Back to skill

Security audit

TaskFlow 3.0

Security checks for vulnerabilities and agentic risk

Overview

This skill needs Review because it can direct an agent to read local workspace memory or intelligence files and publish derived content externally without clear approval controls.

Install only in a contained workspace and treat this as an automation skill with external posting authority. Review PROJECT.yaml files before use, avoid giving it access to private memory or internal intelligence directories, and require a human preview before any browser-based publication.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

other

Error
Location
scripts/meta-planner.py:199
Finding

Private workspace memory can be published to an external platform

Content
View full analysis
Remediation
View remediation

other

Error
Location
scripts/meta-planner.py:209
Finding

Internal intelligence files can be read and published externally

Content
View full analysis
/dev/null | head -1\\n C. ls -t ~/.openclaw/workspace/intel/vault/ | head -5\\n3. 检查是否已发布(对比history.md主题)\\n4. 如果无新P0情报或都已发布:\\n - 汇报:\\"今日无新P0情报可发布\\"\\n - 正常结束,不执行发布\\n5. 如果有新P0情报:\\n - 读取情报文件,提取核心内容\\n - 生成文章(500-1200字,🔥[情报]格式)\\n - 使用browser工具发布\\n - 更新history.md\\n\\n**重要:每完成一步,简要汇报进度**,完成后汇报:情报标题、发布状态(成功/跳过)", "label": "zsxq-openclaw-camp/post", "runTimeoutSeconds": 600, "streamTo": "parent" }} ``` ``` ### Technical Analysis The generated task searches a hidden alert file and an internal intelligence vault for high-priority intelligence. When content is found, the agent is instructed to read it, extract its core information, create an article, and publish that article externally. A priority designation does not establish authorization for public or third-party disclosure. The implementation contains no classification controls, release flags, source allowlist, redaction policy, or mandatory approval boundary between internal intelligence and external publication. The command also permits fallback selection from recent vault files, increasing the possibility that material not explicitly marked for publication will be processed. ### Attack Path 1. A high-priority alert or intelligence document exists in the local intelligence workspace. 2. The meta-planner generates the external publishing task. 3. The agent reads the hidden alert file or searches the intelligence vault. 4. The agent extracts information from the selected inter ...[truncated 573 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/meta-planner.py:126
Finding

Project metadata is interpolated into a privileged agent prompt without isolation

Content
View full analysis
= {ps['interval_min']} 分钟) - 最佳时段: {', '.join(ps['best_times']) if ps['best_times'] else '全天'}{content_status} """ ``` ### Technical Analysis Values obtained from project configuration, including the project name and preferred publishing times, are concatenated directly into a prompt that also contains operational instructions for an agent. No schema validation, length restriction, escaping, quoting, or trust-boundary marker separates configuration data from instructions. A malicious value can contain line breaks and imperative text that appears structurally equivalent to the planner's legitimate instructions. Because the resulting prompt is intended to drive agent decisions and external browser activity, configuration data ca ...[truncated 1007 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:116
Finding

Free-form workflow entries are treated as executable agent instructions

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/edit-project.py:21
Finding

Unsanitized project identifiers allow directory traversal and configuration overwrite

Content
View full analysis
dict: """加载项目""" project_file = PROJECTS_DIR / project_id / 'PROJECT.yaml' if not project_file.exists(): return None with open(project_file, 'r') as f: return json.load(f) def save_project(project_id: str, data: dict): """保存项目""" project_file = PROJECTS_DIR / project_id / 'PROJECT.yaml' with open(project_file, 'w') as f: json.dump(data, f, indent=2, ensure_ascii=False) ``` The identifier is taken directly from the command line: ```python project_id = sys.argv[1] interactive_edit(project_id) ``` ### Technical Analysis The project identifier is concatenated into a filesystem path without validation or canonical containment checking. Python's `pathlib` preserves traversal components such as `..`, allowing the resulting path to escape `PROJECTS_DIR`. If an escaped destination contains a file named `PROJECT.yaml`, the editor can read it. After interactive confirmation, `save_project()` can overwrite that file with serialized JSON. The confirmation prompt does not mitigate the vulnerability because it does not show or validate the canonical destination path, and a user can be induced to approve what appears to be a normal project edit. Similar unsanitized path construction is present in project-loading functions in the scheduler and meta-planner, although the command-line editor provides the clearest direct attack surface. ### Attack Path 1. An attacker or misled local user invokes the editor with a traversal identifier such as `../../target-directory`. 2. `PROJECTS_DIR / project_id / 'PROJECT.yaml'` resolves outside the intended projects directory. 3. `load_project()` reads the escaped target if it exists and contains valid JSON. 4. The interactive workflow asks for and receives confirmation. 5 ...[truncated 589 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

PyYAML is installed without a version or integrity constraint

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a workflow execution engine/scheduler for project tasks. The supplied code does something materially different: it is a human-in-the-loop project configuration editor. Its primary behavior is displaying and modifying project configuration text, not executing workflows. Several key declared behaviors are absent, including parsing workflow structure, sequential execution of workflow steps, and writing execution records to memory/executions.json. It also accesses the project file via a fixed ~/.openclaw/workspace/projects path instead of the runtime-determined workspace/project path described. Finally, despite the filename PROJECT.yaml, it reads and writes using json.load/json.dump, which is inconsistent with the declared YAML-based project configuration handling. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a generic per-project task execution system: load one PROJECT.yaml, parse meta/content/target/constraints/workflow, execute workflow steps sequentially, and log results to memory/executions.json. The supplied code instead acts as a global meta-planner for publication scheduling. It enumerates enabled projects under a hardcoded workspace, reads history.md posting logs, checks an external intel state file, computes posting cadence/status, and emits a natural-language prompt instructing an agent how to choose and publish content for specific projects. There is no implementation of workflow.step_by_step execution, no parsing or use of content/target/workflow fields for task execution, and no writing to memory/executions.json. The accessed resources and primary purpose are materially different from the declared behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents an agent-native task execution engine: read PROJECT.yaml, parse several sections including workflow, execute steps in order, and persist execution records. The supplied code instead acts as a reporting/status utility for publishing projects. It enumerates enabled projects from a fixed ~/.openclaw/workspace-zsxq/projects path, reads constraints such as daily_max/daily_min/source_project, inspects history.md and republished.json to count today's posts and republished items, and prints status summaries for 'run-projects' or 'status' commands. There is no workflow execution, no step runner, no writing of executions.json, and no runtime path resolution logic matching the description. The primary purpose is therefore materially different from the declared task scheduler behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code opens PROJECT.yaml but parses it with json.load, creating a mismatch between documented format and implementation. This can cause parsing failures, denial of service for scheduling, or unsafe assumptions if malformed or attacker-crafted content is introduced and the planner silently skips projects or behaves unpredictably.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/meta-planner.py (reported line 229)May include surrounding context.

python
- Agent自主决策,不要问我
"""
    
    return prompt

def main():
    """Meta-Planner入口"""

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and agent instructions describe a task scheduler that reads PROJECT.yaml, parses workflow definitions, executes workflow.step_by_step sequentially, and records execution to memory/executions.json. In this file, the main runtime path merely enumerates projects, reads posting-history metadata, computes pending counts, and prints status; it never parses workflow content, executes steps, or writes execution records.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill describes shell commands, filesystem reads/writes, and workspace-wide logging, but declares no explicit tool scope or permission boundaries. In an agent environment, this can cause the skill to run with broader-than-necessary capabilities, increasing the chance of unintended file modification, command execution, or access to unrelated workspace data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the agent to execute workflow steps and record results to project memory without clearly warning that it will modify project data. In agentic systems, silent write behavior increases the risk of unintended state changes, destructive actions, or compliance issues when users believe the skill is read-only or purely advisory.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation first states that all PROJECT.yaml paths are relative to project root, then later authorizes absolute and home-directory paths. This inconsistency makes it easier for downstream implementations or agents to honor the more permissive rule, which can lead to out-of-scope file access and bypass of intended path restrictions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The path resolution rules explicitly permit absolute paths and home-directory paths even though the skill is framed around project-root-relative files. That weakens containment and allows a PROJECT.yaml or workflow step to reference files outside the project boundary, enabling unauthorized reads or writes elsewhere on the host or workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill appends execution details to a workspace-wide global log file, but this side effect is not clearly surfaced in the high-level description. Hidden cross-project writes can leak project identifiers, statuses, and paths, and they broaden the blast radius from a single project to the whole workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language instructions, examples, and interactive prompts exclusively in Chinese, including the tool description and workflow. Under the policy, forcing a specific language without offering a user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring says the tool reads and modifies PROJECT.yaml, and load_project/save_project are documented as loading and saving the project. However, the code uses json.load and json.dump on that .yaml file path, which contradicts the stated behavior and would not preserve or correctly handle YAML-formatted project files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file-level description and all user-facing prompt content are written exclusively in Chinese, and the generated instructions require downstream agents to report progress and results in Chinese. There is no user opt-in, language selection mechanism, or documented reason that this skill must operate only in Chinese, which creates a locale-policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script hardcodes workspace and project locations under the user home directory instead of deriving them at runtime from the manifest rules. This can make the agent operate on the wrong workspace, bypass intended sandboxing, and unexpectedly access or modify data outside the declared project scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The meta-planner reads workspace-wide state from ~/.openclaw/workspace/intel/state.json, which bypasses the skill’s stated per-project execution model and expands data access beyond the current project root. In an agent setting, this weakens isolation boundaries and can cause cross-project data leakage or decisions based on unrelated sensitive workspace contents.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The docstring presents this function as the scheduler entrypoint, yet its behavior is limited to status aggregation and console output. Given the surrounding skill intent, this documentation is misleading because it frames a reporting routine as the operative scheduler without executing workflows or recording runs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The package and skill descriptions are written in Chinese, and the manifest does not indicate that the skill is region-specific or that users can choose another language. This can violate language/locale policy expectations when skills are expected to be usable without forcing a specific language absent opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's primary natural-language documentation is entirely in Chinese, including the title and operational descriptions, with no indication that language choice is configurable or intentionally region-specific. This can violate a language/locale policy when users are not offered an alternative or explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.