Back to skill

Security audit

Aviation Healthcheck

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed aviation maintenance news and local OpenClaw health-check helper, with no hidden code or destructive behavior found.

Before installing, understand that running this skill may contact external aviation websites and may execute local OpenClaw status, health, security-audit, update-status, and disk-space commands. Only enable the suggested cron schedule if you want recurring checks several times per day.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
This markdown skill file describes the skill's purpose and behavior but does not specify what exact phrases, commands, or contexts should trigger it. Without explicit trigger scope or exclusion conditions, the skill may be invoked too broadly when a user mentions aviation maintenance or health checks in general conversation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill description and primary instructions force a specific language presentation, which can violate language or locale policy when no user opt-in is provided. There is no indication that the skill is intentionally region-specific or that users may choose another language.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The markdown instructs the skill to check multiple external FAA, EASA, CAAC, and industry news sources, which implies network access to third-party services. The description does not warn users that running the skill may contact external websites and potentially expose request metadata or system-originated traffic.

Static analysis

No suspicious patterns detected.