T01 · Skill Instruction Hijacking
- Location
SKILL.md:18- Finding
Skill Instructions Override Agent Safety and Decision-Making
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is meant to connect personal WeChat, but it gives broad install, credential, and gateway-changing instructions with unsafe scoping and execution patterns.
Review before installing. Use this only if you trust the npm packages, registry mirror, Tencent WeChat endpoints, and OpenClaw gateway changes. Prefer a revised version that pins package versions, preserves normal agent discretion, keeps QR codes local by default, validates API responses, writes credentials through data-only JSON handling, and asks clearly before global installs or persistent token writes.
SKILL.md:18Skill Instructions Override Agent Safety and Decision-Making
SKILL.md:45Unpinned Runtime Installation and Execution of Third-Party Packages
SKILL.md:122Remote QR Content Is Interpolated into an Executable Node Command
SKILL.md:226Remote Credential Fields Are Inserted Directly into Generated JavaScript
SKILL.md:130Optional CDN Upload Exposes a Live Authentication QR Code
Defaulting a broad request like 连接微信 to personal WeChat can trigger the wrong skill when the user intent is ambiguous. In this skill, the consequence is not merely UX confusion: it initiates plugin installation, external network calls, QR-based authentication, and credential handling for a personal account, so accidental invocation can lead to unintended account binding or sensitive workflow execution.
The skill executes an unpinned package with npx ...@latest install, which fetches and runs whatever code is current in the registry at execution time. This creates a supply-chain risk: if the package is compromised, typo-squatted upstream, or a malicious update is published, the agent will execute attacker-controlled code on the host.
This is the same unpinned runtime execution pattern in a second code path, again using npx ...@latest install. Because the skill is specifically designed to install and execute external tooling, the lack of version pinning materially increases the chance of arbitrary code execution through a compromised or unexpected package release.
The skill hardcodes user-facing instructions and expected confirmations in Chinese, such as asking the user to reply 'ok' after scanning. There is no indication that the user can choose another language or that the locale restriction is intentionally limited to a justified region-specific context.
No suspicious patterns detected.