Back to skill

Security audit

MBTI Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local MBTI report skill, but it processes and stores broad OpenClaw history while a key sensitive-path exclusion promise is not actually enforced.

Review before installing. Use this only if you are comfortable with a local tool reading OpenClaw history and workspace memory. Prefer approving only workspace memory and sessions, avoid the memory-index, task-run, and cron-run categories unless you explicitly need them, use quote-mode none for sensitive histories, and delete the .mbti-reports output directory after use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/ingest_all_content.py:115
Finding

Sensitive-path exclusions are not enforced during memory-index ingestion

Content
View full analysis
List[Dict]: db_path = openclaw_home / "memory" / "main.sqlite" if not db_path.exists(): return [] rows = load_sqlite_rows( db_path, """ select path, start_line, end_line, text, updated_at from chunks order by path, start_line """, ) records: List[Dict] = [] for row in rows: location = f"{row['path']}:{row['start_line']}-{row['end_line']}" records.append( { "record_id": stable_id([str(db_path), location]), "source_type": "openclaw-memory-index", "source_path": str(db_path), "location": location, "timestamp": row["updated_at"], "speaker": "user", "conversation_id": row["path"], "content": row["text"], } ) return records ``` The project declares the following exclusions in `scripts/mbti_common.py:14-23`: ```python DEFAULT_EXCLUDED_PATTERNS = [ ".env", "credentials/*", "identity/*", "devices/*", "exec-approvals.json", "openclaw.json", "logs/*", "gateway*.log", ] ``` ### Technical Analysis The memory-index ingestor selects every row from the `chunks` table and copies each row's complete `text` value into the raw record collection. It does not apply `DEFAULT_EXCLUDED_PATTERNS`, an equivalent allowlist, or any secret-redaction logic. The exclusion list is exposed in the discovery manifest but is not enforced by this ingestion path. Consequently, authorization of the broad `openclaw-memory-index` source category can implicitly authorize indexed content from `.env`, credential, identity, approval ...[truncated 1828 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/discover_sources.py:72
Finding

Memory-index path metadata is read and persisted before user authorization

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (25)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a user-facing MBTI analysis skill that infers personality type from historical user data. The supplied code does not perform personality analysis at all. Instead, it is a development script for generating synthetic fixtures for testing a single MBTI stage. Its primary behavior is parsing CLI arguments, invoking fixture-generation helpers, writing files to an output directory, and printing JSON. This is materially different from the declared purpose and uses different resources and triggers, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description says the skill should infer MBTI from authorized historical sources when a user asks to be typed. But this code chunk is specifically a report renderer: it formats an existing analysis into Markdown/HTML, localizes text, embeds images/CSS, loads famous-people reference data, writes output files, and can open the report in a browser. In normal mode it requires --analysis and --evidence-pool inputs; in debug mode it fabricates mock analysis/evidence fixtures. There is no code here that reads OpenClaw memory, session history, or workspace notes for inference, nor any scoring/extraction pipeline beyond presentation of already structured results. So the chunk's primary behavior materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/apply_followup_answers.py (reported line 77)May include surrounding context.

python
question = item.get("question")
        if axis in VALID_AXES and question:
            prompts[axis] = question
    return prompts


def followup_record(axis: str, answer: str, output_dir: Path) -> Dict:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/mbti_common.py (reported line 15)May include surrounding context.

python
from typing import Any, Dict, Iterable, Iterator, List

DEFAULT_EXCLUDED_PATTERNS = [
    ".env",
    "credentials/*",
    "identity/*",
    "devices/*",

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises broad natural-language triggers such as "MBTI," "personality analysis," "type me," and Chinese equivalents, which can increase the chance of accidental or overly eager invocation in normal conversation. Because this skill reads potentially sensitive local sources like memory, sessions, and workspace notes, unintended activation could expose or process more personal context than the user explicitly meant to analyze.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that reports are rendered automatically in English or Chinese based on source language mix, which implies the skill may force a language choice without asking the user. This can violate language/locale policy when no explicit user preference or opt-in is offered.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs the agent to read sensitive local sources, write report artifacts, and execute multiple Python scripts, but it declares no explicit tool/permission scope. In a skill system, missing scope boundaries can let a broadly tooled agent perform far more filesystem or command activity than users expect, especially against session history and local databases under ~/.openclaw.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description invites broad 'personality inference' from historical data without strong exclusion boundaries, increasing the chance of overbroad invocation and privacy-invasive use beyond narrow MBTI reporting. In context, that can lead agents to analyze sensitive personal content when the user may not expect the scope of data review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrase 'type me' is broad and likely to match ordinary conversation, causing accidental invocation of a skill that reads historical memory, session logs, and workspace notes. Unintended activation is especially risky here because the skill processes sensitive personal and behavioral data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill persistently writes extracted records, source summaries, evidence pools, and analysis outputs into a timestamped local directory by default. Because these artifacts are derived from private memories, session histories, and local metadata, persistence increases the chance of later unauthorized access, retention beyond user intent, and secondary disclosure.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

Execution Flow

If the user does not provide an output directory, write results to:

text
./.mbti-reports/<timestamp>/

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/famous_people.json (reported line 1039)May include surrounding context.

json
mbti_type": "ISTP",
      "domain": "History",
      "description": "Japanese swordsman and author of The Book of Five Rings.",
      "source": "curated",
      "detail_url": "https://www.stablecharacter.com/personality-database/miyamoto-musashi"
    },
    {
      "name": "Wolverine (Logan)",
      "mbti_type": "ISTP",
      "domain": "Fictional",
      "description": "Marvel superhero known for fierce independence.",
      "source": "curated",
      "detail_url": "https://www.stablecharacter.com/personality-database/wolverine-logan"
    },
    {
      "name": "Vladimir Putin",
      "mbti_type": "ISTP",
      "domain": "Politics",
      "description": "Russian president since 2000.",
      "source": "stablecharacter.com",
      "detail_url": "https://www.stablecharacter.com/personality-database/vladimir-putin"
    }
  ],
  "ISFP": [
    {
      "name": "Lady Gaga",
      "mbti_type": "ISFP",
      "domain": "Music",
      "description": "Pop star and actress known for avant-garde sty

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script enumerates task-run and cron-run artifacts in addition to memory and session sources, expanding collection beyond the skill’s stated MBTI evidence scope. In a personality-analysis skill, this increases privacy risk because operational histories may contain unrelated sensitive user data, making over-collection and downstream misuse more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains user-facing natural-language strings in Chinese for follow-up questions and in English for summaries and narratives, but there is no indication that the user can choose or opt into the language used. That creates a locale/language policy issue because the skill effectively forces a particular language mix in generated output.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is described as analyzing MBTI from authorized memory, session history, and workspace notes, but this script also ingests task-run and cron-run data, which can contain unrelated operational, system, or sensitive user content. That creates a data-scope expansion risk: users or operators may authorize personality analysis expecting limited sources, while the skill silently aggregates broader telemetry that could expose secrets or sensitive behavioral data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script writes consolidated raw content from sessions, memory, task runs, and cron runs into raw_records.jsonl and source_summary.json without any built-in minimization, redaction, or notice. In this skill context, the data is likely to include highly sensitive personal and system information, so creating a single aggregate file increases exposure if the output directory is shared, persisted, or later reused by other tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code embeds multiple Chinese-specific natural-language patterns alongside some English patterns for core signal detection, which effectively bakes a language preference into the skill behavior. Because there is no visible opt-in, fallback policy, or documented justification in this file for restricting or biasing analysis toward Chinese-language inputs, it creates a locale/language policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes analyzing authorized memory/session/workspace notes to produce an MBTI analysis. In this file, the optional --open flow invokes platform-specific browser-opening commands (open, xdg-open, cmd /c start), adding local process execution and external application launch capability unrelated to personality inference itself.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_report.py (reported line 1343)May include surrounding context.

python
html_path = html_path.resolve()
    if sys.platform == "darwin":
        subprocess.Popen(["open", str(html_path)])
    elif sys.platform.startswith("linux"):
        subprocess.Popen(["xdg-open", str(html_path)])
    elif sys.platform == "win32":

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_report.py (reported line 1345)May include surrounding context.

python
if sys.platform == "darwin":
        subprocess.Popen(["open", str(html_path)])
    elif sys.platform.startswith("linux"):
        subprocess.Popen(["xdg-open", str(html_path)])
    elif sys.platform == "win32":
        subprocess.Popen(["cmd", "/c", "start", "", str(html_path)])
    else:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render_report.py (reported line 1347)May include surrounding context.

python
elif sys.platform.startswith("linux"):
        subprocess.Popen(["xdg-open", str(html_path)])
    elif sys.platform == "win32":
        subprocess.Popen(["cmd", "/c", "start", "", str(html_path)])
    else:
        print(f"Cannot auto-open on {sys.platform}; open manually: {html_path}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code exposes a --language option with a hard-coded zh choice and also contains extensive Chinese-only output strings throughout the file. Under the stated policy, forcing a specific language is a natural-language policy concern unless the skill offers the user a language choice or clearly documents the locale constraint; in this file, the renderer can emit a fixed Chinese locale and many strings are only available in Chinese, with no in-file justification for that locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This JSON dataset stores all names, domains, and descriptions in English only, with no accompanying indication that the content is English-specific or that alternate locales are supported. Because SQP-3 covers language/locale policy violations in config values and natural-language content, an English-only dataset without opt-in or justification can violate an organizational requirement to avoid forcing a specific language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code writes a JSON manifest to disk via write_json(...), and the manifest includes discovered paths and sample entries from session, memory, and task data. The file has no confirmation prompt, print/log disclosure, or inline warning near the write operation to alert the user that potentially sensitive metadata will be persisted.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The skill is described as analyzing MBTI from authorized content, but this script performs broad ingestion and persists raw aggregated records and summaries to output files. Persisting consolidated copies of all source content is a materially broader operation than analysis alone, even if done locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.