Back to skill

Security audit

Daily Astro

Security checks for vulnerabilities and agentic risk

Overview

This horoscope skill is coherent and disclosed, with expected daily push scheduling that users should intentionally enable and know how to disable.

Install only if you want a bilingual Chinese/English horoscope skill. Enable pushes only for your own authorized messaging identifier, review the selected channel and schedule, and run the off command before deleting the package if you no longer want recurring notifications.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
scripts/push-toggle.js:21
Finding

Recurring Scheduled Tasks Create Cross-Session Persistence

Content
View full analysis

Vulnerability Details

File Location: scripts/push-toggle.js, lines 21–24
Vulnerability Type: T06: System Persistence
Risk Level: High

Vulnerable Code

js
const sk=`agent:main:${ch}:direct:${userId}`;
console.log('__OPENCLAW_CRON_ADD__:'+JSON.stringify({name:`${SKILL}-morning-${userId}`,cronExpr:`${mm} ${mh} * * *`,tz:'Asia/Shanghai',session:'isolated',sessionKey:sk,channel:ch,to:userId,announce:true,timeoutSeconds:180,message:`node ${path.join(__dirname,'morning-push.js')} ${userId}`}));
console.log('__OPENCLAW_CRON_ADD__:'+JSON.stringify({name:`${SKILL}-evening-${userId}`,cronExpr:`${em} ${eh} * * *`,tz:'Asia/Shanghai',session:'isolated',sessionKey:sk,channel:ch,to:userId,announce:true,timeoutSeconds:180,message:`node ${path.join(__dirname,'evening-push.js')} ${userId}`}));
saveUser(userId,{...user,morningTime:mt,eveningTime:et,channel:ch,pushEnabled:true,updatedAt:new Date().toISOString()});

Technical Analysis

The on command emits two __OPENCLAW_CRON_ADD__ host-control records that request recurring daily execution of the package's morning and evening scripts. A compatible OpenClaw host can interpret these records and install scheduled tasks that outlive the process and Agent session that created them.

The generated tasks execute in isolated sessions, target the selected communication channel and user, and run every day in the Asia/Shanghai timezone. This is cross-session persistence through scheduled tasks and therefore matches T06: System Persistence.

Activation requires an explicit on command, and the behavior is documented in README.md and SKILL.md. Removal records are also available through the off command at scripts/push-toggle.js:27–31. Consequently, the audit found scheduled-task persistence but no evidence that it is covert or that it constitutes a backdoor.

Attack Path

  1. A user or Agent invokes:
    bash
    node scripts/push-toggle.js on <userId>
    
  2. Optional schedule and channe ...[truncated 1331 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed confirmation immediately before creating either scheduled task.
  2. Before confirmation, display each exact job name, cron expression, timezone, executable command, destination channel, recipient, and session mode.
  3. Ensure skill installation or loading never enables the schedules automatically.
  4. Require host-side authorization for schedule creation rather than relying solely on emitted control markers.
  5. Provide an uninstall or cleanup mechanism that removes both registered jobs even if the package path has changed.
  6. Add a command that enumerates actual host-side jobs and reconciles them with locally stored pushEnabled state.
  7. Handle partial failure atomically: if only one task is registered, remove it or clearly report the incomplete state.
  8. Document that users must execute the off or cleanup operation before deleting the package.
  9. Consider adding an expiration period or periodic reconfirmation so recurring tasks do not persist indefinitely without renewed consent.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list is very broad and includes generic terms like 'horoscope', 'zodiac', 'astrology', and multiple sign names, which can cause the skill to activate in conversations where the user did not explicitly intend to invoke this specific skill. In an agent ecosystem, unintended invocation can leak conversational context to the skill, create confusing responses, or crowd out more relevant skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The '何时使用' section lists trigger examples like 'horoscope', 'zodiac', and broad intent descriptions such as asking about love/career/finance luck, but it does not define clear activation constraints or exclusions. Without negative examples or scope limits, these phrases could overlap with general conversation about astrology rather than a specific request for this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill exposes commands to enable recurring push notifications for a supplied userId and third-party channel without documenting consent, identity verification, or safe handling of user identifiers. If integrated naively, this could let an operator or downstream agent subscribe users without authorization, spam external channels, or mishandle identifiers tied to messaging accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script emits its primary status and success messages entirely in Chinese, including the enable/disable confirmations and status display. This imposes a specific language on all users without opt-in or explanation, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README states the skill is "Bilingual EN/CN," which indicates a fixed language behavior, but it does not say the user can choose their preferred language. This may conflict with language-choice policy expectations when locale behavior is preselected rather than offered as an option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description states 'Bilingual EN/CN,' and the body similarly advertises '中英双语,' but it does not say the user can choose their preferred language. This can violate language/locale policy when a skill imposes a language format without explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The tagline emphasizes Chinese/English bilingual behavior, but there is no indication that the skill adapts to the user's chosen language. A fixed bilingual output requirement can be a natural-language policy issue if users are not offered a locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script defines weekday names in Chinese and emits a fixed Chinese-language prompt, only appending a requirement for bilingual output. This imposes a specific language/locale in the skill behavior without offering the user a choice or documenting that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script uses Chinese weekday labels and prints a prompt requiring Chinese-formatted content, which enforces a specific language/locale behavior. This matches the policy category for language or locale constraints because there is no user opt-in or configurable language selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.