Back to skill

Security audit

🖊️ 语文写作教练

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent Chinese writing tutor, but it stores student writing progress and profile data with unclear user controls, so it should be reviewed before installation.

Install only if you are comfortable with the platform storing student essay topics, drafts or progress, writing-style profiles, and grammar weakness records for future tutoring. Confirm that OpenClaw exposes consent, deletion, and disable controls for the learning-DNA and recovery features, especially if minors will use it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The state machine explicitly persists essay topic, step progress, collected student outputs, and later updates a long-term writing DNA/profile, but this file does not enforce the manifest’s stated requirement that long-term tracking only occurs after explicit user consent. In an education context this can expose minors’ writing samples and behavioral/profile data across sessions without a clear opt-in boundary, creating privacy and compliance risk rather than direct code-execution risk.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The instruction '凡是涉及写作、作文、议论文论证、辩论思辨的语文场景,务必调用此SKILL' creates an overbroad auto-invocation rule that can hijack many normal Chinese-language education interactions. This can cause the agent to activate the skill without clear user intent, increasing the chance of unnecessary memory use, inappropriate workflow enforcement, or unintended handling of student content.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad everyday phrases such as '帮我批改' and '写作思路卡住了', which are ambiguous and may match contexts outside the intended skill scope. Ambiguous triggers can lead to false activations, causing the assistant to apply restrictive writing workflows or collect writing-related signals when the user may have meant a different task.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes broad natural phrases such as asking for help with writing, brainstorming, or revision, which can cause the skill to activate in situations where the user did not clearly intend this specialized workflow. That raises the risk of unexpected collection of writing-related data and unwanted behavior changes, though the impact is mostly privacy and UX-related rather than severe security compromise.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The file defines persistent storage of current step, progress, collected outputs, timestamps, and recovery behavior across sessions, but there is no user-facing notice here that such data will be retained. In the context of student essays, this omission is sensitive because users may reasonably assume tutoring interactions are transient, while the system is actually keeping identifiable educational content and progress metadata.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.