Back to skill

Security audit

Recipe Manager

Security checks for vulnerabilities and agentic risk

Overview

This recipe-management skill is coherent and purpose-aligned, but users should be aware that it stores local recipe data, can delete entries, and exports spreadsheet files without formula sanitization.

Install only if you are comfortable with the skill keeping a local recipe database in your home directory and creating export files there. Confirm delete/export requests carefully, and treat exported spreadsheets as untrusted if recipe text may come from other people because formula-like values are not sanitized.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/recipe_manager.py:87
Finding

Spreadsheet Formula Injection in CSV and Excel Exports

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
README.md:27
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

从该代码片段看,实际行为是配方数据导出,而不是完整的“商用原料配方库”管理与成本计算。导出 CSV/Excel 与声明中的一部分能力一致,但声明强调的核心能力还包括录入配方、调取标准配比、成本计算、多版本管理等,这些在片段中均未体现。虽然单个文件可能只是导出模块,但按本次比对,当前代码块的实际功能范围明显窄于声明。此外,脚本末尾调用了未定义的 export_to_excel(),说明该导出代码本身还存在运行问题。综合判断,描述与此代码块并不准确对应。

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

安装方法

bash
mkdir -p ~/.openclaw/skills/recipe-manager
cp -r * ~/.openclaw/skills/recipe-manager/
openclaw gateway restart
pip3 install pandas openpyxl  # 可选,用于导出 Excel

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill advertises behavior that implies file creation/export and possibly code-assisted operations, but it declares no explicit tool scope or permission boundaries. When a skill can read/write files or invoke shell-like capabilities without a documented allowlist, the runtime may grant broader access than users expect, increasing the risk of unauthorized file access or unsafe command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are overly broad and overlap with ordinary conversation about recipes, ingredients, and cost. This can cause accidental invocation, leading the assistant to perform state-changing actions such as recording recipes or exporting data when the user may have intended only a general discussion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes modification and deletion of recipe data plus CSV export, but it does not warn users before changing stored data or creating files. In practice, this can lead to unintended overwrites, silent data loss, or unanticipated file generation on the host system, especially when paired with ambiguous triggers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code exports recipe data to a CSV file in the user's home directory and then writes an Excel file, but the script provides no prior confirmation, warning message, docstring, or explanatory comment about these file-creation side effects. For code files, file writes affecting user data should have some visible disclosure unless clearly documented as part of the skill's stated purpose within the file or accompanying markdown.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export_excel.py (reported line 9)May include surrounding context.

python
manager = Path(__file__).parent / "recipe_manager.py"
csv_path = Path.home() / "recipes_export.csv"
subprocess.run([sys.executable, str(manager), "export", "--output", str(csv_path)], check=True)

try:
    import pandas as pd

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script exposes a destructive delete capability that is not disclosed in the skill metadata or stated capabilities. In an agent setting, hidden capabilities are risky because users or orchestrators may invoke the skill assuming it only stores, retrieves, calculates, and exports recipes, while it can also permanently remove data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Recipe deletion happens immediately once an ID is provided, with no confirmation, dry-run, recycle bin, or undo path. In a conversational or agent-driven workflow, this increases the chance of accidental or induced data loss from ambiguous prompts, wrong IDs, or prompt-injection-driven tool use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

All user-facing description, triggers, examples, and notes are written only in Chinese, and the trigger model appears to assume Chinese input exclusively. The file does not state that the skill is region-specific or offer an opt-in language/locale choice, which may violate language-choice policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The warning message uses Chinese only ("pandas未安装") with no indication that the skill is intentionally locale-specific or that users can opt into a language. This is a natural-language policy concern because the file imposes a specific language in user-facing output without justification or choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script's structure implies it can be run directly via the main guard, but L21 calls export_to_excel(), which is never defined anywhere in the file. This is an intent-code divergence in the file's own execution path: the file appears documented-by-structure as a runnable exporter, but it will raise a NameError instead of performing export logic when invoked normally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring and user-facing CSV headers and parsing behavior are written specifically for Chinese usage, and the script assumes Chinese currency/unit expressions such as '元/斤'. There is no indication that language or locale is selectable or that the Chinese-only behavior is a documented regional specialization.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.