Back to skill

Security audit

Pet Boarding Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent pet-boarding manager, but it should be reviewed because it directs storing customer, pet health, and billing records in predictable local JSON files without privacy safeguards.

Review this skill before installation if it will be used with real customers. Require owner-only file permissions, avoid storing full payment details, minimize medical and contact data, confirm the correct owner and pet before updates, and define retention and deletion practices.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:65
Finding

Plaintext Storage of Sensitive Customer, Pet Health, and Billing Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 65–119
Vulnerability Type: Sensitive data stored in unprotected local JSON files
Risk Level: Medium

Evidence

text
### Pet Owner Profile

OwnerID: OWN001 Name: John Smith Phone: +1-555-1234 Email: john@example.com Address: 123 Main St, Anytown, USA Emergency Contact: Jane Smith (wife) +1-555-5678 Created: 2026-06-15

text

### Pet Profile

PetID: PET001 Name: Buddy Species: Dog Breed: Golden Retriever Age: 3 years Gender: Male (neutered) Weight: 30kg Vaccination Status: Up-to-date (last: 2026-01-15) Special Instructions: Needs medication after meals (see meds list) Medical Conditions: None OwnerID: OWN001 Created: 2026-06-15

text

### Boarding Reservation

ReservationID: RES20250620001 PetID: PET001 CheckIn: 2026-06-20 10:00 CheckOut: 2026-06-25 16:00 Package: Premium ($45/night, includes daily walks + grooming) Status: Confirmed TotalNights: 5 Subtotal: $225 Tax: $22.50 Total: $247.50 Notes: "First time boarding, may be anxious"

text

### Daily Care Log

LogID: LOG20250621001 PetID: PET001 Date: 2026-06-21 Activities: - 08:00: Fed 500g Royal Canin (ate all) - 09:00: 30min walk (potty training, pooped normally) - 13:00: Medication (antibiotic, after lunch) - 18:00: Fed 500g Royal Canin + supplements - 19:00: 20min playtime in yard HealthNotes: "Energetic, good appetite, no diarrhea" StaffInitials: AS

text

## Pricing Calculator

Base rates (example):
- Standard boarding: $30/night (dogs), $25/night (cats)
- Deluxe boarding: $45/night (dogs), $35/night (cats)
- Luxury suite: $65/night (dogs), $50/night (cats)

Add-on services:
- Extra walk: $10/session
- Grooming: $25/session
- Medication administration: $5/day
- Special diet preparation: $8/day

Tax: 10% (adjustable by location)

## File Storage

All data stored in `~/.openclaw/p
...[truncated 2925 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require creation of ~/.openclaw/pet-boarding-data/ with owner-only permissions, such as mode 0700, and each data file with mode 0600. Verify permissions after creation and reject unsafe ownership or symbolic links.
  2. Encrypt sensitive records at rest using an authenticated encryption scheme. Store encryption keys in an operating-system credential store or dedicated secrets manager rather than alongside the JSON files.
  3. Apply data minimization. Store only information necessary for boarding operations and avoid retaining complete payment credentials. Use a compliant payment provider and retain only non-sensitive transaction references.
  4. Define role-based access controls where multiple staff members use the system. Separate permissions for medical records, billing, administration, and routine care logs.
  5. Add integrity protection, atomic writes, schema validation, and audit logging for changes to medication instructions, reservations, and billing records.
  6. Establish explicit retention and secure-deletion policies for expired reservations, billing records, contact information, and health notes.
  7. Prevent accidental disclosure through logs, generated responses, exports, backups, and synchronization services. Redact sensitive fields by default.
  8. Document secure backup requirements, including encryption, access restrictions, restoration testing, and deletion from retired backup media.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The workflow encourages carrying forward customer and pet details from one interaction into later actions such as creating reservations, implying session or cross-step persistence of sensitive data. In this context, that can cause privacy leaks, accidental reuse of stale records, or unintended actions on the wrong customer or pet if identity and consent are not re-validated before stateful operations.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Register a new customer: John Smith, phone +1-555-1234, email john@example.com. His dog Buddy is a 3-year-old Golden Retriever, neutered, weighs 30kg, special instructions: "needs medication after meals".

text

### 2. Create a boarding reservation

Create a boarding reservation for Buddy (owner John Smith). Check-in: 2026-06-20, check-out: 2026-06-25. Include premium package (daily walks + grooming).

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly directs storage of personally identifiable information and pet medical/care data in local JSON files, but provides no guidance on access controls, minimization, retention, encryption, or consent. This creates a real privacy and confidentiality risk because an agent or operator could persist sensitive customer and animal health information in plaintext in a predictable directory, increasing exposure to unauthorized local access or accidental disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.