Back to skill

Security audit

Openclaw Coach

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed OpenClaw coaching automation that writes synced docs and sends scheduled tips, with some rough edges but no artifact-backed malicious behavior.

Install this only if you want a Chinese-language OpenClaw coach that can run on a schedule, download OpenClaw docs from GitHub, overwrite files under ~/Obsidian/Docs/OpenClaw, and send tips through an OpenClaw/Feishu message target. Back up that Obsidian folder or review the scripts first if local note overwrites would be disruptive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The description claims a multi-function automation skill with four main behaviors, including documentation sync to Obsidian and version update detection. The actual code shown is a minimal event handler that dispatches to three subordinate scripts based on an argument. While the event names loosely align with sync and tip-related features, the supplied chunk does not implement or demonstrate the core declared capabilities, especially version update checking. Because the declared primary purpose is much broader than the observable behavior in this code chunk, this is a description-to-code mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code partially matches the declared purpose: it does perform documentation synchronization into an Obsidian path and retrieves version information. However, major declared behaviors are absent: there is no scheduling logic in the code chunk, no mechanism to send daily tips, no evening interactive prompt, and no actual update reminder/notification. Additionally, the declared sync source is the 'official website,' while the implementation fetches documents from GitHub raw content and release metadata from the GitHub API. Because substantial advertised functionality is not represented in the supplied code and the resource source differs materially, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises and routes shell-script execution but does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization gap where a host may permit broader execution than users expect, especially for scheduled and event-driven tasks that run automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description does not clearly warn that it will automatically synchronize external documentation into the user's Obsidian knowledge base. That weakens informed consent and increases the risk of unwanted data modification, content pollution, or trust in externally sourced material being silently imported into a personal notes system.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill binds automatic actions to generic events like 'sync', 'pick-tip', and 'send-tip' without any visible scope restrictions, origin checks, or confirmation requirements. In an event-rich environment, this can cause unintended or attacker-triggered execution of shell-backed workflows, especially because the mapped actions invoke scripts directly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment implies the file records the presented choices so that tomorrow's tip can be determined from the user's selection. In reality, the script immediately writes only SELECTED[0] to daily-tips.json before any user reply is processed, which contradicts the stated intent of preserving the user's chosen topic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line 35 overwrites the entire daily-tips.json file using shell redirection. While the script comments say it records options for tomorrow, there is no explicit warning, confirmation, or user-facing disclosure that existing file contents will be replaced, which is a safety-relevant file write operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script's natural-language content is entirely in Chinese, including operational comments and user-facing error/output messages. The file does not offer any user language choice or document that the skill is intentionally limited to a Chinese-speaking environment, which matches the policy-violation category for forced language/locale without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script writes fetched remote content directly into files under the user's Obsidian directory using shell redirection. Although there is progress logging, the messages only mention syncing/downloading and do not clearly warn that existing local files will be overwritten.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sync-docs.sh (reported line 67)May include surrounding context.

sh
done

# 获取版本信息
VERSION=$(curl -s "https://api.github.com/repos/openclaw/openclaw/releases/latest" 2>/dev/null | grep -oE '"tag_name": "[^"]+"' | cut -d'"' -f4)
if [[ -n "$VERSION" ]]; then
    echo "$VERSION" > "$OBSIDIAN_PATH/latest-version.txt"
fi

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The user-interaction flow describes scheduled outbound messages and recording user selections, but there is no visible privacy notice explaining what is stored, for how long, or how it is used. While lower severity, this can still surprise users and create avoidable privacy and trust issues around behavioral logging.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script's user-facing output and inline documentation are entirely in Chinese, including the prompt shown to the recipient and the environment-variable warning. Under the stated policy, forcing a specific language without opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest describes documentation sync, tip delivery, topic selection, and version-update reminders. While sending a message is in scope, pulling a target identifier from an environment variable is an additional capability not stated in the skill purpose and is not obviously required from the manifest text alone.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes daily document sync, tip teaching, topic selection, and version-update reminders, but does not mention Feishu integration or use of an environment-provided messaging identity. Reading a specific external messaging target from an environment variable introduces an integration capability beyond the stated purpose of an OpenClaw coach skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script's comments and user-visible echo output are entirely in Chinese, which imposes a specific language on users without any opt-in or documented regional requirement. Under the stated policy, forcing a language without choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script stores the latest release version into a local file under the user's Obsidian path. While the script prints general sync status, it does not specifically disclose that it will create or overwrite this file as part of its operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.