Back to skill

Security audit

Product Requirement Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is a product-requirements toolkit, but its bundled setup script can overwrite installed skill files under a root-owned path without confirmation.

Review carefully before installing. Do not run create-skills.sh as root or against an existing OpenClaw skills directory unless you have backups and intentionally want those files replaced. Also confirm the Chinese-language workflow fits your team, and avoid entering unnecessary personal stakeholder data or sensitive financial details.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
create-skills.sh:47
Finding

Unconditional Overwrite of Existing Skill Files in a Privileged Fixed Directory

Content
View full analysis
"$SKILLS_DIR/$slug/SKILL.md" << 'SKILL_TEMPLATE' ``` ```bash cat > "$SKILLS_DIR/$slug/_meta.json" << META_TEMPLATE ``` ```bash cat > "$WORKFLOWS_DIR/$slug/SKILL.md" << WORKFLOW_TEMPLATE ``` ```bash cat > "$WORKFLOWS_DIR/$slug/_meta.json" << META_TEMPLATE ``` ### Technical Analysis The script writes generated content using the shell truncating-redirection operator (`>`). If a destination already exists, the shell truncates it before writing the replacement content. The script does not: - Check whether the destination already exists. - Request confirmation before replacement. - Create a backup. - Provide an explicit `--force` option. - Enable shell no-clobber behavior. - Validate destination ownership or file type. - Reject symbolic links. - Canonicalize and validate the destination path. The destination is hardcoded beneath `/root`, which means normal users cannot generally run the script successfully. This design encourages execution with elevated privileges even though generating Skill templates does not inherently require root access. If an existing destination is a symbolic link, ordinary shell redirection follows it. Under a deployment where another party can modify entries inside the destination hierarchy, this could cause the privileged process to truncate the link target. Exploitation of that condition requires prior ability to place or replace an entry in the target hierarchy; the reviewed project does not itself grant that ability. ### Attack Path 1. Existing customized or trusted Skill files are present under `/root/.openclaw/workspace/skills/require ...[truncated 1731 chars]
Remediation
View remediation
&2 exit 1 fi ``` 3. **Create destination directories explicitly** ```bash mkdir -p -- "$SKILLS_DIR" "$WORKFLOWS_DIR" ``` 4. **Prevent replacement by default** - Test each destination with `[[ -e "$destination" || -L "$destination" ]]`. - Exit if it already exists. - Require an explicit `--force` option before replacing files. - Alternatively, enable `set -o noclobber` and handle collisions safely. 5. **Reject symbolic links** ```bash if [[ -L "$destination" ]]; then echo "Refusing to overwrite symbolic link: $destination" >&2 exit 1 fi ``` 6. **Back up files before forced replacement** - Create a timestamped backup outside the replacement directory. - Preserve ownership, permissions, and timestamps where appropriate. - Report every replaced file to the user. 7. **Use atomic file creation** - Write content to a temporary file created securely in the destination directory. - Set appropriate permissions. - Rename the temporary file into place only after successful generation and validation. 8. **Validate canonical paths** - Resolve the configured base directory to its canonical form. - Verify every generated destination remains beneath that base. - Reject unexpected traversal, link resolution, or ownership conditions. 9. **Display a dry-run summary** - List files that will be created, skipped, or replaced. - Require confirmation for destructive operations in interactive use. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (36)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description says the skill 'defines problems from the user's perspective' but does not specify concrete invocation phrases, scope boundaries, or exclusion conditions. In a markdown/manifest context, this is broad enough to overlap with many general product discussions and could lead to unintended activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description advertises coverage of the entire requirement-analysis lifecycle, but it does not define when the skill should or should not be invoked. Because the scope is extremely broad and no negative examples or contextual limits are given, ordinary requirement-related conversation could accidentally match it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow is described as end-to-end requirement analysis from problem definition to PRD output, but there is no explicit trigger list, narrow context, or exclusion criteria. That makes the activation condition ambiguous for any conversation involving requirements or documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script is filled with Chinese-only user-facing strings and generates SKILL.md files whose headings, labels, prompts, and examples are all in Chinese. Because the file provides no opt-in, language selection, or documented region-specific constraint, it appears to impose a specific language/locale in violation of the stated policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly prompts users to collect named decision-makers, influencers, and users along with roles and concerns, which is personal/business-contact intelligence. Without any privacy notice, lawful-basis guidance, minimization rule, or handling/storage restrictions, the skill can encourage unnecessary collection and dissemination of personal data, creating privacy, compliance, and misuse risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown skill forces a specific language for instructions, examples, and usage, which is a natural-language locale policy concern under the stated rules. The file does not indicate that Chinese is optional, user-selected, or justified as a region-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown skill enforces a specific language throughout its title, instructions, templates, and examples, but does not mention any user opt-in or alternative language support. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The display name and description are written only in Chinese, with no indication that the skill is region-specific or that users can choose another language. This can violate language/locale policy when a skill implicitly enforces one language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is written entirely in Chinese and its commands, prompts, and output templates assume Chinese-language interaction without offering any language selection or documenting that the skill is intentionally limited to a Chinese-speaking audience. This can exclude users, cause misunderstanding of investment decisions, and reduce safe/accurate use in multilingual environments, though it is not a code-execution or privilege-escalation issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill appears to require Chinese for invocation guidance, usage instructions, and output templates, but it does not state that the user may choose another language or that the skill is intended only for a Chinese-speaking context. That creates a natural-language policy concern because it effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown skill forces a specific language for all instructions, examples, and usage guidance, which can violate organizational language/locale policy when no user opt-in or alternative is provided. The file does not state that the skill is region-specific or that Chinese is optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill is authored in Chinese and does not indicate that users may request another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest presents the skill's user-facing display name and description entirely in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking region. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown skill file presents all operational instructions and examples in Chinese, which effectively forces a specific language for users. The policy allows locale constraints only when they are explicitly justified or when users are given a language/locale choice, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill forces a specific language for instructions, examples, and usage without indicating that users can opt into another language. Under the language/locale policy, a fixed language is a violation unless choice or justification is explicitly provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown skill mandates Chinese as the interaction language through all headings, instructions, examples, and command guidance, but does not state that the skill is region-specific or provide any user opt-in for language selection. Under the language/locale policy rule, forcing a specific language without choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown skill file presents all user-facing instructions, examples, and invocation guidance exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in or a documented justification is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown skill file presents its instructions, usage, and examples almost entirely in Chinese, which effectively enforces a specific language for users. Under the policy, locale or language constraints should either be optional for the user or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents the skill instructions and usage entirely in Chinese, which effectively forces a specific language for users. The policy allows locale or language constraints only when users are given a choice or the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents the workflow instructions entirely in Chinese, including the title, description, stages, and usage guidance. Under the policy rule for language/locale, forcing a specific language without offering user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill content is written entirely in Chinese, including the title, workflow stages, usage, and outputs, with no indication that users may choose another language or that the skill is region-specific. This creates a natural-language locale constraint that can conflict with organizational language-choice policies when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest uses Chinese for the display name and description, but does not indicate that the workflow is intended only for Chinese-speaking users or that language is selectable. This can violate language/locale policy when a skill imposes a language implicitly without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's natural-language instructions, prompts, and examples are entirely in Chinese, effectively forcing a specific language experience. There is no opt-in, alternative language option, or documented justification that this skill is intended only for a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest presents the skill name and description entirely in Chinese, but does not document that the skill is China-region-specific or that users may choose another language. This can conflict with language/locale policy requirements when skills are expected to respect user language preferences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest presents the user-facing display name and description only in Chinese, with no indication that language is selectable or that the skill is intended solely for a Chinese-speaking context. This can violate a language/locale policy when users are not given an opt-in choice or a documented locale justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.