Back to skill

Security audit

WorkboardSkill

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Chinese-language skill for using OpenClaw Workboard, with its state changes and worker dispatch behavior disclosed and scoped to that tool.

Installers should be comfortable with Chinese documentation. Installing the skill itself does not run code, but following its instructions may enable/restart the Workboard plugin, write local Workboard SQLite state, and dispatch local Gateway worker runs, so use it only with an OpenClaw profile where you are comfortable granting operator.write access.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
The natural-language content of the skill is entirely in Chinese, including the description and operational instructions, with no indication that users may choose another language. This can violate a language/locale policy when the organization expects skills to avoid forcing a specific language unless explicitly documented or user-selected.

Static analysis

No suspicious patterns detected.