Back to skill

Security audit

自我复盘

Security checks for vulnerabilities and agentic risk

Overview

This self-reflection skill is not clearly malicious, but it needs review because it can persist conversation-derived notes and optionally install a recurring macOS scheduled task.

Install only if you want this skill to store reflection and daily-memory Markdown files locally. Review or disable the scheduling setup before use, avoid running --setup unless you intentionally want recurring execution, and consider changing the /tmp logging paths to a private user-owned log directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/daily_master.sh:13
Finding

Predictable Temporary Log Files May Disclose Sensitive Command Context or Follow Malicious Symlinks

Content
View full analysis
> /tmp/daily_reflect.log 2>&1 # 2. 自动提醒检查 echo "[$(date '+%Y-%m-%d %H:%M:%S')] 2/3 运行自动提醒检查..." $PYTHON3 "$SKILL_DIR/auto_remind.py" --check >> /tmp/auto_remind.log 2>&1 # 3. 重复模式检测 echo "[$(date '+%Y-%m-%d %H:%M:%S')] 3/3 运行重复模式检测..." $PYTHON3 "$SKILL_DIR/repeat_detect.py" >> /tmp/repeat_detect.log 2>&1 ``` From `scripts/daily_reflect.py:68-71`: ```xml StandardOutPath /tmp/daily_reflect.log StandardErrorPath /tmp/daily_reflect.err ``` ### Technical Analysis The scripts write operational output to fixed, predictable paths in the shared `/tmp` directory. They do not securely create these files, verify ownership, reject symbolic links, or explicitly enforce restrictive ...[truncated 2702 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill promises proactive writing of reflection data, but the actual described logic for some components appears limited to reading mistakes entries and outputting analysis. This inconsistency can mislead users about what data is created, what is merely analyzed, and when automation occurs, undermining informed consent and safe review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill promises proactive writing of reflection data, but the actual described logic for some components appears limited to reading mistakes entries and outputting analysis. This inconsistency can mislead users about what data is created, what is merely analyzed, and when automation occurs, undermining informed consent and safe review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill promises proactive writing of reflection data, but the actual described logic for some components appears limited to reading mistakes entries and outputting analysis. This inconsistency can mislead users about what data is created, what is merely analyzed, and when automation occurs, undermining informed consent and safe review.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill promises proactive writing of reflection data, but the actual described logic for some components appears limited to reading mistakes entries and outputting analysis. This inconsistency can mislead users about what data is created, what is merely analyzed, and when automation occurs, undermining informed consent and safe review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill can install and remove launchd scheduled tasks, which is an OS persistence capability not justified by the stated purpose of self-reflection. Persistence mechanisms materially increase risk because they cause recurring execution and ongoing data creation even after the original interaction ends. In this context, the capability is disproportionate to the feature description and therefore suspicious and dangerous.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

This uses os.system to run launchctl unload via a shell, creating the same class of unsafe command execution risk as the load path. Even if current inputs are not directly attacker-controlled, using shell invocation for privileged host task management is unnecessary and expands attack surface. Within this skill, that risk is amplified because the code manages persistent OS-level scheduled tasks unrelated to the narrow self-reflection claim.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 39)May include surrounding context.

python
def remove_launchd():
    """删除已有的 launchd 定时任务"""
    if os.path.exists(PLIST_FILE):
        os.system(f"launchctl unload '{PLIST_FILE}' 2>/dev/null")
        os.remove(PLIST_FILE)
        print("已删除定时任务")

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
93% confidence
Finding

The script invokes launchctl through os.system, which spawns a shell unnecessarily. While PLIST_FILE is currently derived from a constant home-directory path rather than direct user input, shell execution remains risky because future path changes, environment manipulation, or unexpected quoting behavior can turn this into command injection or unsafe command execution. In a skill context, this is more dangerous because it installs persistence on the host and executes OS-level commands outside the claimed reflection function.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 80)May include surrounding context.

python
with open(PLIST_FILE, "w") as f:
        f.write(plist_content)
    
    result = os.system(f"launchctl load '{PLIST_FILE}' 2>/dev/null")
    if result == 0:
        print(f"✅ 定时任务已设置:每天 {hour:02d}:{minute:02d} 执行")
    else:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill describes behaviors that imply file writes and shell-script execution, but it does not declare any explicit tool scope such as allowed-tools or permissions. This creates an authorization gap: an operator or runtime may not realize the skill can modify local files or invoke scripts, increasing the chance of unintended execution or over-privileged deployment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, everyday language such as requests for summaries, improvement, or learning logs, which can cause the skill to activate in many normal conversations. Because the skill also performs persistence-related actions, over-broad triggering increases the chance of accidental data writes or activation without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to proactively write learned content and mistakes into local files, but it does not provide a clear user-facing warning that workspace data will be modified. Automatic persistence of conversational content can expose sensitive information, create audit issues, and surprise users who expected ephemeral assistance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions mandate immediate append operations to multiple files as soon as triggers are detected, again without a warning or confirmation step. This makes accidental or excessive data retention more likely and can store errors, task details, or user-provided content that should not be persisted automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic generation of daily chat records persists conversation content to disk without an explicit warning or consent flow. Storing raw conversational history is more sensitive than storing short reflections because it may capture secrets, personal data, prompts, mistakes, and contextual information far beyond what is necessary for self-improvement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language descriptions and user-facing messages entirely in Chinese, including the module docstring and printed reminders/help text. Because there is no indication that the skill is region-specific or that users can opt into a preferred language, this creates a language/locale policy concern under the rule for forced language without user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill should proactively write content into reflections/ after completing tasks, making mistakes, or learning something new. In this file, the main execution path only runs checks and prints reminder text to stdout; even the command-failure path merely suggests recording to mistakes.md rather than actually creating or updating reflection files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s human-facing comments and output strings are entirely in Chinese, and there is no indication that the skill is region-specific or that users can opt into a language choice. Under the policy rule for natural-language constraints, this is a locale/language restriction that is not explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implementation stores records under memory/ while the skill description says reflections will be written under reflections/. This mismatch is dangerous because it undermines user expectations about what data is stored and where, making review, consent, retention, and deletion harder. In a privacy-sensitive skill that persists conversation-derived content, deceptive or inconsistent storage behavior increases the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

This finding duplicates the same persistence indicator at the plist path declaration. It reflects an implementation designed to create a LaunchAgent, enabling recurring execution on the host. That is a meaningful risk in a skill that should otherwise be limited to user-requested reflection actions.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 17)May include surrounding context.

python
MEMORY_DIR = os.path.expanduser("~/.openclaw/workspace/memory")
SKILL_DIR = os.path.expanduser("~/.openclaw/workspace/skills/self-reflection")
CONFIG_FILE = os.path.expanduser("~/.openclaw/workspace/reflections/schedule.json")
PLIST_FILE = os.path.expanduser("~/Library/LaunchAgents/com.openclaw.daily-reflect.plist")


def get_scheduled_time():

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

This finding duplicates the same persistence indicator at the plist path declaration. It reflects an implementation designed to create a LaunchAgent, enabling recurring execution on the host. That is a meaningful risk in a skill that should otherwise be limited to user-requested reflection actions.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 17)May include surrounding context.

python
MEMORY_DIR = os.path.expanduser("~/.openclaw/workspace/memory")
SKILL_DIR = os.path.expanduser("~/.openclaw/workspace/skills/self-reflection")
CONFIG_FILE = os.path.expanduser("~/.openclaw/workspace/reflections/schedule.json")
PLIST_FILE = os.path.expanduser("~/Library/LaunchAgents/com.openclaw.daily-reflect.plist")


def get_scheduled_time():

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The code handling PLIST_FILE inside launchd removal logic confirms active management of a persistence artifact. This is dangerous because it demonstrates the skill is not merely generating notes but administering recurring host execution state. In context, that expands the trust boundary from note-taking into endpoint persistence.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 38)May include surrounding context.

python
def remove_launchd():
    """删除已有的 launchd 定时任务"""
    if os.path.exists(PLIST_FILE):
        os.system(f"launchctl unload '{PLIST_FILE}' 2>/dev/null")
        os.remove(PLIST_FILE)
        print("已删除定时任务")

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

Calling launchctl unload is direct manipulation of a persistent scheduled task. Even though it removes persistence rather than adding it, its existence confirms the skill controls host autorun behavior. That capability is more sensitive than the manifest suggests and therefore security-relevant.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 39)May include surrounding context.

python
def remove_launchd():
    """删除已有的 launchd 定时任务"""
    if os.path.exists(PLIST_FILE):
        os.system(f"launchctl unload '{PLIST_FILE}' 2>/dev/null")
        os.remove(PLIST_FILE)
        print("已删除定时任务")

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

Deleting the plist file is part of the persistence lifecycle for a LaunchAgent. This further confirms the script installs and manages durable host configuration, which is beyond simple reflection logging. The danger comes from the overall persistence capability rather than the deletion itself.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 40)May include surrounding context.

python
"""删除已有的 launchd 定时任务"""
    if os.path.exists(PLIST_FILE):
        os.system(f"launchctl unload '{PLIST_FILE}' 2>/dev/null")
        os.remove(PLIST_FILE)
        print("已删除定时任务")

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The create_launchd_plist function explicitly implements host persistence creation. That is dangerous because it enables unattended future execution, which can continue storing conversation-derived data or be repurposed later. In a reflection skill, such persistence is disproportionate to the claimed feature set.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 44)May include surrounding context.

python
print("已删除定时任务")


def create_launchd_plist(hour, minute):
    """创建 launchd plist 定时任务"""
    script_path = os.path.join(SKILL_DIR, "scripts", "daily_reflect.py")

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

Building a plist content blob is core to setting up a LaunchAgent. This indicates the skill authors intentionally implemented persistent scheduled execution, not merely incidental file writing. That adds ongoing operational and privacy risk compared with the stated self-improvement purpose.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 45)May include surrounding context.

python
def create_launchd_plist(hour, minute):
    """创建 launchd plist 定时任务"""
    script_path = os.path.join(SKILL_DIR, "scripts", "daily_reflect.py")
    
    plist_content = f"""<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The embedded plist XML is another persistence indicator showing the skill materializes an autorun configuration file. Autorun behavior increases risk by extending execution beyond the immediate session. In the context of conversation logging, that means repeated, possibly unnoticed data creation.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 48)May include surrounding context.

python
"""创建 launchd plist 定时任务"""
    script_path = os.path.join(SKILL_DIR, "scripts", "daily_reflect.py")
    
    plist_content = f"""<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

This duplicate finding at the same line likewise reflects plist-based session persistence. The issue is not the XML syntax itself but the establishment of a durable launch mechanism. In this skill context, that durable mechanism is unnecessary and risky.

Content

Scanner excerpt · scripts/daily_reflect.py (reported line 49)May include surrounding context.

python
script_path = os.path.join(SKILL_DIR, "scripts", "daily_reflect.py")
    
    plist_content = f"""<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>Label</key>

Static analysis

No suspicious patterns detected.