daily or weekly activity. This retention policy is broader than required for career-progress tracking. The project does not specify explicit consent, field-level minimization, an expiration period, secure deletion, encryption, access-control requirements, or a user-facing mechanism to inspect and remove retained data. The documented Markdown storage format also indicates that sensitive profile information may remain readable as plaintext on the local filesystem. This is a privacy and local data-exposure weakness rather than evidence of remote exfiltration. No code in the reviewed project was found sending the stored information to an external service. ### Attack Path 1. A user uploads a CV or answers the Scan module's questions. 2. The skill extracts employment, edu ...[truncated 1177 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
charts/map-radar.html:7
Finding

Third-Party Chart Library Is Executed at Runtime Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis Each affected chart downloads and executes Chart.js from a third-party CDN at rendering time. The URL pins version `4.4.0`, which reduces accidental version drift, but the document does not provide a Subresource Integrity hash. Consequently, the browser trusts and executes whatever bytes are returned by the CDN URL. A compromise of the CDN, package publication channel, DNS or network delivery path, or upstream asset could replace the expected library with malicious JavaScript after the skill package has already passed review. Because every rendered chart loads this resource, the dependency forms a recurring remote code-execution channel within the browser iframe. No evidence was found that the current Chart.js asset is malicious. The vulnerability is the absence of cryptographic verification and local vendoring. ### Attack Path 1. An attacker compromises an upstream package account, CDN asset, CDN infrastructure, DNS resolution path, or another part of the dependency-delivery chain. 2. The pinned CDN URL begins serving modified JavaScript. 3. A user invokes a workflow that renders one of the affected chart templates. 4. The browser downloads the modified asset from jsDelivr. 5. The malicious JavaScript executes automatically in the chart iframe before the local chart-rendering logic runs. 6. The payload gains the browser privileges available to that iframe and may alter chart output, access same-origin data, or communicate externally if permitted by browser policy. ### ...[truncated 569 chars]
Remediation
View remediation
``` 3. Verify the integrity value against a trusted, independently obtained copy of the release. 4. Apply a restrictive Content Security Policy that permits scripts only from the required source and rejects unverified inline execution. 5. Render charts in a sandboxed, unique-origin iframe with no unnecessary access to the parent application. 6. Maintain a dependency inventory and periodically review pinned versions for known vulnerabilities. 7. Use reproducible build or checksum verification procedures when updating the vendored library. 8. Define an availability-safe failure mode: if integrity verification fails, show a static chart error instead of falling back to an unverified source. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (40)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are extremely broad and include common conversational language such as '我该怎么办', '下一步', and '不知道做什么'. In a host environment that auto-routes messages to skills based on trigger text, this can cause unintended activation on unrelated user conversations, exposing sensitive career or personal context to the skill without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt directs collection of sensitive personal and career data, including financial reserves, network contacts, motivation, and CV-derived details, and instructs storing all answers in memory without any retention notice, consent flow, or minimization. This creates privacy and data-governance risk because sensitive data may be persisted beyond the immediate interaction and later reused or exposed contrary to user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README explicitly encourages users to upload CVs, which commonly contain personal data such as names, contact details, employment history, and education, but provides no warning about privacy, retention, redaction, or safe handling. That omission can lead users to share sensitive data without informed consent or precautions, especially because CV upload is presented as a normal entry point to the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises very broad activation conditions such as generic help-seeking phrases and even direct CV upload, which can cause the skill to trigger in ordinary conversations without clear user intent. In a career-planning skill, this increases the chance that sensitive personal or employment information is routed into the skill unexpectedly, creating privacy and consent risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly encourages users to upload CVs, which commonly contain sensitive personal data such as full name, email, phone number, employment history, education, and location, but provides no warning or handling guidance. This increases the risk of unnecessary collection, oversharing, and downstream retention of personal data, especially because the metadata also indicates persistent memory use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This README states that the AI reads user data from memory and injects it into HTML templates for rendering. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect user data or privacy, and no caution or disclosure is provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document declares lang="zh", and all visible UI text is written in Chinese, which imposes a specific language/locale on users. The file does not provide any opt-in, alternative locale, or explanation that this chart is intentionally region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The page loads executable JavaScript from a third-party CDN, which creates a supply-chain and integrity risk: if the CDN response is tampered with, blocked, or replaced, arbitrary code can run in the user's browser. This is more concerning because the rest of the file injects template variables directly into script/HTML, so any compromised external script would execute in a page handling user-derived content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The page declares lang="zh" and all visible UI text is hard-coded in Chinese, which imposes a specific language on users with no opt-in or alternative locale handling. This matches the policy category for language or locale constraints that are not user-selectable or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file declares lang="zh" and all visible UI text is Chinese, which imposes a specific language on users without any opt-in or alternative locale path. Under the policy, locale-specific behavior should either offer user choice or be clearly documented as a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L002 sets the document language to Chinese (lang="zh"), and the visible UI text throughout the file is also fixed in Chinese. This appears to impose a specific locale without opt-in or an explanation that the skill is intentionally region-specific, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example shows the skill ingesting an uploaded resume and then requesting additional sensitive financial information ('how many months of savings') without any visible privacy notice, data-minimization rationale, or handling guidance. In a career-coaching context, this can normalize oversharing of personal and financial data and increase privacy risk if users do not understand how the information will be stored, processed, or protected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example conversation is entirely in Chinese and does not indicate any language selection step, fallback behavior, or justified locale restriction. In a general-purpose career-planning skill, forcing a single language can exclude users, cause misunderstanding of advice, and reduce safe/accurate use by users who cannot fully understand the guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is entirely written as a Chinese-only demonstration dialogue and does not offer any user language choice or explain a locale restriction. In a career-planning skill, this can exclude or mislead users who cannot read Chinese, causing usability, consent, and accessibility issues rather than a direct security compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents the full interaction and instructions only in Chinese, which can amount to forcing a specific language on users without opt-in. The policy allows locale constraints only when users are given a choice or when the restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file presents the skill example and all user-facing dialogue exclusively in Chinese, which can amount to a language/locale policy violation when no user opt-in or alternative language option is provided. The content does not indicate that the skill is region-specific or that Chinese is required for a documented reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

All headings, trigger phrases, and output templates require Chinese-language interaction, which effectively enforces a specific language. There is no indication that the user can choose another language or that the locale restriction is intentionally documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger conditions are broad and ambiguous enough that this skill could activate when the user did not clearly request path-planning behavior. In an agent setting, unintended invocation can cause context switching, confusing outputs, and downstream actions or recommendations based on incomplete user intent, which increases prompt-routing risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

All prompts, triggers, and required user-facing responses are specified in Chinese, including exact phrases the user may say and mandatory response text. There is no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The listed triggers include broad state-based conditions such as '用户第一次使用 Pacer' and 'memory 中没有用户扫描记录', which could cause the skill to activate automatically without a clear user request. The file also does not provide exclusion conditions or negative examples to clarify when scanning should not start.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatically extracting resume data and later storing it without scope limits increases privacy risk because CVs often contain highly sensitive personal information beyond the listed fields, such as contact details, dates, employers, and education history. Without explicit bounds or redaction rules, the agent may ingest and persist more data than needed for the skill's purpose.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to store all collected answers in memory causes persistence of personal data without visible scoping, minimization, or lifecycle controls. In the context of a career assistant, this may include sensitive employment, financial, and personal preference data that could be unnecessarily retained and later surfaced in unrelated contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The prompt content is entirely in Chinese and prescribes fixed Chinese output patterns without any mechanism to detect or honor the user's preferred language. This can lead to accessibility and usability failures, especially for users interacting in another language, and may cause misunderstanding in a guidance-oriented career tool.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad natural-language phrases such as '模拟一下' and 'X个月后会怎样', which can easily match ordinary conversation outside the intended workflow. This can cause the skill to activate unexpectedly and steer users into a persuasive simulation flow, creating unintended behavior and reducing user control over when this module runs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to 'remember everything' and store every user-stated fact in memory encourages indiscriminate collection of personal data without necessity boundaries. This creates a natural-language privacy and leakage risk because highly sensitive user disclosures may be retained and later surfaced, exposed, or misused beyond what is needed for the assistant's function.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.