Back to skill

Security audit

Business Analyst Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a business analytics prompt package, not malware, but it needs Review because it handles sensitive company finance data and points agents at broad memory/storage without clear consent or scoping.

Review before installing in an agent with persistent memory or connected business systems. Use only scoped, approved company datasets; avoid secrets and personal data; do not let it read general agent memory; and add privacy, retention, and access-control rules before using Supabase, CRM, Sheets, 1C, or testimonial storage. Also fix the broken shell scripts and missing .env.example before relying on the installer.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:351
Finding

Unrestricted Access to Agent Memory for Financial Analysis

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:351
Vulnerability Type: Unrestricted access to Agent memory
Risk Level: Medium

Vulnerable Code Snippet

markdown
- **OpenClaw / VPS** — historical data from memory/ агента → trends and forecasts

English translation:

text
OpenClaw / VPS — historical data from the Agent's memory/ → trends and forecasts

Technical Analysis

The Skill instructs the Agent to use historical data from the general memory/ area when producing trends and forecasts. It does not:

  • restrict access to a Skill-specific directory;
  • identify the records that may be read;
  • require explicit user authorization;
  • limit retrieval to the current company or conversation;
  • exclude credentials, unrelated conversations, or other sensitive records.

A shared Agent memory may contain information from unrelated sessions, users, companies, or tasks. Treating that entire location as an analytics data source violates least-privilege principles. The legitimate task only requires financial records explicitly supplied by the user or stored in a dedicated, scoped dataset.

The repository does not include code that independently reads this directory, so exploitation depends on the host Agent interpreting and acting on the Skill instruction. No network exfiltration mechanism was identified.

Attack Path

  1. A user or operator installs and loads the Skill in an OpenClaw/VPS Agent that has access to persistent memory.
  2. The Agent's memory/ area contains historical information from other conversations or business activities.
  3. A user requests a trend analysis or forecast.
  4. Following SKILL.md:351, the Agent searches or reads the general memory area as a historical data source.
  5. Unrelated sensitive information is incorporated into calculations, summaries, assumptions, or generated reports.
  6. The requesting user may infer or directly receive information that was not intended for the current analysis.

Impact

...[truncated 583 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to access the general Agent memory/ directory implicitly.

  2. Require explicit user consent before reading persistent historical information.

  3. Store Skill data in a dedicated location, such as:

    text
    memory/business-analyst-pro/<tenant-or-company-id>/
    
  4. Enforce tenant, company, and user ownership checks before every read.

  5. Allow users to select or approve the exact files and periods used for analysis.

  6. Restrict retrieval to an allowlist of financial data types required for the requested report.

  7. Exclude credentials, tokens, integration configuration, unrelated conversations, and free-form Agent state.

  8. Record data provenance in generated reports so users can verify which records were used.

  9. Prefer current-session data or explicitly uploaded datasets when persistent history is unnecessary.

  10. Add host-level permission controls so the Skill cannot access memory belonging to another user or company.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (88)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes an end-user business analytics capability, but the supplied code does not implement analytics, dashboards, forecasting, reporting, or any CEO-facing business logic. Instead, it is purely a build/packaging automation script for assembling and validating a release ZIP. This is a materially different primary purpose and includes undeclared capabilities related to file system operations, archiving, and test execution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents an analytics skill focused on financial/business reporting capabilities. However, the actual code chunk does not implement KPI dashboards, forecasting, P&L, cash flow, cohorts, or investor reporting. It is purely an installer/setup script for deploying the skill locally. While installation can be a supporting component of a skill package, this specific code chunk's behavior is materially different from the declared purpose because it performs filesystem operations and environment setup rather than business analytics. Therefore, the description does not accurately represent what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents an end-user business analytics capability. However, the actual code does not compute KPIs, build dashboards, perform forecasting, analyze cohorts, or produce financial/investor reports. Instead, it is purely a local validation script for the skill/package itself. This is not merely a supporting implementation detail of analytics behavior; its primary purpose is QA/packaging verification and marketplace compatibility checks, including unrelated checks for required documentation, marketing assets, and manifest fields. Therefore the code chunk does not accurately represent the declared business analytics purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 30)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 32)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля
echo ""

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The changelog text is written in Russian throughout, including the primary heading and notes, with no indication that language selection is optional or that the skill is intentionally region-specific. This can violate language/locale policy because it implicitly constrains users to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly instructs users to populate config.yaml with real company identity and financial data, but provides no privacy notice, storage guidance, masking recommendation, or retention policy. This increases the chance that sensitive business information is stored in plaintext, committed to source control, shared in support channels, or exposed to other tools in the skill environment.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description explicitly targets Russian-speaking CEOs, and the skill content and triggers are written to operate in Russian without offering an alternative language or an opt-in choice. Under the policy, forcing a specific language without user choice is a natural-language locale constraint that should be either optional or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad triggers like 'покажи цифры', 'как дела с деньгами', and 'сводка' can activate the skill during ordinary conversation, causing unintended analysis of whatever business data is in context. In a skill handling potentially sensitive financial information, accidental activation can lead to over-collection, unnecessary retention, or disclosure of confidential metrics in the wrong conversational context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Triggers such as 'ключевые метрики' and 'как бизнес' are highly ambiguous and likely to appear in normal discussion. This raises the chance that the skill will parse and structure sensitive company performance data without a clear user intent boundary, which is risky in executive or mixed-topic chats.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Generic comparison triggers like 'динамика' or 'что изменилось' can match normal business conversation and unintentionally invoke retrospective analysis across periods. That can surface sensitive financial or customer trend data in contexts where the user did not explicitly request structured reporting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly invites users to input revenue, expenses, customer counts, CAC, MRR, cohorts, and investor-report data, but provides no warning about confidentiality, retention, third-party storage, or safe handling practices. For CEO-facing finance workflows, this omission materially increases the chance of users sharing regulated, confidential, or investor-sensitive business data without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quick-start phrase 'что улучшить?' is extremely broad and common in ordinary consulting dialogue, making unintended activation likely. Because the skill is designed to generate prioritized business actions from financial context, an accidental trigger could cause the model to infer, summarize, or expose sensitive operational weaknesses without an explicit analytics request.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Most of the descriptive content, headings, and metadata are presented in Russian, while the skill itself is not documented as region-specific or Russian-only. This can violate language/locale policy expectations when no user opt-in or alternative language option is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very generic business phrases such as 'Build a financial model', 'Analyze our P&L', and 'Forecast revenue', which can match ordinary user requests outside a narrowly intended invocation context. This can cause accidental activation or routing to this skill when the user did not explicitly intend it, increasing the chance of inappropriate data collection, misleading outputs, or workflow interference in multi-skill environments.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file presents core skill metadata and instructions in Russian script and phrasing without offering any language choice or stating that the skill is region-specific. That creates a natural-language locale policy concern because the skill appears to impose a specific language context on users by default.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.