Back to skill

Security audit

Nex Gdpr

Security checks for vulnerabilities and agentic risk

Overview

This GDPR tool has a coherent local-compliance purpose, but it can scan, export, and delete sensitive local data while making stronger safety claims than the code supports.

Review this carefully before installing. Use it only on accounts and directories where you are authorized to process GDPR data, narrow scan paths, and do not run erasure processing until you have backups and a reviewed deletion plan. Treat exports and the ~/.nex-gdpr database as plaintext sensitive data unless you add encryption and strict permissions yourself.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
lib/config.py:8
Finding

GDPR records and exports are stored in plaintext without enforced restrictive permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
lib/processor.py:244
Finding

Erasure processing deletes entire matching files without secure overwrite or record-level isolation

Content
View full analysis
bool: """Safely delete a file (non-system).""" try: # Don't delete system files system_prefixes = ["/sys/", "/proc/", "/dev/", "/etc/"] if any(file_path.startswith(p) for p in system_prefixes): return False # For demo, just log the deletion # In production: use secure_delete() instead if os.path.exists(file_path) and os.path.isfile(file_path): # Check if it's a user-owned file stat_info = os.stat(file_path) if stat_info.st_uid == os.getuid(): os.remove(file_path) return True return False except Exception: return False ``` ### Technical Analysis The scanner identifies a file when the requested identifier appears anywhere in its contents. Erasure processing then passes the whole file to `_safe_delete_file()`. There is no record-level deletion, content rewriting, tenant isolation, review manifest, or confirmation that the file exclusively belongs to the target data subject. ...[truncated 1818 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
nex-gdpr.py:258
Finding

Any local CLI caller can mark an identity as verified and authorize export or deletion

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.sh:65
Finding

Setup installs unpinned executable dependencies from mutable package indexes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/processor.py:286
Finding

Export packaging allows basename collisions and disclosure of stale files

Content
View full analysis
10MB)", "size": file_size, } ) except Exception as e: manifest["findings"].append( { "file": file_path, "exported": False, "reason": str(e), } ) # Write manifest with open(export_dir / "manifest.json", "w") as f: json.dump(manifest, f, indent=2) # Create ZIP zip_path = EXPORT_DIR / f"access_request_{request_id}.zip" shutil.make_archive(str(zip_path.with_suffix("")), "zip", export_dir) ``` ### Technical An ...[truncated 1993 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (39)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The README instructs users to run rm on the SQLite journal file as a troubleshooting step. This is dangerous because operators may execute a destructive filesystem command against a live or recovering database, causing data loss, corruption, or destruction of audit/compliance records that are especially sensitive in a GDPR workflow.

Content

Scanner excerpt · README.md (reported line 223)May include surrounding context.

Database locked error

Wait for any background operations to complete, or delete the journal file:

bash
rm ~/.nex-gdpr/gdpr.db-journal

Python module not found

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the primary observed behavior is bootstrap/installation while the README markets a full operational GDPR platform, users may execute the skill under false assumptions about what protections and workflows are in place. Although this is partly a product-integrity issue, in a compliance tool it becomes a security and privacy risk because operators may expose or fail to protect personal data based on incorrect expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the primary observed behavior is bootstrap/installation while the README markets a full operational GDPR platform, users may execute the skill under false assumptions about what protections and workflows are in place. Although this is partly a product-integrity issue, in a compliance tool it becomes a security and privacy risk because operators may expose or fail to protect personal data based on incorrect expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the primary observed behavior is bootstrap/installation while the README markets a full operational GDPR platform, users may execute the skill under false assumptions about what protections and workflows are in place. Although this is partly a product-integrity issue, in a compliance tool it becomes a security and privacy risk because operators may expose or fail to protect personal data based on incorrect expectations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the primary observed behavior is bootstrap/installation while the README markets a full operational GDPR platform, users may execute the skill under false assumptions about what protections and workflows are in place. Although this is partly a product-integrity issue, in a compliance tool it becomes a security and privacy risk because operators may expose or fail to protect personal data based on incorrect expectations.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
- "nex-gdpr.py"

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The erasure workflow claims it only logs deletions in this demo, but it actually invokes _safe_delete_file(), which performs real os.remove() operations on user-owned files. In a GDPR-focused skill that scans broadly for personal data, this mismatch is dangerous because operators may run the feature expecting a dry-run or audit-only action and instead permanently delete files.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The erasure path can delete files immediately based on scan results without an explicit confirmation step, preview, or approval barrier in this code path. Because the skill's purpose is to discover personal data across multiple locations automatically, false matches, broad identifiers, or operator mistakes could trigger irreversible deletion of unintended files.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

secure_delete performs an irreversible operation by overwriting file contents and deleting the file, but the function contains no confirmation prompt or user-visible disclosure. A developer-facing docstring is insufficient warning for a destructive action of this severity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The helper says it 'just logs the deletion' for demo purposes, but the implementation deletes existing user-owned files with os.remove(). This deceptive behavior increases the chance of accidental data loss, especially because surrounding GDPR tooling encourages broad scans over sessions, logs, and databases where matched files may be sensitive or operationally important.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
- **Deadline Tracking**: Monitor 30-day GDPR response deadlines with extension support
- **PII Detection**: Identify personal information (emails, phone numbers, national IDs)
- **Retention Policies**: Configure and auto-clean data based on retention rules
- **Secure Deletion**: Overwrite data before deletion for compliance
- **Audit Trail**: Complete history of all actions taken on requests

## Installation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly instructs scanning broad local directories containing sessions, memory, logs, uploads, and other skill databases, which can sweep in unrelated or highly sensitive personal data. In a GDPR tool this may be functionally relevant, but without prominent warnings, scoping guidance, data minimization advice, or consent/authorization checks, operators may over-collect data and expose third-party information during access or export processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The erasure workflow presents destructive commands as routine steps but does not warn that processing an erasure request may permanently remove data and be difficult or impossible to reverse. In a system that scans multiple storage locations, this creates real risk of accidental data loss, especially if identity verification, scope validation, or backup exceptions are mishandled.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 190)May include surrounding context.

md
## Security Considerations

- **Audit Trail**: All actions are logged with actor and timestamp
- **Secure Deletion**: Uses 3-pass overwrite before file deletion
- **Encryption**: Export files should be encrypted before transmission
- **Access Control**: Ensure proper file permissions on `~/.nex-gdpr`
- **Backup**: Maintain backups of audit trail for compliance

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · README.md (reported line 235)May include surrounding context.

Permission denied on exports

Check file permissions:

bash
ls -la ~/.nex-gdpr/exports/
chmod 700 ~/.nex-gdpr/

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 236)May include surrounding context.

Check file permissions:

bash
ls -la ~/.nex-gdpr/exports/
chmod 700 ~/.nex-gdpr/

Scan finds no data

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and documents capabilities that imply broad access to environment variables, filesystem contents, shell execution, and possible network use, yet it declares no explicit tool scope or permission boundaries. In a GDPR-focused skill that scans sessions, logs, memory, and databases, this creates a significant risk of over-privileged execution, unintended data access, and misuse of highly sensitive personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes erasure and cleanup operations but does not prominently warn that these actions may permanently delete data. In a GDPR tool that may touch sessions, memory, logs, uploads, and databases, insufficient warning materially increases the risk of irreversible data loss, operational disruption, and deletion beyond what the user intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad privacy-related phrases such as general references to personal data, PII, audit trails, and compliance topics, which can cause the skill to activate during ordinary discussion rather than explicit compliance workflows. For a skill with broad local data-scanning and deletion/export behavior, over-triggering increases the chance of unintended access to sensitive data or accidental initiation of privacy-affecting actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented process command automates scanning and subsequent export or deletion actions across potentially broad data stores without a strong privacy warning or explicit consent flow. Because the skill operates on highly sensitive personal data, a single command that aggregates discovery and action increases the blast radius of mistakes and can lead to over-collection, over-disclosure, or unintended erasure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code defines scan paths for session data, memory, logs, uploads, and other skill databases, which are likely to contain user data. While comments describe the paths technically, there is no user-facing disclosure, confirmation, or warning in this file that the skill will inspect these potentially sensitive locations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes discovery of personal data across OpenClaw sessions, agent memory, application logs, and skill databases as part of GDPR handling. This config expands that scope to hard-coded databases for other nex-* skills such as life-logger, inbox, and notes, which is a broader cross-application data access capability than the description explicitly claims.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code writes a JSON file containing the data subject's name, email, ID, and findings to disk and then packages it into a ZIP archive. The function docstring describes the behavior for developers, but there is no visible user disclosure or warning that sensitive personal data will be written to local storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The function writes an anonymized copy of the source content to a new file, which is a file-write operation affecting user data. There is no confirmation, print/log statement, or other user-visible warning in this code path to disclose that a new file will be created.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The access export routine copies discovered source files into an export directory and records original file paths in a manifest, increasing the number of plaintext copies of personal data on disk. In this skill context, which automatically scans sessions, logs, and databases for personal data, that replication meaningfully expands exposure if export directories are accessible, retained too long, or collected by backups.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.