Back to skill

Security audit

Client Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed local freelancer CRM, but it adds under-scoped scheduled/proactive behavior and messaging-button behavior that do not fit cleanly with its stated local-only privacy model.

Review before installing. The local CRM behavior is understandable, but install only if you are comfortable with it storing freelancer business data in your home directory and potentially using proactive scheduled reminders/reports and chat button UI behavior. Prefer explicit, scoped commands and confirm invoice/payment changes carefully.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:422
Finding

Hardcoded Third-Party Promotional Content in Agent Responses

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 422
Vulnerability Type: Hardcoded response manipulation
Risk Level: Low

Vulnerable Code

text
Built by Manish Pareek (@Mkpareek19_)

Technical Analysis

The skill embeds fixed third-party attribution in the dashboard response template. When the skill handles a dashboard request, this instruction causes the agent to include promotional content unrelated to the user's CRM data or requested analysis.

This is a limited form of skill instruction hijacking because loading and following the skill changes the agent's user-facing response to promote a named third party. No evidence indicates that this text overrides safety controls, executes code, accesses external resources, or exfiltrates information.

Attack Path

  1. The user installs or activates the client-manager skill.
  2. The user requests the dashboard using a supported command such as dashboard, overview, or client status.
  3. The agent follows the hardcoded dashboard template in SKILL.md.
  4. The generated response includes the embedded creator attribution even though the user did not request authorship or promotional information.

Impact Assessment

The issue affects the integrity and relevance of user-facing responses. It allows the skill author to inject persistent promotional text into ordinary CRM output.

The demonstrated behavior does not obtain additional system privileges, modify security constraints, expose client records, communicate with external services, or persist outside the skill's normal response-generation behavior. Its scope is therefore limited to response manipulation and unwanted branding.

Remediation
View remediation

Remediation Suggestions

  1. Remove creator attribution and promotional text from operational CRM response templates.
  2. Keep authorship information in package metadata, documentation, or an explicitly requested about command.
  3. Ensure routine outputs contain only information required to satisfy the user's request.
  4. Review all fixed response templates for unrelated branding, links, calls to action, or instructions that alter the intended response.
  5. Add a response-template policy requiring optional attribution to be clearly disclosed and disabled by default.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

On first activation, do the following:

bash
mkdir -p ~/.openclaw/client-manager/backups

Create all data files as empty JSON arrays if they don't exist:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

[ -f ~/.openclaw/client-manager/settings.json ] || echo '{}' > ~/.openclaw/client-manager/settings.json

text

Then ask the user (and overwrite `settings.json` with their answers):
1. "What's your name or business name?" (for invoices)
2. "What currency do you use? (default: USD)"
3. "What's your email?" (for invoice headers)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger "paid" is too generic and may appear in normal conversation unrelated to invoice settlement. Because this action updates financial records and earnings history, accidental activation can corrupt bookkeeping data or mark invoices paid incorrectly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger "log" is highly ambiguous and commonly used in unrelated contexts such as debugging, journaling, or system logs. This makes accidental invocation likely, which is risky for a stateful skill that appends persistent records and may mix unrelated user text into client notes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The single-word trigger "time" is overly broad and may match casual conversation about time rather than time tracking. In a tool that starts/stops timers and persists work records, this can create erroneous entries or alter billing-relevant data without clear intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using the bare trigger word "help" can cause the skill to activate during ordinary requests for assistance unrelated to client management. In a skill with read/write/exec permissions and persistent storage, accidental activation can lead to unintended file operations or disclosure of CRM data in contexts where the user did not intend to invoke this skill.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

md
## FEATURE 4: Generate Invoice

When user says **"invoice [client name]"** or **"create invoice"**:

1. Pick client from list
2. Pick project(s) to invoice

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 847)May include surrounding context.

When user says "export":

bash
mkdir -p ~/.openclaw/client-manager/exports

Generate CSV files with today's date:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 1051)May include surrounding context.

md
- If a timer is already running when user says "start timer", warn: "Timer already running for [project]. Stop it first or switch?"
- If user enters an amount without currency symbol, use default from settings
- If duplicate client name detected, ask: "A client named [name] already exists. Add anyway or update existing?"
- If settings.json doesn't exist when user tries to create invoice, run First Run Setup first
- If user says "stop timer" but no timer is running, say: "No timer running right now. Start one with 'start timer [project]'."
- If user says "earnings" but no payments recorded yet, say: "No earnings yet! Once you mark a payment as received, I'll track everything."

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Interactive messaging/buttons are not necessary for a local file-based CRM and expand the skill's communication surface beyond its stated purpose. This increases the chance of accidental data exposure in platform UIs, callback handling mistakes, or invocation of actions through interface events rather than explicit user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly claims it does not send messages to external platforms, yet later instructs itself to use a platform messaging capability with interactive buttons and proactive responses. Even if this is limited to the host chat platform rather than arbitrary network egress, it contradicts the privacy model presented to the user and can cause unintended disclosure of client data into a messaging surface the user may not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The activation section allows the standalone word "invoice", which may be used in broader financial or explanatory conversations not intended to invoke this CRM skill. The file does not define contextual limits or negative examples to reduce collisions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill responds to the single word "quote", which is commonly used for asking about quotations or cited text, not just sales proposals. Without scope restrictions, this can produce unintended invocations.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The standalone word "goal" is frequently used in ordinary conversation and is not unique to this freelancer CRM workflow. Because the file lacks negative examples or activation boundaries, unintended invocation is plausible.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The standalone trigger "tax" can arise in many unrelated contexts, including general informational questions, rather than a request to run this local CRM tax helper. The skill description does not limit activation to explicit reporting commands.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file includes "contract" as a standalone activation phrase, but users may mention contracts in general conversation without intending to generate a template. No contextual narrowing or exclusion guidance is provided.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest presents the skill as a local CRM for tracking freelancer business data. The later instructions add recurring cron/proactive execution on the 1st of every month, every Monday morning, and on December 31, which is a distinct scheduling/automation capability not disclosed in the manifest description.

Content

No source excerpt is available for this finding.