Back to skill

Security audit

RiskOfficer

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed RiskOfficer integration for portfolio analytics and virtual portfolio management, with sensitive account-token use and destructive API actions that users should handle carefully.

Install only if you trust RiskOfficer and are comfortable giving this skill an account-level RiskOfficer token. Prefer a session environment variable over saving the token in openclaw.json, revoke the token when done, and review confirmations carefully before allowing portfolio deletes, broker snapshot deletion, optimization apply, or broker disconnect actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (69)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The documentation exposes a destructive parameterized deletion path for broker portfolio snapshots on live accounts (sandbox=false), creating a real risk of tool misuse if an agent populates parameters incorrectly or is prompt-influenced into targeting production data. Because these are authenticated external API actions, a parameter mix-up can cause irreversible account-state changes.

Content

Scanner excerpt · SKILL.md (reported line 383)May include surrounding context.

md
- `sandbox=false` for live connection, `sandbox=true` for sandbox
- Removes the connection and its saved API key; portfolio snapshot **history is preserved**
- To also delete snapshot history, first use `DELETE /portfolio/broker/{broker}?sandbox=false`
- **ALWAYS confirm before disconnecting** — reconnection requires the mobile app

**Difference between the two delete endpoints:**

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The paired broker connection deletion endpoint can remove saved broker connectivity, and its similarity to snapshot-deletion operations makes parameter/tool confusion plausible. In an agent workflow, wrong-endpoint selection is a meaningful security and integrity risk because it can sever access and require manual mobile-app reconfiguration.

Content

Scanner excerpt · SKILL.md (reported line 388)May include surrounding context.

md
**Difference between the two delete endpoints:**

| Action | DELETE /portfolio/broker/{id} | DELETE /brokers/connections/{id} |
|--------|-------------------------------|----------------------------------|
| Deletes snapshots | ✅ Yes (archives history) | ❌ No (history kept) |
| Deletes connection | ❌ No | ✅ Yes |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The paired broker connection deletion endpoint can remove saved broker connectivity, and its similarity to snapshot-deletion operations makes parameter/tool confusion plausible. In an agent workflow, wrong-endpoint selection is a meaningful security and integrity risk because it can sever access and require manual mobile-app reconfiguration.

Content

Scanner excerpt · SKILL.md (reported line 388)May include surrounding context.

md
**Difference between the two delete endpoints:**

| Action | DELETE /portfolio/broker/{id} | DELETE /brokers/connections/{id} |
|--------|-------------------------------|----------------------------------|
| Deletes snapshots | ✅ Yes (archives history) | ❌ No (history kept) |
| Deletes connection | ❌ No | ✅ Yes |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 1031)May include surrounding context.

md
→ `GET /portfolio/history?days=45` → find snapshot from ~30 days ago
→ `PATCH /portfolio/active-snapshot` with that `snapshot_id` and `portfolio_key`
→ `POST /risk/calculate-var` → poll → present results
→ Offer to reset: `DELETE /portfolio/active-snapshot`

### User tries to mix currencies
"Add Apple to my RUB portfolio"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The example demonstrates an irreversible DELETE action keyed by portfolio name, which is vulnerable to mistaken targeting, name ambiguity, or prompt-induced destructive use. Because all snapshots for the named manual portfolio are archived and cannot be undone, misuse can cause permanent loss of analysis history.

Content

Scanner excerpt · SKILL.md (reported line 1048)May include surrounding context.

md
### User wants to delete a portfolio
"Delete my test portfolio" / "Удали портфель 'Тест'"
→ Confirm: "This will permanently delete all N snapshots for 'Test'. Cannot be undone. Continue?"
→ On confirmation: `DELETE /portfolio/manual/Test`
→ Report `archived_snapshots` count

### User wants to disconnect a broker

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This example shows a live broker disconnect action (sandbox=false) that removes the connection and saved API key, making it a meaningful destructive account-management operation. In agent settings, such actions are sensitive because a misfire or adversarial prompt could silently sever financial-data integrations.

Content

Scanner excerpt · SKILL.md (reported line 1054)May include surrounding context.

md
### User wants to disconnect a broker
"Disconnect Tinkoff" / "Отключи Тинькофф"
→ Confirm: "This will remove the Tinkoff connection. Portfolio history will be kept. Continue?"
→ On confirmation: `DELETE /brokers/connections/tinkoff?sandbox=false`
→ Inform that reconnection requires the mobile app

### User wants Black-Litterman optimization

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 5)May include surrounding context.

md
Manage investment portfolios, calculate risk metrics (VaR, Monte Carlo, Stress Tests), and optimize allocations using Risk Parity, Calmar, or Black-Litterman — all through natural language chat. Includes pre-trade risk checks with sector concentration limits and cross-portfolio correlation analysis.

**Required:** One env var — `RISK_OFFICER_TOKEN` (create in RiskOfficer app → Settings → API Keys).  
**Source:** [github.com/mib424242/riskofficer-openclaw-skill](https://github.com/mib424242/riskofficer-openclaw-skill) · [riskofficer.tech](https://riskofficer.tech)

## Features

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises portfolio deletion and broker disconnect capabilities without any explicit warning that these are state-changing actions with potential data/account impact. In an agentic chat setting, users may invoke such operations casually or ambiguously, increasing the risk of unintended destructive changes if the skill or host agent does not enforce confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage examples include "Delete my test portfolio" and "Disconnect Tinkoff broker" as natural-language commands without any nearby caution or confirmation guidance. In a conversational interface, examples shape user expectations and can normalize unsafe direct execution of destructive commands, raising the chance of accidental loss of portfolio data or service access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is very broad and includes many generic finance and portfolio-management phrases, increasing the chance that the skill is auto-invoked for loosely related user requests. Because the skill can read portfolio data and perform modifying or destructive actions against an external API, over-broad routing materially raises the risk of unintended sensitive operations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill instructs users to persist a powerful account-level token in environment variables or ~/.openclaw/openclaw.json, and later notes tokens are not scoped. Persisting a non-scoped token in agent-accessible config materially increases the blast radius if local files, logs, or other skills are compromised.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
Connects to the RiskOfficer API to manage investment portfolios and calculate financial risk metrics.

**Required:** One environment variable — `RISK_OFFICER_TOKEN` (create in RiskOfficer app → Settings → API Keys). No other env vars or binaries are required.

**Source:** Official skill repository: [github.com/mib424242/riskofficer-openclaw-skill](https://github.com/mib424242/riskofficer-openclaw-skill). Product: [riskofficer.tech](https://riskofficer.tech). The token is issued only by the RiskOfficer app; this skill does not collect or store credentials.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documented API base URL and bearer-token requirement establish that all skill operations depend on sending authenticated requests to an external service. In a finance skill, this means sensitive portfolio metadata and account operations are delegated to a third party, making transmission itself security-significant.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

API Base URL

text
https://api.riskofficer.tech/api/v1

All requests require: Authorization: Bearer ${RISK_OFFICER_TOKEN}

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This skill sends user queries and an account bearer token to an external service, which is a real external data transmission of potentially sensitive financial interest data. In this skill's context, ticker searches can reveal user intent, and elsewhere the same token authorizes access to portfolio data and modifications, so unscoped external transmission is security-relevant.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

Use this before creating or editing any portfolio to validate ticker symbols and get their currency/exchange info. Also use when the user mentions a company name instead of a ticker.

bash
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Apple&limit=10&locale=en" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This skill sends user queries and an account bearer token to an external service, which is a real external data transmission of potentially sensitive financial interest data. In this skill's context, ticker searches can reveal user intent, and elsewhere the same token authorizes access to portfolio data and modifications, so unscoped external transmission is security-relevant.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

Use this before creating or editing any portfolio to validate ticker symbols and get their currency/exchange info. Also use when the user mentions a company name instead of a ticker.

bash
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Apple&limit=10&locale=en" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

bash
# Search by company name (English)
curl -s "https://api.riskofficer.tech/api/v1/tickers/search?q=Gazprom&locale=en&limit=5" \
  -H "Authorization: Bearer ${RISK_OFFICER_TOKEN}"

# Search by Russian name

Static analysis

No suspicious patterns detected.