Back to skill

Security audit

Testcase Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it can overwrite existing test-case spreadsheets and persist PRD-derived files locally without strong safeguards, so it belongs in Review before installation.

Install only if you are comfortable with a Chinese-language testcase workflow that reads local PRDs and configured Excel case libraries, writes generated files and PRD-derived notes under ~/.openclaw/workspace, and may update configured case-library spreadsheets in place. Use backups before running updates, review product config paths, avoid untrusted PRD content in generated spreadsheets, and inspect generated files before opening them in Excel.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/case_generator.py:88
Finding

Spreadsheet Formula Injection in Generated Excel Workbooks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/case_generator.py:110
Finding

Output Path Traversal Through Unsanitized Requirement Name

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/version_manager.py:58
Finding

Product Identifier Path Traversal Can Load Out-of-Root Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the actual skill modifies existing case-library Excel files and local metadata instead of generating separate output files as documented, users may authorize a seemingly safe export workflow while the skill performs destructive in-place changes. That mismatch can lead to silent corruption of trusted test repositories or unintended persistence of user data.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the actual skill modifies existing case-library Excel files and local metadata instead of generating separate output files as documented, users may authorize a seemingly safe export workflow while the skill performs destructive in-place changes. That mismatch can lead to silent corruption of trusted test repositories or unintended persistence of user data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and examples are entirely in Chinese and present the workflow as Chinese-only, with no indication that users may choose another language. This can violate language/locale policy when a specific language is imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes file reads and writes across the user's home/workspace but does not declare any explicit tool scope or permissions boundaries. This creates an authorization gap where a caller may not understand that the skill can access and persist local files, increasing the chance of unintended data exposure or modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are generic requests like '帮我写测试用例' and '分析这个需求的测试点', which can match ordinary conversations too broadly. In a skill with file access and persistent writes, overbroad activation increases the risk that the skill runs unexpectedly on sensitive PRDs or creates files without the user realizing a side-effecting workflow was invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill specifies creating multiple markdown and Excel files under the user's workspace, but it does not present a clear upfront warning that execution will persist potentially sensitive PRD content and derived analysis. Users may disclose confidential product plans assuming transient processing, while the skill silently leaves recoverable artifacts on disk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions direct the skill to save PRD summaries, test-point analyses, and comparison reports into a long-lived workspace under the user's home directory. PRDs often contain unreleased features, pricing, interfaces, or customer-specific details, so persisting this content by default increases the chance of later disclosure to other tools, users, backups, or compromised local environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The format rules require Chinese full-width brackets and Chinese numbering/style conventions, effectively forcing a specific language/locale in the skill output. Because the document does not offer user opt-in or explain that the skill is intentionally limited to a Chinese-language test-case environment, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Natural-language content in the file—including the main docstring and inline usage guidance—appears exclusively in Chinese, with no indication that the skill is intentionally limited to a Chinese-speaking audience or that users can opt into another language. The policy requires avoiding forced language or locale unless it is optional or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing natural-language instructions entirely in Chinese, including the top-level usage docstring and later CLI descriptions, but it does not offer any language selection or indicate that the tool is intentionally limited to a Chinese-speaking audience. That can violate a language/locale policy requiring user choice rather than forcing a specific language by default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

技能清单描述强调的是基于已有用例库和 PRD 进行分析并生成新增/更新两个 Excel 结果文件,而本文件提供的是对既有用例库按 UUID 直接覆盖并保存到原文件的版本管理能力。此外,L139-L142 还会将版本信息写入用户主目录下的元数据文件,这属于额外的持久化副作用,不是描述中显式声明的产出。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

manifest 描述的核心目标是生成并区分新增、更新的用例结果文件;而 update_library 会直接打开目标 Excel 用例库、按 UUID 覆盖内容并保存回原路径。这种维护主数据源的写操作更像后台库管理能力,而不是单纯生成输出文件所必需的能力。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The update operation directly overwrites and appends rows in the configured workbook and saves back to the original path with no confirmation, backup, rollback, or integrity validation. In a skill ecosystem where actions may be triggered by user-provided files or automated agent flows, this increases the risk of silent data corruption or irreversible modification of a shared testcase library.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown states that output files are saved to ~/.openclaw/workspace/, which is a user-data affecting operation. While the destination is documented, there is no explicit warning or caution about creating files there or potential overwrites/conflicts with existing files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document mandates Chinese-specific conventions such as full-width Chinese brackets and Chinese naming/path conventions, but it does not state that this applies only in a Chinese-language or region-specific workflow. Under the policy, forcing a specific language or locale without opt-in or clear justification can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code performs a filesystem write by saving a generated workbook to a path under the user's workspace, but there is no confirmation prompt, logging, or explicit warning in the function before the write occurs. For code files, file writes should have some form of user disclosure unless the behavior is clearly surfaced; here the side effect is only implied by the function name and docstring, not actively disclosed at execution time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function creates directories and writes an output .xlsx file, but it does so silently with no user-facing print/log message or confirmation around the file write. Under the code-file criteria, safety-relevant file writes lacking any visible disclosure should be flagged.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

文件头部文档明确声明这是“用例库版本管理工具”,并列出接收增量更新文件、按 UUID 覆盖现有用例等功能;这与技能清单中“针对已有用例库和 PRD 分析交互,最终输出生成的用例”的生成型定位存在明显意图偏移。虽然文档与代码本身一致,但它主动呈现了与技能对外宣称不同的用途。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.