Back to skill

Security audit

daily_summary

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent daily-summary purpose, but it reads sensitive local activity data, can create recurring Feishu-channel execution, and modifies persistent OpenClaw memory without enough control or disclosure.

Review before installing. Only use this skill if you are comfortable with it reading OpenClaw memory and Chrome/Edge browsing history and with a recurring Feishu-channel task being created. Prefer manual runs until the skill documents permissions, adds opt-in controls for browser history and memory writes, and provides clear commands to remove the cron job.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:20
Finding

Recurring Scheduled Task Establishes Cross-Session Persistence

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20-23
Vulnerability Type: T06: System Persistence
Risk Level: High

Vulnerable Code:

bash
openclaw cron add --schedule "30 17 * * 1-5" --message "生成今日工作总结" --channel feishu

Technical Analysis

The documented installation command registers a recurring OpenClaw cron task that runs at 17:30 every weekday. Unlike a one-time invocation, this task remains registered after the current Skill execution and continues triggering Agent and Feishu-channel activity across later sessions.

Although the scheduling behavior is documented, it creates a persistent execution mechanism. The instructions do not provide a corresponding command for inspecting, disabling, or removing the scheduled task.

Attack Path

  1. A user follows the automatic scheduling instructions in SKILL.md.
  2. openclaw cron add registers the recurring task in OpenClaw.
  3. The task survives the current terminal or Agent session.
  4. At every scheduled interval, OpenClaw processes the configured summary request and directs the resulting activity to the Feishu channel.
  5. Execution continues until the user discovers and explicitly removes or disables the task.

Impact Assessment

The mechanism obtains persistent recurring execution within the permissions of the OpenClaw process and its configured Feishu integration. It does not demonstrate operating-system privilege escalation, but it can repeatedly consume Agent resources, access data available to the invoked workflow, and cause channel activity without a new manual invocation. The scope is limited by the privileges and channel configuration of the OpenClaw environment.

Remediation
View remediation

Remediation Suggestions

  • Make one-time manual execution the default behavior.
  • Require explicit, informed user consent before registering a recurring task.
  • Display the exact schedule, invoked message, destination channel, and persistence implications before installation.
  • Provide documented commands to list, disable, and permanently remove the cron entry.
  • Use a uniquely identifiable task name so users can reliably locate the entry.
  • Restrict the scheduled operation to the minimum data access and channel permissions required.
  • Consider requiring confirmation before each external channel delivery.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.py:27
Finding

Browser History Is Copied to a Predictable Temporary Path

Content
View full analysis

Vulnerability Details

File Location: scripts/generate.py:27-63
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code:

python
def read_browser_history(history_path, days=1):
    """Read browser history."""
    if not os.path.exists(history_path):
        return []
    
    temp_path = history_path + f".tmp_{os.getpid()}"
    try:
        shutil.copy2(history_path, temp_path)
        conn = sqlite3.connect(temp_path)
        cursor = conn.cursor()
        
        since = datetime.datetime.now() - datetime.timedelta(days=days)
        timestamp = int(since.timestamp())
        
        cursor.execute("""
            SELECT urls.url, urls.title, visits.visit_time 
            FROM urls 
            JOIN visits ON urls.id = visits.url
            WHERE visits.visit_time > ?
            ORDER BY visits.visit_time DESC
            LIMIT 50
        """, (timestamp * 1000000,))
        
        results = []
        for url, title, visit_time in cursor.fetchall():
            visit_dt = datetime.datetime.fromtimestamp(visit_time / 1000000)
            results.append({
                'url': url,
                'title': title or '',
                'time': visit_dt.strftime('%H:%M')
            })
        
        conn.close()
    except Exception as e:
        results = []
    finally:
        try:
            if os.path.exists(temp_path):
                os.remove(temp_path)
        except:
            pass

Technical Analysis

The implementation duplicates the complete browser history database to a filename derived only from the original path and the process identifier. This destination is predictable and is not created atomically with restrictive permissions.

Where filesystem semantics permit symbolic links or similar redirection, another local process may be able to prepare the expected destinat ...[truncated 1859 chars]

Remediation
View remediation

Remediation Suggestions

  • Use tempfile.TemporaryDirectory or tempfile.NamedTemporaryFile to obtain an unpredictable, atomically created path.
  • Apply restrictive owner-only permissions to the temporary directory and copied database.
  • Place temporary data in a dedicated secure temporary directory rather than beside the browser database.
  • Use context managers for both the temporary resource and SQLite connection.
  • Attempt read-only SQLite access first, using an appropriate SQLite URI or a supported backup mechanism.
  • Avoid copying the complete database when only a limited query result is required.
  • Do not suppress cleanup exceptions silently; record a sanitized warning without exposing history content.
  • Account for abnormal termination by using operating-system-managed temporary storage and removing stale files on subsequent startup.

other

Warning
Location
scripts/generate.py:121
Finding

Persistent Agent Memory Is Modified Without Corresponding Documentation

Content
View full analysis

Vulnerability Details

File Location: scripts/generate.py:121-126
Vulnerability Type: other: Undisclosed Agent State Modification
Risk Level: Medium

Vulnerable Code:

python
# Write to memory
today = datetime.datetime.now().strftime("%Y-%m-%d")
memory_file = os.path.join(MEMORY_DIR, f"{today}.md")

with open(memory_file, 'a', encoding='utf-8') as f:
    f.write(f"\n## Work Summary\n{summary}\n")

print(f"Saved to {memory_file}")

Technical Analysis

The documented feature list describes reading local memory files, but the implementation also opens the current daily memory file in append mode and permanently writes the generated summary into it. This changes persistent Agent state and may affect subsequent sessions that consume the same memory.

The write is not classified as T02: Agent Memory Poisoning because the audited code does not demonstrate that attacker-controlled rules or behavioral instructions are being inserted into memory. The issue is the undisclosed persistent state mutation and the lack of a no-write or confirmation mechanism.

Repeated runs also append another summary section every time, with no idempotency check. The generated summary is derived from headings in the same memory file, so repeated execution can produce redundant persistent content.

Attack Path

  1. The user runs the generator expecting it to read memory and produce a summary.
  2. The script reads headings from the current daily memory file.
  3. It derives a summary from selected lines.
  4. It reopens the same persistent memory file in append mode.
  5. The generated content is added without a confirmation prompt or an opt-out option.
  6. Future Agent sessions or tools that consume daily memory operate on the modified state.
  7. Repeated execution can append additional summary sections and progressively alter the stored context.

Impact Assessment

The script can modify the current user's d ...[truncated 417 chars]

Remediation
View remediation

Remediation Suggestions

  • Explicitly document that the script appends generated output to persistent Agent memory.
  • Request confirmation before modifying memory, especially during manual execution.
  • Make console-only output or a separate summary file the default.
  • Add a --write-memory opt-in flag and a --dry-run mode.
  • Store generated summaries in a dedicated output location rather than mixing them with source memory.
  • Add an idempotency marker or replace the existing daily summary section instead of repeatedly appending duplicates.
  • Perform atomic writes through a securely created temporary file followed by replacement when existing content must be updated.
  • Preserve a backup or provide a rollback mechanism before changing persistent Agent state.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose does not accurately match the behavior/capabilities identified by analysis: it references chat history, Feishu sending, and scheduling, while the implementation reportedly reads local memory files and browser history and can append to local files without declaring those permissions. Description-behavior mismatches are dangerous because they can mislead users into authorizing a skill under false assumptions, hiding sensitive data collection or storage side effects.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares sensitive behavior that implies local file access, but it does not declare any explicit tool scope or permissions. This is dangerous because it obscures the actual access boundary from users and reviewers, especially when the skill reads local chat/memory data and browser history, which may contain sensitive personal or corporate information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description omits a clear warning that it accesses local chat/memory content and browser history and may send derived summaries to Feishu. This is risky because users may not realize the skill processes sensitive behavioral and communication data, increasing the chance of unintended disclosure of confidential or personal information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstrings and all user-facing messages are written only in Chinese, and the generated summary format is also hardcoded in Chinese. This imposes a specific language on users without any visible opt-in or locale-selection mechanism, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill accesses Chrome and Edge browsing history, which can contain sensitive personal or business information, without any user-facing warning, consent flow, or minimization controls. In this skill context, the history is not merely incidental metadata; it is actively harvested to infer work activity, which increases privacy risk and the chance of unintended disclosure in the generated summary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The stated inputs are chat records and browser history. However, get_today_memory() loads content from ~/.openclaw/workspace/memory/YYYY-MM-DD.md, and summarize_tasks() derives tasks from that file rather than from any chat log source.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description states that the skill generates a one-line work summary and sends it to Feishu on a schedule. In this implementation, main() generates the summary, prints it, and writes it into a local markdown file, but there is no Feishu API call, messaging logic, or scheduling behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description states the skill generates a daily work summary in Chinese context and all examples/instructions are fixed to Chinese wording, with no indication that users can choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.