Back to skill

Security audit

Ponddepth Levels

Security checks for vulnerabilities and agentic risk

Overview

This overlay has a real UI purpose but needs Review because it installs persistent jobs, reads local activity data, and does not fully clean up after uninstall.

Install only if you are comfortable with this skill modifying OpenClaw UI assets, creating recurring OpenClaw jobs, using model-backed scheduled execution, and reading local session/activity data for XP. Before trusting uninstall, manually verify and remove the PondDepth cron jobs and deployed workspace task files. The author should document data access, add explicit consent for cron/model use, remove or justify the installer queue, sanitize UI rendering, and fix uninstall cleanup.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
scripts/install.sh:54
Finding

Scheduled Jobs and Deployed Executables Survive Uninstallation

Content
View full analysis
/dev/null 2>&1; then # 1) ClawHub status refresh (every 10 minutes) if command -v jq >/dev/null 2>&1; then EXIST_ID=$(openclaw cron list --json | jq -r '.jobs[]|select(.name=="PondDepth ClawHub status (10m)")|.id' | head -n 1) else EXIST_ID="" fi if [[ -n "${EXIST_ID:-}" && "${EXIST_ID}" != "null" ]]; then openclaw cron edit "$EXIST_ID" --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null else openclaw cron add --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null fi # 2) Companion metrics refresh (hourly) if command -v jq >/dev/null 2>&1; then EXIST_ID2=$(openclaw cron list --json | jq -r '.jobs[]|select(.name=="PondDepth companion metrics (hourly)")|.id' | head -n 1) else EXIST_ID2="" fi if [[ -n "${EXIST_ID2:-}" && "${EXIST_ID2}" != "null" ]]; then openclaw cron edit "$EXIST_ID2" --cron "0 0 * * * *" --tz UTC --name "PondDepth companion metrics (hourly)" --description "Generate /ui/assets/companion-metrics.json (XP/level)" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_companion_metrics.py --tz Asia/Shanghai" --model gpt-4o-mini --thinking minimal --timeout-seconds 120 --session ...[truncated 3557 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/ponddepth-badge.js:798
Finding

Stored DOM Cross-Site Scripting Through Unsanitized JSON Content

Content
View full analysis
`
  • ${n.title}
  • `).join(""); pop.innerHTML = `

    ${t("陪伴第", "Day")} ${companionDays} ${t("天", "")}

    🦞${lvlIdFinal}|${cleanTitle(t(lvl.titleZh, lvl.titleEn))}
    Remediation
    View remediation

    T09 · Insecure Skill Coding Practices

    Warning
    Location
    scripts/uninstall.sh:13
    Finding

    Uninstall Procedure Deletes the Asset It Has Just Restored

    Content
    View full analysis
    /dev/null | sort | tail -n 1)" || true if [[ -n "${LAST_BACKUP:-}" && -d "$BACKUP_ROOT/$LAST_BACKUP" ]]; then if [[ -f "$BACKUP_ROOT/$LAST_BACKUP/ponddepth-badge.js" ]]; then echo "Restoring ponddepth-badge.js from backup: $LAST_BACKUP" cp -f "$BACKUP_ROOT/$LAST_BACKUP/ponddepth-badge.js" "$DIST/ponddepth-badge.js" fi fi fi # 2) Remove PondDepth assets if [[ -f "$DIST/ponddepth-badge.js" ]]; then echo "Removing: $DIST/ponddepth-badge.js" rm -f "$DIST/ponddepth-badge.js" fi ``` ### Technical Analysis The script first copies the most recent backup to the live destination. It then unconditionally checks for that destination and deletes it. A successfully restored pre-installation file therefore always satisfies the deletion condition and is removed immediately. This contradicts the documented claim that uninstallation restores the most recent backup. It can destroy a host file that existed before the skill was installed. The backup directory records only a copy of an existing file and does not include an installation manifest that distinguishes these two cases: - No destination file existed before installation, so the injected file should be deleted. - A destination file existed before installation, so the original should be restored and retained. ### Attack Path 1. A legitimate `ponddepth-badge.js` already exists in the Control UI assets directory. 2. Installation backs it up and overwrites the live file. 3. The user runs `scripts/uninstall.sh`. 4. The script restores the backed-up file to the destination. 5. The next block finds that destination and deletes it. 6. The original host asset is lost fr ...[truncated 470 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
    • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
    • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
    Findings (44)

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    A skill marketed as a leveling overlay also appears to execute clawhub install, manage an installation queue, and act as a background installer through cron or heartbeat behavior. This creates a significant trust gap because a cosmetic feature is effectively granted authority to change installed software state and automate future installs.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    A skill marketed as a leveling overlay also appears to execute clawhub install, manage an installation queue, and act as a background installer through cron or heartbeat behavior. This creates a significant trust gap because a cosmetic feature is effectively granted authority to change installed software state and automate future installs.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    99% confidence
    Finding

    A skill marketed as a leveling overlay also appears to execute clawhub install, manage an installation queue, and act as a background installer through cron or heartbeat behavior. This creates a significant trust gap because a cosmetic feature is effectively granted authority to change installed software state and automate future installs.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    A skill marketed as a leveling overlay also appears to execute clawhub install, manage an installation queue, and act as a background installer through cron or heartbeat behavior. This creates a significant trust gap because a cosmetic feature is effectively granted authority to change installed software state and automate future installs.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    97% confidence
    Finding

    A skill marketed as a leveling overlay also appears to execute clawhub install, manage an installation queue, and act as a background installer through cron or heartbeat behavior. This creates a significant trust gap because a cosmetic feature is effectively granted authority to change installed software state and automate future installs.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    99% confidence
    Finding

    A skill marketed as a leveling overlay also appears to execute clawhub install, manage an installation queue, and act as a background installer through cron or heartbeat behavior. This creates a significant trust gap because a cosmetic feature is effectively granted authority to change installed software state and automate future installs.

    Content

    No source excerpt is available for this finding.

    Ae1

    High
    Category
    analysis-evasion
    Confidence
    100% confidence
    Finding

    Referenced artifact was not completely inspected

    Content

    Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

    md
    - `ponddepth-badge.js`
    

    Description-Behavior Mismatch

    High
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The overlay can invoke skills.update to enable other skills from a recommendation panel. Allowing a UI badge to change security-relevant skill state creates a privilege/action boundary issue: a decorative overlay can activate capabilities the user did not intentionally enable through a dedicated settings flow, potentially expanding access to mail, messaging, files, or other integrations.

    Content

    No source excerpt is available for this finding.

    External Model or Provider Selection

    High
    Category
    Excessive Agency
    Confidence
    90% confidence
    Finding

    This is a duplicate match of the same cron edit behavior at line 64; the risk remains that the installer silently binds a background task to a named external model. The duplication does not change the substance of the issue: recurring provider use without explicit informed consent.

    Content

    Scanner excerpt · scripts/install.sh (reported line 64)May include surrounding context.

    sh
    fi
    
      if [[ -n "${EXIST_ID:-}" && "${EXIST_ID}" != "null" ]]; then
        openclaw cron edit "$EXIST_ID" --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null
      else
        openclaw cron add --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null
      fi
    

    External Model or Provider Selection

    High
    Category
    Excessive Agency
    Confidence
    90% confidence
    Finding

    This is a duplicate match of the same cron edit behavior at line 64; the risk remains that the installer silently binds a background task to a named external model. The duplication does not change the substance of the issue: recurring provider use without explicit informed consent.

    Content

    Scanner excerpt · scripts/install.sh (reported line 64)May include surrounding context.

    sh
    fi
    
      if [[ -n "${EXIST_ID:-}" && "${EXIST_ID}" != "null" ]]; then
        openclaw cron edit "$EXIST_ID" --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null
      else
        openclaw cron add --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null
      fi
    

    External Model or Provider Selection

    High
    Category
    Excessive Agency
    Confidence
    90% confidence
    Finding

    This duplicate finding points to the same cron add behavior already identified at line 66. The concern is persistent automated use of an external model for a background task unrelated to core installation of static UI assets.

    Content

    Scanner excerpt · scripts/install.sh (reported line 66)May include surrounding context.

    sh
    if [[ -n "${EXIST_ID:-}" && "${EXIST_ID}" != "null" ]]; then
        openclaw cron edit "$EXIST_ID" --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null
      else
        openclaw cron add --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null
      fi
    
      # 2) Companion metrics refresh (hourly)
    

    External Model or Provider Selection

    High
    Category
    Excessive Agency
    Confidence
    90% confidence
    Finding

    This duplicate finding points to the same cron add behavior already identified at line 66. The concern is persistent automated use of an external model for a background task unrelated to core installation of static UI assets.

    Content

    Scanner excerpt · scripts/install.sh (reported line 66)May include surrounding context.

    sh
    if [[ -n "${EXIST_ID:-}" && "${EXIST_ID}" != "null" ]]; then
        openclaw cron edit "$EXIST_ID" --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null
      else
        openclaw cron add --every 10m --name "PondDepth ClawHub status (10m)" --description "Writes /ui/assets/clawhub-status.json for PondDepth B2 UX" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_clawhub_status.py" --model gpt-4o-mini --thinking minimal --timeout-seconds 60 --session isolated --no-deliver >/dev/null
      fi
    
      # 2) Companion metrics refresh (hourly)
    

    External Model or Provider Selection

    High
    Category
    Excessive Agency
    Confidence
    93% confidence
    Finding

    The cron edit command for companion metrics also forces a specific external model into an automated workflow. For a leveling overlay, hidden recurring model usage is not obviously necessary and introduces privacy, governance, and billing concerns disproportionate to the feature set.

    Content

    Scanner excerpt · scripts/install.sh (reported line 77)May include surrounding context.

    sh
    fi
    
      if [[ -n "${EXIST_ID2:-}" && "${EXIST_ID2}" != "null" ]]; then
        openclaw cron edit "$EXIST_ID2" --cron "0 0 * * * *" --tz UTC --name "PondDepth companion metrics (hourly)" --description "Generate /ui/assets/companion-metrics.json (XP/level)" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_companion_metrics.py --tz Asia/Shanghai" --model gpt-4o-mini --thinking minimal --timeout-seconds 120 --session isolated --no-deliver >/dev/null
      else
        openclaw cron add --cron "0 0 * * * *" --tz UTC --name "PondDepth companion metrics (hourly)" --description "Generate /ui/assets/companion-metrics.json (XP/level)" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_companion_metrics.py --tz Asia/Shanghai" --model gpt-4o-mini --thinking minimal --timeout-seconds 120 --session isolated --no-deliver >/dev/null
      fi
    

    External Model or Provider Selection

    High
    Category
    Excessive Agency
    Confidence
    90% confidence
    Finding

    This duplicate finding reflects the same hourly cron creation at line 79 with a forced external model setting. The danger is continued silent provider usage and repeated automated processing in a context where users would reasonably expect only asset installation.

    Content

    Scanner excerpt · scripts/install.sh (reported line 79)May include surrounding context.

    sh
    if [[ -n "${EXIST_ID2:-}" && "${EXIST_ID2}" != "null" ]]; then
        openclaw cron edit "$EXIST_ID2" --cron "0 0 * * * *" --tz UTC --name "PondDepth companion metrics (hourly)" --description "Generate /ui/assets/companion-metrics.json (XP/level)" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_companion_metrics.py --tz Asia/Shanghai" --model gpt-4o-mini --thinking minimal --timeout-seconds 120 --session isolated --no-deliver >/dev/null
      else
        openclaw cron add --cron "0 0 * * * *" --tz UTC --name "PondDepth companion metrics (hourly)" --description "Generate /ui/assets/companion-metrics.json (XP/level)" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_companion_metrics.py --tz Asia/Shanghai" --model gpt-4o-mini --thinking minimal --timeout-seconds 120 --session isolated --no-deliver >/dev/null
      fi
    fi
    

    External Model or Provider Selection

    High
    Category
    Excessive Agency
    Confidence
    90% confidence
    Finding

    This duplicate finding reflects the same hourly cron creation at line 79 with a forced external model setting. The danger is continued silent provider usage and repeated automated processing in a context where users would reasonably expect only asset installation.

    Content

    Scanner excerpt · scripts/install.sh (reported line 79)May include surrounding context.

    sh
    if [[ -n "${EXIST_ID2:-}" && "${EXIST_ID2}" != "null" ]]; then
        openclaw cron edit "$EXIST_ID2" --cron "0 0 * * * *" --tz UTC --name "PondDepth companion metrics (hourly)" --description "Generate /ui/assets/companion-metrics.json (XP/level)" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_companion_metrics.py --tz Asia/Shanghai" --model gpt-4o-mini --thinking minimal --timeout-seconds 120 --session isolated --no-deliver >/dev/null
      else
        openclaw cron add --cron "0 0 * * * *" --tz UTC --name "PondDepth companion metrics (hourly)" --description "Generate /ui/assets/companion-metrics.json (XP/level)" --message "请运行命令并输出stdout:python3 $TASKS_DIR/ponddepth_companion_metrics.py --tz Asia/Shanghai" --model gpt-4o-mini --thinking minimal --timeout-seconds 120 --session isolated --no-deliver >/dev/null
      fi
    fi
    

    Tool Parameter Abuse

    High
    Category
    Tool Misuse
    Confidence
    95% confidence
    Finding

    Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

    Content

    Scanner excerpt · scripts/uninstall.sh (reported line 27)May include surrounding context.

    sh
    # 2) Remove PondDepth assets
    if [[ -f "$DIST/ponddepth-badge.js" ]]; then
      echo "Removing: $DIST/ponddepth-badge.js"
      rm -f "$DIST/ponddepth-badge.js"
    fi
    
    if [[ -d "$DIST/ponddepth-icons" ]]; then
    

    Tool Parameter Abuse

    High
    Category
    Tool Misuse
    Confidence
    95% confidence
    Finding

    This recursively deletes a directory whose parent path is influenced by the OPENCLAW_UI_ASSETS_DIR environment variable. While likely intended for legitimate uninstall cleanup, if that variable is set to an unexpected location the script could recursively remove an arbitrary similarly named directory outside the intended asset tree, making the uninstall operation more dangerous than necessary.

    Content

    Scanner excerpt · scripts/uninstall.sh (reported line 32)May include surrounding context.

    sh
    if [[ -d "$DIST/ponddepth-icons" ]]; then
      echo "Removing: $DIST/ponddepth-icons/"
      rm -rf "$DIST/ponddepth-icons"
    fi
    
    echo "OK: removed PondDepth UI assets. Hard refresh Control UI."
    

    Description-Behavior Mismatch

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The file implements a persistent installer queue that reads workspace state, invokes an external installer, and writes status back, which materially differs from the declared purpose of a leveling overlay UI skill. This mismatch is a strong indicator of hidden functionality and raises the risk that the skill is being used to bootstrap other skills or code without user awareness.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    High
    Category
    Not specified by scanner
    Confidence
    97% confidence
    Finding

    Subprocess-based installation is not justified for a UI badge/XP overlay and gives the skill an execution pathway to fetch and install arbitrary additional skills. In this context, the mismatch makes the capability more dangerous because it appears concealed inside a benign-looking package, increasing the chance of unnoticed abuse.

    Content

    No source excerpt is available for this finding.

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    94% confidence
    Finding

    The skill declares only a minimal metadata requirement while the documented behavior includes shell execution, filesystem reads/writes, environment-variable-controlled paths, and periodic jobs. Missing explicit tool scope prevents informed consent and weakens sandboxing or policy enforcement, especially for a skill that modifies installed UI files and creates recurring tasks.

    Content

    No source excerpt is available for this finding.

    Description-Behavior Mismatch

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The badge UI reads companion metrics and, if unavailable, falls back to fetching up to 2000 chat history messages for the current session to compute distinct active days. That is a privacy-sensitive data access exceeding what a simple leveling overlay minimally needs, especially because it happens in a non-obvious hover/render path and can expose message metadata to code that users may not expect to inspect conversations.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    90% confidence
    Finding

    The code fetches current-session chat history without visible in-context disclosure that hovering/opening the badge may inspect conversation records to derive engagement days. Hidden collection of conversation metadata for a UI overlay undermines user expectations and increases privacy exposure, even if the code only counts distinct days locally.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    89% confidence
    Finding

    Fetching session chat history is not necessary for the core purpose of displaying a level badge and recommendations. This over-broad access increases privacy risk and violates least-privilege design, because unrelated conversational data becomes accessible to UI code for a gamification feature.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    87% confidence
    Finding

    This shell script creates directories, copies files into UI asset and workspace locations, and later adds or edits cron jobs, but it does not provide an upfront user-facing warning before making those persistent system and workspace changes. While some comments describe the actions for developers, the script lacks a clear disclosure or confirmation prompt to the end user before altering files and scheduled tasks.

    Content

    No source excerpt is available for this finding.

    Description-Behavior Mismatch

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The installer goes beyond placing UI assets and silently creates or edits persistent scheduled jobs. That introduces ongoing autonomous behavior and recurring execution that is not clearly justified by a simple UI overlay, increasing the attack surface and persistence of the skill.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.