Back to skill

Security audit

English Daily

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local English-learning tool, but its persistent memory and scheduled prompts can be influenced by unchecked profile names.

Review before installing. Use only with trusted users or after tightening validation for names/profile fields, and be aware that it creates persistent learning records in MEMORY.md plus optional scheduled OpenClaw reminders. Avoid crafted names or any profile text containing markdown delimiters, newlines, quotes, backticks, or instruction-like content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/wordbank.js:154
Finding

Unsanitized profile names enable persistent prompt injection and unsafe command generation

Content
View full analysis
## 英语学习档案 · ${profile.name} - userId: ${pr ...[truncated 4589 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a full-featured English learning system with spaced repetition, quizzes, streaks, and progression. The supplied code chunk, however, is a lightweight prompt generator: it validates a userId, gets today’s date, and prints instructions telling an agent to read a user profile from MEMORY.md, invoke another quiz script, and write results back. That is materially narrower and different from the declared end-user functionality. While orchestration can support the overall skill, this specific code does not itself provide the described capabilities and explicitly relies on external memory access and other scripts despite declared permissions being empty. Therefore this chunk does not accurately represent the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a user-facing English learning skill with concrete learning functionality: built-in vocabulary content, spaced repetition, quizzes, streaks, and progression. The supplied code chunk does not perform those functions. Instead, it validates a userId, gets the current date, and prints a Chinese instruction directing another agent/process to read user state from MEMORY.md, run a separate script with that state, and write updated memory back. That is a materially different primary purpose for this chunk: prompt/orchestration generation. It also references reading and writing MEMORY.md, which is inconsistent with the declared empty permissions. While this chunk may be part of a larger system, based on the provided code alone the implemented behavior does not accurately match the declared skill description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents an end-user English learning product centered on spaced repetition, built-in vocabulary content, quiz modes, streak tracking, and progression. The supplied code chunk does not implement those learning behaviors. Instead, its primary function is operational: toggling scheduled daily push notifications for a user. It emits OPENCLAW_CRON_ADD / OPENCLAW_CRON_RM directives, validates scheduling/channel options, and builds a message instructing an agent to later read MEMORY.md and run daily-push.js. While this is plausibly related to a broader English-learning system, this specific code chunk's actual behavior is a scheduling/configuration utility, not the described learning skill itself. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The code is related to the declared English-learning purpose and does support parts of the description: built-in level selection A1–B2, quiz generation, and spaced-repetition progress updates. However, the description overstates what this specific code chunk does. Quiz modes implemented are only vocab, sentence, and mixed; there is no spelling mode. The script does not itself perform daily lesson delivery or streak progression management; it mostly accepts existing values as arguments and outputs updated state for another agent to write back. It also relies on an external MEMORY.md persistence workflow, which is an undeclared resource interaction relative to the empty permissions declaration. So the description does not accurately represent the actual behavior of this supplied code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
node scripts/daily-push.js <userId> --level <等级> --goal <目标> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
node scripts/daily-push.js <userId> --level <等级> --goal <目标> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
node scripts/daily-push.js <userId> --level <等级> --goal <目标> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
node scripts/daily-push.js <userId> --level <等级> --goal <目标> \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
node scripts/quiz.js <userId> [vocab|sentence|mixed] --level <等级> --progress '<SRS进度JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
node scripts/quiz.js <userId> [vocab|sentence|mixed] --level <等级> --progress '<SRS进度JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
node scripts/quiz.js <userId> [vocab|sentence|mixed] --level <等级> --progress '<SRS进度JSON>'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
node scripts/push-toggle.js on <userId> --level <等级> --goal <目标> [--morning 08:00] [--channel telegram]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
node scripts/push-toggle.js on <userId> --level <等级> --goal <目标> [--morning 08:00] [--channel telegram]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
node scripts/push-toggle.js on <userId> --level <等级> --goal <目标> [--morning 08:00] [--channel telegram]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
node scripts/push-toggle.js on <userId> --level <等级> --goal <目标> [--morning 08:00] [--channel telegram]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
node scripts/push-toggle.js on <userId> --level <等级> --goal <目标> [--morning 08:00] [--channel telegram]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
node scripts/push-toggle.js on <userId> --level <等级> --goal <目标> [--morning 08:00] [--channel telegram]

Hidden Instructions

High
Category
Prompt Injection
Confidence
81% confidence
Finding

These hidden workflow instructions are not malicious by themselves, but they direct persistent memory reads and writes outside the visible user interaction path. In an agent environment, concealed state manipulation can become dangerous if a user-controlled field breaks block boundaries, injects markdown/comments, or alters the data later passed to scripts and automation, leading to profile corruption or unintended actions.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
**流程:**

1. 新用户 → 运行 `register.js`,它输出一段 `<!-- english-daily:profile:<userId> -->` markdown 区块。**把该区块写入 MEMORY.md。**
2. 后续每次学习/测验/看进度 → 先**读取 MEMORY.md** 中该区块,把 等级/每日目标/streak/积分/SRS进度(JSON) 作为参数传给脚本。
3. `daily-push.js`(刷新 streak/上次学习)、`quiz.js --score`(累加积分、更新 SRS)、`progress.js`(升级时)会输出**更新后的区块**——用它覆盖 MEMORY.md 中的旧区块。
4. SRS 进度是一段紧凑 JSON,存在区块的「SRS进度」行;传参时原样作为 `--progress '<JSON>'`,勿手动改写。

Hidden Instructions

High
Category
Prompt Injection
Confidence
81% confidence
Finding

These hidden workflow instructions are not malicious by themselves, but they direct persistent memory reads and writes outside the visible user interaction path. In an agent environment, concealed state manipulation can become dangerous if a user-controlled field breaks block boundaries, injects markdown/comments, or alters the data later passed to scripts and automation, leading to profile corruption or unintended actions.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
**流程:**

1. 新用户 → 运行 `register.js`,它输出一段 `<!-- english-daily:profile:<userId> -->` markdown 区块。**把该区块写入 MEMORY.md。**
2. 后续每次学习/测验/看进度 → 先**读取 MEMORY.md** 中该区块,把 等级/每日目标/streak/积分/SRS进度(JSON) 作为参数传给脚本。
3. `daily-push.js`(刷新 streak/上次学习)、`quiz.js --score`(累加积分、更新 SRS)、`progress.js`(升级时)会输出**更新后的区块**——用它覆盖 MEMORY.md 中的旧区块。
4. SRS 进度是一段紧凑 JSON,存在区块的「SRS进度」行;传参时原样作为 `--progress '<JSON>'`,勿手动改写。

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The inline comments contradict the script's actual operational intent by claiming no file access while the generated instruction tells the agent to fetch profile data from MEMORY.md and later overwrite that memory block. In an agent setting, this kind of deceptive or inaccurate metadata is dangerous because it can bypass human review, policy gating, or trust decisions based on the claimed behavior rather than the effective behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as an 'English Daily' learning skill and all described functionality is framed exclusively around English, with no indication that users can choose another language or opt into this locale constraint. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless the constraint is clearly documented and justified as region- or purpose-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The title and introductory description frame the skill around English learning only, and the profile example hard-codes a native language field of "zh" later in the document. There is no explicit opt-in or language-choice mechanism described for interface or instructional language, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The listed triggers are common phrases a user could say in many contexts, not just when intending to invoke this specific skill. The document does not provide negative examples or tighter context boundaries to distinguish English-learning usage from general conversation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

"开启推送" is a broad everyday phrase that could refer to many kinds of reminders, alerts, or notifications beyond English learning. The skill description does not constrain it to English-study push notifications or provide disambiguation rules.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.