Back to skill

Security audit

Aloudata CAN SKILLS - scheduled-report

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for scheduled reports, but it creates persistent agent tasks from conversation-derived content using unsafe shell and temporary-file patterns.

Review before installing. Use it only for analyses whose parameters and conclusions are safe to store in a scheduled task, require explicit confirmation of the exact stored prompt, and avoid executing the provided shell snippets unless OpenClaw supports safe argument-array or structured task creation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:260
Finding

Shell Command Injection Through Conversation-Controlled Task Parameters

Content
View full analysis
" --cron "" --agent-turn "" ``` ```bash # Write the prompt to a file first cat > /tmp/task_prompt.txt << 'PROMPT_EOF' {完整 prompt 内容} PROMPT_EOF # Then create the task openclaw cron add --name "销售业绩周报" --cron "0 9 * * 1" --agent-turn "$(cat /tmp/task_prompt.txt)" ``` ### Technical Analysis The Skill directs the Agent to interpolate a task name, cron expression, and generated prompt into shell source. These values are derived wholly or partly from conversation-controlled content. The instructions do not require strict validation, shell-safe encoding, or execution through an argument-array API. If the Agent generates the displayed command by substituting values directly into its text, embedded quotation marks, heredoc terminators, newlines, or shell operators may alter the intended command structure. The heredoc approach remains susceptible to generated content containing a line exactly equal to `PROMPT_EOF`, which terminates the heredoc early. Subsequent attacker-controlled lines can then be interpreted as shell commands. The warning elsewhere in the Skill that prompts may contain special characters does not provide a reliable security control. Moving content into a heredoc only changes the injection boundary; it does not make arbitrary generated content safe when a fixed delimiter is used. ### Attack Path 1. An attacker supplies analysis text, a report name, or another parameter containing shell syntax. 2. The Skill records that content and incorporates it into the scheduled-task configuration or prompt. 3. The Agent emits and executes the documented shell command. 4. The malicious value breaks out of its quoted argument, or a line matching `PROMPT_EOF` closes the heredoc. 5. Remaining attacker-controlled text is parsed by the shel ...[truncated 991 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:260
Finding

Predictable Temporary File Permits Symlink-Based File Overwrite or Prompt Substitution

Content
View full analysis
/tmp/task_prompt.txt << 'PROMPT_EOF' {完整 prompt 内容} PROMPT_EOF # Then create the task openclaw cron add --name "销售业绩周报" --cron "0 9 * * 1" --agent-turn "$(cat /tmp/task_prompt.txt)" ``` ### Technical Analysis The Skill uses the fixed path `/tmp/task_prompt.txt` without exclusive creation, ownership verification, restrictive permissions, or cleanup. Temporary directories are commonly shared among local users and processes. Because ordinary shell redirection follows symbolic links, a local attacker may create `/tmp/task_prompt.txt` as a symbolic link to another file before the Skill runs. The documented `cat >` operation may then truncate and overwrite that target if the Agent account has permission to write it. The fixed filename also permits race conditions and cross-task interference. Another process can replace or modify the file between the write and the subsequent `cat`, causing attacker-selected prompt content to be registered as a scheduled Agent task. Default file permissions may additionally expose the prompt to other local users, depending on the process umask and host configuration. ### Attack Path 1. A local attacker predicts the fixed path `/tmp/task_prompt.txt`. 2. Before task creation, the attacker creates that path as a symbolic link to a file writable by the Agent account, or repeatedly replaces the path during execution. 3. The Agent executes `cat > /tmp/task_prompt.txt`. 4. Shell redirection follows the symbolic link and overwrites the linked target. 5. Alternatively, the attacker replaces or edits the temporary file after it is written but before `$(cat /tmp/task_prompt.txt)` reads it. 6. `openclaw cron add` receives attacker-controlled prompt content and creates a persistent scheduled task from it. ### Impac ...[truncated 570 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and all user-facing guidance are written as mandatory Chinese instructions, beginning with '将当前对话中已完成的分析流程...'. There is no indication that the user may choose another language or that the locale restriction is region-specific, which can violate language/locale policy for broadly applicable skills.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest states as a prerequisite that the user must first complete an analysis in the conversation, and that if no analysis history exists the user should be guided to complete analysis before triggering this skill. Later instructions broaden the skill's behavior: when there is no analysis history, the skill should trigger, remember the scheduled intent, guide metric discovery, invoke analysis skills, run a full analysis, and then automatically continue into task creation. That goes beyond merely extracting and solidifying an already completed workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The '定位' section explicitly says the skill is only a faithful recorder/replayer and 'does not' define analysis logic itself. However, the later boundary-case workflow instructs the skill to intervene immediately, retain user intent, guide the user to determine what to monitor and what counts as abnormal, search for relevant metrics, and drive a complete analysis round before auto-creating the task. This is an active contradiction in the skill's own documentation about what role it plays.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to faithfully extract and preserve prior analysis steps, parameters, filters, conclusions, and user judgments from the full conversation, then reuse them in a future scheduled prompt. That can capture secrets, sensitive business logic, personal data, identifiers, or one-off investigative context and persist them into long-lived automation, increasing risk of later disclosure to operators, logs, downstream tools, or future task outputs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt-assembly step explicitly creates a self-contained future prompt embedding all conversation-derived instructions and query parameters so it can run independently later. In a scheduling context this is more dangerous because the embedded prompt becomes durable state that may be logged, inspected, exported, or executed repeatedly, turning transient sensitive context into persistent and repeatedly exposed data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.