Back to skill

Security audit

Skill创作发明家

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local, user-directed tool for creating and auditing agent skills, with no evidence of hidden data collection, persistence, or destructive behavior.

Install only if you want a Chinese-first workflow for creating and auditing OpenClaw skills. Run the audit script with an explicit target or a carefully chosen SKILL_BASE if you do not want it to inspect all local skills under the detected skills directory. Treat the landing page's publishing language as imprecise: the skill prepares and audits handoff packages, but publishing should remain with a dedicated publishing tool.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage examples advertise highly generic trigger phrases such as 'Create a skill that does X' and 'Check my skill for anti-patterns', which can overlap with ordinary user requests in a broader agent environment. In a skill system with automatic activation, this can cause unintended invocation, context hijacking, or the wrong workflow being applied to unrelated tasks, especially because this skill performs audit and creation actions across other skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow trigger table maps common phrases like 'Create a skill that does X' and 'My skill isn't triggering' to powerful workflows without defining trigger boundaries or exclusions. This ambiguity increases the chance of accidental activation or misrouting, which is more concerning here because the skill is positioned as a gatekeeper with authority to audit, refactor, and hand off other skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Quick Start tells users to invoke the skill using broad natural-language prompts that are not sufficiently scoped to this specific tool. In ecosystems where multiple skills compete for activation, this can lead to unintended loading of this skill, interference with user intent, or misuse of its auditing workflow on the wrong target.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage examples show highly generic user utterances like '创建一个做 X 的 Skill' and '帮我审计 my-skill 的质量' without constraints on context, scope, or non-goals. Because this skill appears to orchestrate multi-stage creation and audit behavior, overbroad examples increase the chance of accidental or adversarial triggering, which can divert the agent into an unintended workflow and affect other tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger examples are broad natural-language phrases such as creating, auditing, or delivering a skill, but the README does not define clear activation boundaries, exclusions, or disambiguation rules. In an agent environment, this can cause the skill to activate in unintended contexts, leading to workflow hijacking, incorrect tool selection, or execution of a high-authority creation/audit flow when the user meant something else.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The display name and core description are written in Chinese, and the document consistently frames triggers and operating instructions only in Chinese. There is no statement offering a language choice or limiting the skill to a Chinese-speaking context, so this imposes a locale/language assumption without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompts and expected behaviors are written to assume Chinese-language interaction, but this file does not indicate that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. That creates a natural-language policy concern because it hard-codes a locale/language expectation without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The eval defines triggering behavior using natural-language examples without clear negative boundaries or a formal activation contract. In a routing or orchestration system, this can cause the skill to activate for adjacent requests outside its intended scope, leading to misrouting, incorrect workflow execution, or bypass of the more appropriate skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L26、L27、L28、L29 与 L30 多处把 mu-skill-creator 描述为包含发布前检查、发布、交付甚至“从创建到发布的全流程质量门控”。但给定 manifest 明确写明该技能不适用于 skill 发布,发布相关工作应由 mu-skill-auditor 处理。这会让用户对技能实际职责边界产生错误预期,属于描述与声明用途不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The title and document body are written as Chinese guidance, and the examples/requirements consistently prescribe Chinese output conventions rather than offering a language choice. In particular, the document presents a language-specific workflow as the default without stating that users may choose another locale, which can violate a language/locale policy requiring opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

These lines describe '纯英文' input as a non-expected edge case for a '中文 Skill', indicating the skill is designed around a fixed Chinese-language assumption. Because the document does not pair this with user choice or a clearly justified region-specific constraint, it reads as a language policy violation rather than a documented opt-in locale limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script presents its purpose, usage guidance, status labels, and audit checklist primarily in Chinese, with one Japanese column label, and does not indicate any user choice or opt-in for language/locale. That can violate a language/locale policy when users are not explicitly offered a preferred language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document is initialized with lang="zh", which sets Chinese as the default language for the page. Although a language switcher exists later in the UI, the initial experience forces a specific locale before the user has made a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script calls applyLang('zh') unconditionally, which forces the interface into Chinese regardless of user preference. This is a natural-language locale policy issue because the skill does not obtain user opt-in or honor ambient locale settings before choosing the language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations in natural language. This file presents all guidance exclusively in Chinese and does not provide any user opt-in, alternative language option, or justification for a Chinese-only constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.