Back to skill

Security audit

ling-shu-agent-designer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese-language agent-design helper that creates OpenClaw configuration and skill-package skeletons with no executable payload or hidden system changes found.

Install this if you want a Chinese-language workflow for designing OpenClaw agents and generating configuration/skill skeletons. Review any generated skill package, API/database configuration, and publishing step before approving it, especially when connecting real business systems.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The identity document presents the skill entirely in Chinese and does not provide a user-language choice, fallback, or opt-in mechanism. This can cause users to misunderstand capabilities, constraints, or safety-relevant guidance, especially in a meta-agent that designs other agents and may collect requirements or produce configurations based on misunderstood input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are broad enough to match very common user requests such as designing an agent or building an assistant, which can cause this skill to activate in situations where a different, more appropriate skill or safer workflow should handle the request. Because this skill is an agent incubator that can generate configurations, skills, and integration plans, over-triggering increases the risk of unintended scope capture, confused-deputy behavior, and unsafe automation design without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger table uses ambiguous mappings like '帮我连接数据库/API' and '发布 Agent' without precise boundaries or safety gates, so the skill may claim requests that involve sensitive integrations, deployment steps, or architectural changes beyond a simple design consultation. In this context, the skill explicitly plans data sources, tool bindings, and skill packaging, making ambiguous activation more dangerous because it can steer users into configuration and integration actions that should require stricter validation and approval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill guidance is written as a Chinese-only behavioral standard and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.