T08 · Insecure Dependencies
- Location
references/ai-humanizer.md:8- Finding
Dynamic Loading of Unpinned External Skills
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is openly designed to rewrite articles to avoid similarity checks and can read and write local files, so users should review it carefully before installing.
Install only if you intentionally want a Chinese article-rewriting workflow and you have rights to the source material. Avoid using it to republish third-party content without attribution, review any generated output for copyright and platform-policy compliance, and approve exact input/output paths before allowing file writes. Treat the referenced helper skills as additional dependencies that should be independently reviewed.
references/ai-humanizer.md:8Dynamic Loading of Unpinned External Skills
SKILL.md:61Unrestricted File Input and Predictable Adjacent Output Writes
references/user-command.md:42Platform-Specific Plagiarism Detection Evasion Workflow
The skill explicitly includes originality checks, similarity scoring, platform-specific plagiarism risk thresholds, and iterative optimization to lower detectable similarity while preserving the source meaning. That goes beyond ordinary editing and materially enables evasion of plagiarism detection and reposting controls on publishing platforms.
The trigger terms are very broad and include generic requests like '改写' and '二次创作', making accidental or unintended activation likely. Because the skill performs file reads/writes and promotes plagiarism-evasion workflows, overbroad triggering increases the chance of unsafe invocation in unrelated contexts.
Claiming to 'remove AI flavor' and convert AI text into human text is an evasion-oriented capability that can help conceal machine generation from reviewers, readers, or policy systems. In this context it is paired with low-similarity rewriting, which increases the likelihood of deceptive use rather than simple style improvement.
The prescribed workflow systematically preserves the original information while changing wording, structure, and sequence, then measures similarity and iterates to reduce platform-detectable duplication. In context, this is a concrete operational playbook for laundering source content into derivative copies designed to evade moderation and plagiarism checks.
The skill instructs saving output files into the source directory and describes file creation behavior without a prominent warning or explicit confirmation step. Any skill that modifies filesystem state should clearly disclose where files will be written and require user approval to avoid unintended data sprawl, overwrites, or privacy issues.
The documentation states the final deliverable should contain only the processed article content with no intermediate process or metadata. However, the later required response template instructs the AI to output processing information, statistics, previews, and workflow details, which contradicts the earlier 'only article content' requirement at the intent/documentation level.
This markdown file describes granting the AI permission to read and reply to WeChat messages, which is a privacy-impacting behavior. Although the text briefly says it 'won't touch other things,' it presents the permission casually and does not include a clear warning about message access, data handling, or the need to avoid exposing sensitive chats.
The activation criteria rely on vague judgments such as '进入到第7步' and '仍感觉AI味任然不是"无菌"', without defining the workflow, the evaluation standard, or when the skill should not be used. This can cause inconsistent or unintended invocation because different users or agents may interpret these conditions differently.
The document discloses an internal absolute filesystem path to another local skill ('~/.openclaw/workspace/skills/ai-humanizer/SKILL.md'), which exposes environment structure and enumerates available capabilities. In an adversarial setting, this can help an attacker map the agent's local workspace and craft follow-on prompts or dependency-targeting attacks against known skill locations.
调用方式:
读取:~/.openclaw/workspace/skills/ai-humanizer/SKILL.md
应用:核心原则(AI生成的文本更具人性化。重写文本使其听起来自然、具体且有人情味)
The conditions for calling 'humanizer-zh' say it should run after 'ai-humanizer' if AI traces still need removal or for creative writing when text still feels '无菌', but these are subjective and not operationally defined. The file does not specify measurable criteria, explicit scope limits, or negative examples, so invocation may overlap broadly with normal rewriting tasks.
This line similarly reveals an internal skill path ('~/.openclaw/workspace/skills/humanizer-zh/SKILL.md'), enabling capability and environment enumeration. While not an exploit by itself, the skill context makes it more sensitive because it tells an attacker exactly which auxiliary skill exists and where it is expected to reside.
调用方式:
读取:~/.openclaw/workspace/skills/humanizer-zh/SKILL.md
应用:核心原则(去除文本中的 AI 生成痕迹,审阅 AI 生成内容、优化写作风格、让文字不那么像机器生成的)
This markdown file presents all instructions and labels exclusively in Chinese, which can constitute a language/locale policy violation when no user opt-in or justification is provided. The content does not indicate that the skill is region-specific or that users may choose another language.
This markdown file contains natural-language instructions entirely in Chinese and begins with a mandatory requirement phrased as '必须满足', which indicates a fixed language/locale expectation. Under the policy, forcing a specific language without user opt-in or clear regional justification is a natural-language policy violation.
The trigger language is broad and workflow-coupled rather than tied to explicit user intent, which can cause the polishing skills to run automatically in situations the user did not request. In this context, unintended invocation can propagate hidden transformations to user content and cascade into additional skill loading without clear consent or narrowing conditions.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
调用方式:
读取:~/.openclaw/workspace/skills/blog-rewriter/SKILL.md
应用:核心原则(对文章进行润色、排版)
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
调用方式:
读取:~/.openclaw/workspace/skills/chinese-writing-polish/SKILL.md
应用:核心原则(去除文本中的 AI 生成痕迹,审阅 AI 生成内容、优化写作风格、让文字不那么像机器生成的)
The instruction explicitly directs the system to remove signs of AI-generated writing as a default behavior, without indicating that this should occur only when the user asks for it. That creates a policy and trust risk because it encourages concealment-oriented rewriting and may materially alter provenance, style, or disclosure expectations for generated content.
The instruction says the rewritten output must use a natural, everyday colloquial tone, which imposes a particular linguistic style by default. Under the policy, forced language or locale/style constraints should either be optional or clearly offered as a user choice.
The file's natural-language instructions and guidance are entirely in Chinese, which may amount to an implicit language constraint for users who do not read that language. There is no indication that the language choice is optional or that the skill is intended only for a Chinese-speaking audience.
The article says the AI will automatically fetch, parse, and organize content from supplied links, which implies network access and transfer of user-supplied data to external resources or services. The description does not warn readers that using this feature may involve outbound requests and associated privacy or data-governance considerations.
This plain-text skill content presents all instructions and descriptions in a single language with no indication that users may choose another language or that the locale restriction is intentional. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.
The skill instructs the agent to 'generate the final file and save it' and provide a save path, but it does not define safe write boundaries, destination constraints, overwrite behavior, or require explicit user confirmation before writing. In an agentic environment, ambiguous save behavior can lead to unintended file creation or overwriting in sensitive locations, even if the author likely intended normal document export.
The instructions require outputs to be '符合日常生活化的语气' and to avoid complex wording in favor of '通俗易懂的日常表达'. This imposes a specific language/register choice by default rather than offering the user a style or locale preference, which matches the policy concern for forced language behavior.
No suspicious patterns detected.