Back to skill

Security audit

Daily Reflect

Security checks for vulnerabilities and agentic risk

Overview

This journaling skill is mostly coherent, but it can create recurring cross-session push messages to external channels and stores per-user settings with limited top-level disclosure.

Install only if you want this skill to manage recurring morning and evening journaling prompts. Before enabling push, confirm the exact user ID, channel, schedule, timezone, and how to disable or audit the resulting jobs; avoid enabling it for users who only want one-off writing prompts.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
scripts/push-toggle.js:21
Finding

Recurring Scheduled Tasks Create Cross-Session Persistence

Content
View full analysis

Vulnerability Details

File Location: scripts/push-toggle.js:21-24
Vulnerability Type: T06: System Persistence
Risk Level: High

Complete Code Snippet

js
const sk=`agent:main:${ch}:direct:${userId}`;
console.log('__OPENCLAW_CRON_ADD__:'+JSON.stringify({name:`${SKILL}-morning-${userId}`,cronExpr:`${mm} ${mh} * * *`,tz:'Asia/Shanghai',session:'isolated',sessionKey:sk,channel:ch,to:userId,announce:true,timeoutSeconds:180,message:`node ${path.join(__dirname,'morning-push.js')} ${userId}`}));
console.log('__OPENCLAW_CRON_ADD__:'+JSON.stringify({name:`${SKILL}-evening-${userId}`,cronExpr:`${em} ${eh} * * *`,tz:'Asia/Shanghai',session:'isolated',sessionKey:sk,channel:ch,to:userId,announce:true,timeoutSeconds:180,message:`node ${path.join(__dirname,'evening-push.js')} ${userId}`}));
saveUser(userId,{...user,morningTime:mt,eveningTime:et,channel:ch,pushEnabled:true,updatedAt:new Date().toISOString()});

The corresponding removal logic is located at scripts/push-toggle.js:27-31:

js
function disablePush(userId){
  userId=sanitizeId(userId);
  console.log(`__OPENCLAW_CRON_RM__:${SKILL}-morning-${userId}`);
  console.log(`__OPENCLAW_CRON_RM__:${SKILL}-evening-${userId}`);
  saveUser(userId,{...loadUser(userId),pushEnabled:false,updatedAt:new Date().toISOString()});

Technical Analysis

When the documented on command is invoked, the script emits two __OPENCLAW_CRON_ADD__ control records. These records request daily morning and evening jobs that execute the bundled Node.js scripts and announce their output to a configured messaging recipient.

The jobs continue beyond the lifetime of the process that creates them and remain active until explicitly removed. The script also stores persistent per-user configuration under data/users, including the enabled state, delivery channel, and execution times.

The feature is openly documented and its inputs are constrained: user IDs are allowlisted by pattern, times are validated, and chan ...[truncated 1443 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit informed confirmation immediately before creating recurring jobs.
  2. Display the exact commands, delivery destination, schedule, time zone, and persistence duration before activation.
  3. Prefer schedules with an expiration date or a bounded opt-in period, requiring renewal for continued operation.
  4. Record stable scheduler job identifiers and verify ownership before updating or removing jobs.
  5. Provide automatic cleanup for expired, orphaned, or partially configured schedules.
  6. Ensure disabling the feature verifies that both jobs were actually removed rather than only emitting removal requests and updating local state.
  7. Clearly document where scheduler entries and per-user configuration are stored.
  8. Protect referenced scripts and their parent directory from unauthorized modification so an existing scheduled job cannot become an execution path for replaced code.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is ներկայացված as a simple journaling prompt tool, but the documentation reveals additional operational capabilities for scheduled push notifications, per-user state handling, and outbound delivery to third-party channels. This hidden expansion of scope increases privilege and data-handling expectations, making it easier for users or reviewers to underestimate the security and privacy risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad terms such as 'journal', 'journaling', 'writing prompt', and 'self-reflection' that can match many ordinary user requests outside the skill’s narrow daily-journaling intent. This can cause unintended skill invocation, misrouting user interactions, and possible interception of sensitive reflective or emotional conversations that the user did not intend to route to this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The user-facing title and usage instructions are presented in Chinese, while the metadata also includes English keywords, suggesting the skill may be invoked by multilingual users. There is no natural-language statement offering a language choice or clarifying that Chinese is the intended locale, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The '何时使用' section lists trigger phrases such as '今天写什么', 'writing prompt', and '帮我复盘今天', which are broad phrases that can arise in ordinary conversation outside this specific skill. The file does not provide exclusion conditions or narrower scope constraints, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest promises journaling prompts, but the body includes commands for enabling/disabling scheduled notifications and selecting delivery channels. This discrepancy can bypass user expectations and review assumptions, leading to unanticipated collection, storage, or transmission of user-related data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Multi-channel push control is a materially broader capability than a journaling prompt generator and may involve external integrations, identifiers, and message delivery outside the core stated purpose. Even if intended as a convenience feature, the lack of clear justification and disclosure increases the chance of over-privileged deployment or privacy-impacting use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script defines weekday names in Chinese and emits a fully Chinese prompt, including a stylistic instruction, with no user opt-in or alternative locale handling. This is a natural-language policy concern because it forces a specific language experience regardless of user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script hardcodes Chinese weekday names and emits a fully Chinese prompt beginning with '早安!', which directs the generated content format and tone in Chinese. This imposes a specific language/locale behavior without any opt-in or configuration, matching the policy-violation criteria for language constraints.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Supporting multiple messaging platforms is not inherently unsafe, but in this skill it broadens the external communication surface beyond the stated journaling purpose. That creates additional privacy and abuse risk, since user identifiers and prompts may be routed through third-party channels without clear necessity or disclosure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script provisions persistent scheduled jobs that send direct messages over external channels, which materially exceeds a simple local journaling-prompt utility. This increases the skill's operational scope and trust requirements, because it can create ongoing outbound communications and automate future actions without that behavior being clearly justified by the declared skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script hard-codes tz:'Asia/Shanghai' in scheduled jobs and prints status/confirmation messages entirely in Chinese. This imposes a specific locale and language on all users with no visible choice or opt-in, which matches the policy's language/locale violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The feature list says the skill is "Bilingual — Chinese and English," but does not explain how the language is selected or whether the user can choose their preferred language. Under the policy, language constraints should offer user choice or clearly document the locale behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.