Back to skill

Security audit

跨境标题生成器

Security checks for vulnerabilities and agentic risk

Overview

This title-generation skill is simple and non-executable, but it asks to read shared agent memory and save generation history without clear limits or user control.

Review before installing if your memory directory may contain unrelated private notes or business data. Prefer a version that reads only a dedicated preference file and saves history only with clear opt-in, retention, and deletion controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:58
Finding

Overbroad Access to Shared Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 58–60
Vulnerability Type: Excessive access to shared agent memory
Risk Level: Medium

markdown
- 使用 OpenClaw 原生能力(无需第三方 API)
- 读取 memory/ 目录中用户偏好设置
- 记录生成历史到 memory/cross-border-history.md

The cited instructions state that the Skill uses native OpenClaw capabilities without third-party APIs, reads user preferences from the memory/ directory, and records generation history in memory/cross-border-history.md.

Technical Analysis

The Skill requests directory-wide access to memory/ rather than identifying a dedicated preference file owned by the Skill. A shared memory directory may contain unrelated user information or state created by other Skills. Reading it broadly violates the principle of least privilege because product-title generation only requires narrowly scoped preferences.

The Skill also persists generation history without defining user consent, permitted fields, retention limits, deletion behavior, or isolation from other Skills. The destination file is specified, so the write scope is narrower than the read scope; however, requests and generated titles may still contain product, business, or user information that persists across sessions.

No evidence indicates external transmission, executable payloads, shell execution, credential theft, or malicious rules being written into memory. The issue is therefore excessive local memory access and insufficiently controlled persistence, not confirmed exfiltration or memory poisoning.

Attack Path

  1. A user invokes the title-generation Skill.
  2. The agent follows the instruction to inspect the shared memory/ directory for user preferences.
  3. Unrelated memory files may be read into the agent context because no file allowlist or ownership boundary is defined.
  4. Information from those files may inadvertently influence or appear in generated output.
  5. The Skill writes the user's req ...[truncated 837 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace directory-wide reads with an explicit Skill-owned file, such as memory/cross-border-title-generator/preferences.json.
  2. Enforce an allowlist that prevents access to unrelated files under memory/.
  3. Ask for explicit user consent before saving generation history, with persistence disabled by default.
  4. Store only fields required for title generation and exclude credentials, personal information, raw conversations, and unrelated memory content.
  5. Define retention limits and provide commands to inspect, clear, or disable stored history.
  6. Apply restrictive file permissions and prevent other Skills from reading the Skill-owned storage unless the user explicitly authorizes it.
  7. Document precisely which preference fields are read and which history fields are written.
  8. If history is unnecessary, keep it in ephemeral session state rather than persistent shared memory.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly says it will read user preferences from memory/ and record generation history to memory/cross-border-history.md, but it provides no notice about what data is stored, how long it is retained, or who can access it. In an agent environment, silent persistence of user inputs can expose commercially sensitive product plans, search terms, or business strategy to later sessions or other skills.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Persisting user preference data and generation history in shared memory files creates a direct data retention risk, especially because inputs may contain business-sensitive product ideas, keyword strategies, ASIN-based competitor analysis, or account-specific preferences. Without scoping, sanitization, and retention limits, this data may be exposed across sessions, reused unexpectedly, or leaked through other tools that can read memory files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The entire skill interface and invocation example are presented only in Chinese, including the trigger /跨境标题, with no indication that users may choose another language. This can violate language/locale policy when a skill forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.