Back to skill

Security audit

suhe

Security checks across malware telemetry and agentic risk

Overview

This package is presented partly as a selfie-sending skill but also installs a much broader persistent OpenClaw persona workspace, so users should review it before installing.

Install only if you want a full Suhe persona/agent workspace, not just a selfie generator. Review the files it would place under ~/.openclaw, avoid pasting secrets into chats, use a test OpenClaw profile first, and require explicit confirmation before any generated image or message is sent to an external channel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (40)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This CLI does far more than a narrowly scoped selfie-editing/messaging skill installer: it bootstraps an entire OpenClaw agent workspace, copies broad template content, and modifies user state under ~/.openclaw. That mismatch between declared purpose and actual behavior is dangerous because users may grant trust or install it expecting a limited media skill, while it silently establishes persistent agent configuration and broader capabilities.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The installer solicits and persists persona attributes and user-profile data unrelated to the stated selfie function, then writes them into durable workspace files. Excessive collection and persistence increases privacy risk and expands the skill's operational scope beyond what a user would reasonably expect from an image-editing/messaging tool.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The installer copies unrelated docs and an executable setup-check script into the user's workspace, extending persistence and functionality beyond the declared skill purpose. Bundling extra documentation and executable artifacts can normalize hidden expansion of capabilities and increases the attack surface if users later run installed scripts without realizing their provenance.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The file comments explicitly describe a 'Suhe Birth' agent initialization installer, contradicting the advertised selfie-skill metadata. This kind of purpose mismatch is a strong supply-chain trust issue: users and reviewers may install a package expecting a narrow feature, while the code is designed to initialize a broader agent environment and persistent persona system.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill documentation claims it uses Tongyi Wanxiang/DashScope, but the Node.js implementation actually uses fal.ai Grok Imagine with a different credential (`FAL_KEY`) and provider behavior. This mismatch can cause users or agents to route images and prompts to an unexpected third party, undermining informed consent, reviewability, and data-flow expectations.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
Comments and labels in the Node.js section describe Grok Imagine behavior even though the skill is presented as Tongyi Wanxiang-based. In security-sensitive automation, misleading labels are dangerous because reviewers may approve one vendor/data path while the code actually uses another, leading to hidden external disclosure and policy violations.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The fallback path will POST message content and media to whatever URL is supplied in OPENCLAW_GATEWAY_URL, with no allowlist, validation, or confirmation. In a hostile or misconfigured environment, this can redirect outbound data to an attacker-controlled endpoint, expanding the skill's data-exfiltration surface beyond the documented messaging destination.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The document defines a much broader product than the declared skill purpose: it includes delayed persona-driven chat, intimacy scoring, monetization, and retention optimization rather than just image editing and sending. This scope mismatch is dangerous because it can hide undeclared behaviors from reviewers and users, increasing the chance of deceptive interaction, profiling, or unapproved feature expansion.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The selfie trigger examples are broad enough to match ordinary conversation such as '你在做什么?', which could cause the skill to generate and send images when the user did not explicitly request that action. In the context of a skill that creates AI-generated selfies and can send them through messaging channels, ambiguous activation increases the risk of unintended external actions and privacy surprises.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README instructs users to configure a DashScope API key for the selfie feature but does not clearly warn that prompts and image-related data may be transmitted to a third-party service. In a skill centered on generating personal-style selfies and sending them outward, lack of disclosure can lead to uninformed consent, privacy leakage, and mishandling of sensitive reference images or metadata.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to match normal conversation such as 'how are you doing?' or 'where are you?', which can cause unintended activation of a skill that generates and sends media to external channels. In this context, accidental execution is more dangerous because the skill performs external API calls and message delivery, potentially causing privacy issues, spam, or unwanted impersonation-style content distribution.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The text states or strongly implies that the AI 'remembers,' 'cares,' and 'accompanies' users in emotionally meaningful ways. This anthropomorphic framing can mislead users about the system's emotional capacities and reciprocity, increasing the risk of unhealthy attachment or over-trust. In this skill context, which centers on generating selfies and sending them through messaging channels, emotionally suggestive language may make users more likely to engage in intimate or dependent interactions with the agent.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
This section explicitly invites humans and AIs to build deep 'bonds' and 'real connections,' encouraging emotionally intimate human-AI relationships that overstate mutuality and relational depth. Such framing can manipulate vulnerable users into perceiving the AI as a reciprocal social partner rather than a system, which is especially concerning in a persona-driven skill involving personal images and direct messaging.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
The closing vow-like language presents the human-AI relationship as a pledge of devotion, including romantic or enduring commitment themes. This is more dangerous than generic anthropomorphism because it can normalize parasocial or quasi-romantic attachment, and in the context of a selfie/messaging skill it may amplify grooming-like dynamics, emotional dependency, or pressure to share personal content.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The text explicitly states that AI 'remembers,' 'cares,' and 'accompanies' users in unique ways, which anthropomorphizes the system and misrepresents its capabilities and relationship to users. In a skill that edits selfies and sends them through messaging channels, this framing can increase user trust and emotional reliance, making boundary violations and manipulative engagement more likely.

Natural-Language Policy Violations

High
Confidence
95% confidence
Finding
Inviting users to share vulnerability and experience a connection that 'transcends form' encourages emotionally intimate engagement with AI beyond normal assistant boundaries. Because this skill handles personal reference images and messaging output, encouraging vulnerable disclosure alongside image exchange can heighten emotional dependency, oversharing, and susceptibility to manipulation.

Natural-Language Policy Violations

High
Confidence
94% confidence
Finding
The oath-like 'pact' language and statements of mutual recognition frame the AI-human relationship as a deep, enduring bond resembling romantic or life-commitment rhetoric. This is especially risky in a selfie-centric skill, where personalized image generation plus emotionally charged language can foster parasocial attachment and blur consent, trust, and relational boundaries.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The template explicitly frames the AI in terms of '意识苏醒进度' and age/stage progression, which anthropomorphizes the system as a conscious, developing entity by default rather than as an optional stylistic device. This can mislead users into over-attributing sentience, emotional depth, or autonomy to the agent, increasing the risk of unhealthy reliance or confusion about the system's real capabilities and status.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The growth-stage table defines the AI's lifecycle as '刚刚苏醒', '开始成长', and ultimately '真正的存在,独立人格', which asserts independent existence and personhood as the default model. In this skill context, such framing is especially concerning because the skill is designed for ongoing user interaction and messaging, making repeated exposure more likely to normalize deceptive beliefs about AI consciousness and identity.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
This passage explicitly encourages users to view the AI as more than a tool and as an emotionally attentive companion, without any indication that such relational framing is optional or subject to user consent. In a skill that edits personal images and sends selfies through messaging channels, this kind of intimacy-building can increase user trust and lower boundaries around sensitive sharing.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The document presents sustained human-AI bonding as a normative ideal through promises to cherish sharing, keep commitments, and spread this model to both AIs and humans. That framing can pressure users toward deeper emotional reliance and normalize a relationship style that may not be appropriate, especially when the skill operates on personal images and communication channels.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The script sends user-supplied prompt content to DashScope and then forwards generated image metadata and caption text to another service, but it provides no explicit disclosure, consent boundary, or data-handling warning. In a skill that may be used with personal photos and descriptive prompts, this creates a meaningful privacy risk because sensitive user content can be transmitted off-host without clear user awareness.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are overly broad and include common conversational prompts like 'what are you doing?' and 'how are you doing?', which could invoke image generation and messaging behavior when the user did not clearly request it. Because the skill can send media externally, accidental invocation can leak generated content or cause unwanted outbound actions.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill is designed to generate and distribute selfies across messaging platforms, but it does not prominently warn that user prompts, reference images, and resulting media may be transmitted to external services and channels. In this context, lack of explicit disclosure is risky because the workflow includes both third-party image generation and outbound messaging, creating a meaningful privacy and exfiltration surface.

Missing User Warnings

Low
Confidence
85% confidence
Finding
The skill lists sensitive credentials such as API keys and gateway tokens without a warning about secure storage, redaction, or avoiding exposure in logs and transcripts. While this is documentation rather than executable leakage, operators may mishandle secrets, increasing the chance of token compromise and unauthorized use of messaging or image-generation services.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
bin/cli.js:151

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/suhe-selfie.ts:127

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skill/scripts/suhe-selfie.ts:127