Back to skill

Security audit

Task Planner

Security checks for vulnerabilities and agentic risk

Overview

The skill looks like a legitimate task planner, but it needs review because it handles private schedule data, optional audio transcription through OpenAI, and reminder persistence without clear enough scoping or user controls.

Install only if you are comfortable with a planner that stores task details in plaintext files under your home directory and may send voice audio to OpenAI when transcription is used. Prefer a virtual environment with pinned dependencies, review any cron setup before enabling reminders, avoid putting highly sensitive information in task titles or audio, and check the generated calendar/log files and their permissions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:20
Finding

Unpinned Third-Party Dependency Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: README.md:20 and SKILL.md:51-52
Vulnerability Type: Unpinned runtime dependency
Risk Level: Medium

Vulnerable code snippets:

README.md:20

bash
pip3 install openai

SKILL.md:51-52

markdown
- Set the environment variable `OPENAI_API_KEY`
- Install the dependency: `pip install openai`

Technical Analysis

The installation instructions retrieve the latest version of the openai package and its transitive dependencies without specifying reviewed versions or validating package hashes. Consequently, the exact code installed can change independently of this project's reviewed source code.

Python package installation may execute package build or installation logic. If the named package, a transitive dependency, the package registry, or the user's configured package index is compromised, following these instructions could execute attacker-controlled code. Lack of version pinning also introduces compatibility and reproducibility risks even when packages are not malicious.

Attack Path

  1. An attacker compromises a future openai package release, one of its transitive dependencies, or a package index configured on the target system.
  2. A user follows the documented pip install openai or pip3 install openai command.
  3. Pip resolves the mutable, compromised package version because no version or hash is constrained.
  4. Attacker-controlled installation or runtime code executes with the privileges of the account performing the installation.
  5. The malicious dependency can access files, environment variables, and network resources available to that account, potentially including OPENAI_API_KEY.

Impact Assessment

Successful exploitation permits arbitrary code execution with the privileges of the user who installs or runs the dependency. The accessible scope can include the user's home directory, task database, reminder logs, calenda ...[truncated 254 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a dependency file that pins an explicitly reviewed openai release and every transitive dependency.
  2. Generate cryptographic hashes for all approved distributions and require their validation:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Use a lock-file workflow and an isolated virtual environment rather than installing an unconstrained package into the user's global Python environment.
  4. Configure pip to use the official, trusted package index and reject untrusted additional indexes.
  5. Automate dependency vulnerability scanning and review dependency updates before changing the lock file.
  6. Update both README.md and SKILL.md so all documented installation commands use the same pinned, hash-verified dependency manifest.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/task_manager.py:13
Finding

Private Task and Reminder Data Is Stored Without Enforced Owner-Only Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/task_manager.py:13,17-25 and scripts/send_reminders.py:21-23
Vulnerability Type: Insecure permissions for plaintext sensitive data
Risk Level: Low

Vulnerable code snippets:

scripts/task_manager.py:13,17-25

python
DATA_FILE = Path.home() / ".openclaw_tasks.json"

def load_tasks():
    if DATA_FILE.exists():
        with open(DATA_FILE, 'r') as f:
            return json.load(f)
    return {"next_id": 1, "tasks": []}

def save_tasks(data):
    with open(DATA_FILE, 'w') as f:
        json.dump(data, f, indent=2, ensure_ascii=False)

scripts/send_reminders.py:21-23

python
log_path = Path.home() / "openclaw_reminders.log"
with open(log_path, 'a', encoding='utf-8') as f:
    f.write(f"{datetime.now()}: {text}\n")

Technical Analysis

The task database and reminder log may contain private task titles, deadlines, schedules, notes, cinema and seat information, and reminder history. These files are written in plaintext using ordinary open() calls without explicitly setting owner-only permissions.

File permissions therefore depend on the process umask and the permissions of any pre-existing file. Under a permissive umask, newly created files may be readable by the user's group or other local accounts. If a pre-existing file already has unsafe permissions, reopening it does not correct them.

The task database is also overwritten directly rather than being written atomically. Although that primarily creates an integrity and availability risk during interruption or concurrent execution, secure atomic replacement would also provide a reliable point at which restrictive permissions can be applied.

Attack Path

  1. The application runs in an environment with a permissive umask, or the target files already exist with broad read permissions.
  2. A user creates tasks or the reminder process records reminders.
  3. Sensitive sch ...[truncated 950 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create new data and log files with owner-only mode 0600, using os.open with explicit flags and permissions rather than relying solely on the process umask.
  2. Correct permissions on existing files after opening or before use:
    python
    os.chmod(DATA_FILE, 0o600)
    os.chmod(log_path, 0o600)
    
  3. Ensure parent directories are owned by the expected user and are not writable by untrusted local accounts.
  4. Save the task database atomically: write to an owner-only temporary file in the same directory, flush and synchronize it, then replace the destination with os.replace.
  5. Consider file locking because the task manager and scheduled reminder process may access the database concurrently.
  6. Document that these files contain private information and provide a secure deletion or retention policy for reminder logs.
  7. If the threat model includes compromise of the local account or backup storage, consider encrypting sensitive task metadata at rest with keys protected by the operating system credential store.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (18)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises automatic WeChat reminders and voice-to-text using an OpenAI API key, which implies user task content and possibly voice-derived personal data may be transmitted to external services. Because the documentation provides no warning, consent guidance, or data-handling explanation, users may unknowingly expose sensitive schedule, contact, or speech data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 17)May include surrounding context.

安装方法

bash
mkdir -p ~/.openclaw/skills/task-planner
cp -r * ~/.openclaw/skills/task-planner/
openclaw gateway restart
pip3 install openai

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares no permissions or allowed-tools, yet its documentation clearly implies access to environment variables, filesystem writes, and shell execution. This creates hidden capability expansion: a reviewer or runtime may underestimate the skill's power, increasing the chance of unauthorized file creation, command execution, or secret access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad trigger phrases increase the likelihood of accidental invocation during normal conversation. Because the skill can modify tasks, generate files, and potentially engage external processing paths, unintended activation could cause silent state changes or data handling the user did not intend.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list contains ambiguous, generic phrases that are likely to overlap with routine speech, especially in messaging or assistant contexts. In a skill that can create, alter, delete, and export task data, ambiguous matching raises the risk of unintended operations and privacy-impacting outputs.

Content

No source excerpt is available for this finding.

Scope Creep

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims no required permissions while instructing use of an environment-stored API key and external dependency installation. This mismatch hides the true trust and execution requirements of the skill, making it easier to deploy in contexts where credential access and networked processing were not expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill writes a fixed file to ~/openclaw_calendar.md without warning about the destination, overwrite behavior, or sensitivity of the exported contents. This can lead to accidental data disclosure, clobbering of an existing file, or persistence of personal schedule information in an unexpected location.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The task-planning skill includes audio transcription via an external AI API, which expands data exposure beyond the stated scheduling function. Voice messages may contain sensitive personal content, and sending them to a third-party service without tight justification or clear boundary controls introduces unnecessary privacy and supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The voice-input flow omits a clear warning that audio content is transmitted to an external API using stored credentials. Users may reasonably believe they are only interacting locally with a planner, so undisclosed external transmission creates a meaningful privacy and consent failure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function documentation at L17-L18 says it sends a message to WeChat, which implies an external messaging action. However, the actual implementation at L20-L24 only writes the reminder text to a local file in the user's home directory and prints a status message, so the documented intent contradicts the code's real behavior.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/send_reminders.py (reported line 29)May include surrounding context.

python
# TODO: 如果你有企业微信或 itchat,请替换为实际发送代码

def get_reminders():
    result = subprocess.run(
        [sys.executable, str(TASK_MANAGER), "remind"],
        capture_output=True, text=True
    )

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language deadline parsing recognizes Chinese terms such as 今天, 明天, 后天, and 月/日 formats, indicating a language-specific interaction model. There is no visible opt-in, fallback choice, or documented justification for restricting natural-language date handling to this locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The delete_task function removes a task from persistent storage and saves the modified data, which is a destructive operation. In this code path there is no confirmation prompt, warning message, or other user-facing disclosure before the deletion occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and usage instructions are written only in Chinese, and all runtime messages are also Chinese-only. This imposes a specific language on users without offering a choice or documenting a justified locale constraint, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description and trigger phrases are entirely specified in Chinese and present the expected interaction language without any opt-in, alternative language support, or explanation that the skill is intentionally region- or language-specific. This can constitute a language/locale policy issue under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The top-level natural-language documentation is written entirely in Chinese and gives operational guidance only in that language. Under the policy rule for language/locale, this can be a violation when the skill imposes a specific language without user opt-in or an explicit documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill is named and presented as a task planner, but the code additionally writes a calendar document to ~/openclaw_calendar.md. Creating a new export artifact is a broader behavior than basic planning/reminder state management, and it is only partially hinted at in the module docstring rather than the manifest context provided here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The export_doc function writes a calendar document containing task details to ~/openclaw_calendar.md. Although exporting is part of the function name, the code path itself provides no user-facing warning or notice that task content will be written to a file in the user's home directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.