T02 · Agent Memory Poisoning
- Location
scripts/parse_input.js:73- Finding
Persistent Prompt Injection Through Stored Model-Generated Tags
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears purpose-built for exam mistake tracking, but it retains sensitive screenshot/study data and exports it with several under-scoped safety issues users should review before installing.
Install only if you are comfortable with the skill saving exam text, annotations, and screenshots under ~/.openclaw/skills/shiyi and using your configured vision model to process images. Avoid sending screenshots with personal/account details, review exported spreadsheets before sharing them, and consider fixing the export sanitization, tag validation, temp-file handling, dependency pinning, and broad trigger phrases before using it on shared machines or sensitive materials.
scripts/parse_input.js:73Persistent Prompt Injection Through Stored Model-Generated Tags
scripts/export_xlsx.js:112Spreadsheet Formula Injection in Exported XLSX Files
scripts/export_xlsx.js:150Path Traversal and Invalid Worksheet Name Through Export Section Filter
scripts/update_daily.js:62Path Traversal Through Unvalidated Daily Record Date
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
data/
config.json
*.xlsx
.env
.DS_Store
*.log
The declared description presents the skill as a full-featured exam mistake-management tool centered on screenshot recognition and review workflows. The supplied code chunk does not implement those core capabilities. Instead, it performs a setup flow: sending a welcome prompt, asking for the exam type, resolving/storing an exam key, and handling later reconfiguration via '换考试'. While exam selection could be a supporting part of the broader skill, this chunk's actual behavior is materially narrower than the declared purpose and introduces local file storage that is not mentioned in the declared permissions. Therefore this code chunk does not accurately represent the advertised functionality on its own.
Referenced artifact was not completely inspected
| `scripts/tag_library.js` | 标签词库读写与统计 |
Referenced artifact was not completely inspected
| `scripts/update_daily.js` | 写入错题和每日记录 |
Referenced artifact was not completely inspected
| `scripts/export_xlsx.js` | 导出 Excel(含筛选和截图嵌入) |
Referenced artifact was not completely inspected
| `scripts/review_reminder.js` | 二刷提醒和自评处理 |
Referenced artifact was not completely inspected
| `scripts/daily_summary.js` | 每日定时总结 |
The README says '安装后发任意消息' ('after installation, send any message'), which makes the trigger condition extremely broad and likely to overlap with ordinary conversation. It does not define clear boundaries for when the skill should activate versus ignore unrelated messages.
The README explicitly describes persistent local storage of wrong-question records, daily logs, backups, and exports, but does not warn users that screenshots and text may contain sensitive educational or personal data. In a messaging-integrated skill, silent retention and export of user-submitted content increases privacy risk, especially on shared hosts or devices where exported files and backups may be accessible to others.
The trigger list includes broad everyday phrases such as '记得' and '不记得', which can cause the skill to activate unintentionally during unrelated conversations. Because the skill handles study records and file-backed state, accidental invocation can lead to unintended data writes, state changes, or confusing exports/reminders.
The skill describes screenshot recognition, persistent storage, reminders, and export behavior without clearly informing users what personal study data is collected, where it is stored, how long it is retained, or when it is exported. Since screenshots and wrong-question logs may contain sensitive personal or educational content, lack of transparent notice increases privacy and consent risk.
The code decodes base64 screenshots and writes them as JPG files into the system temp directory before embedding them into the spreadsheet. These files contain sensitive study content and may remain accessible to other local users, backup tools, or forensic recovery if cleanup fails, so this is a real privacy/security weakness even though the files are later deleted on a best-effort basis.
The skill generates a temporary Python script, writes it to disk, and runs it via execFile. This combines file creation with subprocess execution, but the only visible log appears after completion, so users are not warned beforehand that code will be written and executed locally.
The natural-language prompts instruct the user entirely in Chinese and explicitly tell them to send the exam name, without offering any language choice or opt-in. This is a language/locale policy concern because the skill appears to assume a specific language for all users.
The confirmation and usage messages are also entirely in Chinese and do not provide any alternative locale or explain that the skill is region- or language-specific. This continues the language policy issue beyond the initial welcome prompt.
The code sends user-provided image content and captions to an external vision-capable agent via agentCall without any visible consent, warning, or minimization in this component. Because this skill processes screenshots of exam mistakes, the images can easily contain personal data, handwritten notes, account details, or other sensitive educational content, creating a privacy and data-handling risk.
The function returns raw_image_b64 in the parsed result object, which increases the chance that full image contents are retained, logged, stored, or forwarded beyond the immediate OCR task. In this skill context, screenshots of study materials may also include personal notes or metadata, so retaining the raw image materially expands exposure if downstream storage, export, or logging occurs.
This file contains natural-language prompts and comments that assume Chinese as the operating language, but there is no indication that users can opt into another language or that the skill is intentionally region-specific. Under the language/locale policy, forcing a specific language without user choice can be a policy concern.
The description is written entirely in Chinese, which can indicate a fixed language expectation for the skill. In this manifest there is no accompanying note that the skill is region-specific or that users may choose another language, so it may conflict with a language/locale choice policy.
The dependency xlsx is specified with a caret range, which allows future compatible versions to be installed implicitly. Because this package family has had multiple security advisories, leaving the version range open increases supply-chain risk and makes builds non-reproducible, especially for a skill that imports user-provided screenshots/data and exports files.
"author": "",
"license": "MIT",
"engines": { "node": ">=18" },
"dependencies": { "xlsx": "^0.18.5" },
"optionalDependencies": { "sharp": "^0.33.0" },
"scripts": {
"export": "node scripts/export_xlsx.js",
The manifest includes xlsx, a package with several published advisories, but the version is not pinned, so it is unclear whether deployed installs are affected. In this skill's context, spreadsheet export from potentially user-influenced study data increases the relevance of parser/serialization bugs such as prototype pollution or denial of service.
The optional dependency sharp is also specified with a caret range, allowing unreviewed patch/minor updates at install time. Although optional dependencies may not always be installed, if this image-processing library is present it may process user-supplied images, so uncontrolled version drift creates unnecessary supply-chain exposure.
"license": "MIT",
"engines": { "node": ">=18" },
"dependencies": { "xlsx": "^0.18.5" },
"optionalDependencies": { "sharp": "^0.33.0" },
"scripts": {
"export": "node scripts/export_xlsx.js",
"export:pending": "node scripts/export_xlsx.js --pending-only",
The code persists the user's exam choice to a config file in the home directory, but the user-facing onboarding messages do not disclose that this information will be stored locally. For a code file, persistent file writes affecting user data should have some visible warning, confirmation, or explanatory notice.
The file-level description is written entirely in Chinese, and the rest of the user-facing comments and defaults in the file follow the same language assumption. Under the stated policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy issue.
Detected: suspicious.dangerous_exec