Back to skill

Security audit

Todos

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward local todo manager that stores tasks in a disclosed JSON file, with no evidence of hidden network access, privilege escalation, or destructive behavior beyond user-directed todo edits.

Before installing, confirm you are comfortable with the skill creating and modifying ~/.openclaw/workspace/memory/todos.json. Use explicit commands for completion and deletion, and be aware that the interface is written in Chinese and the script help text has a minor filename mismatch.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description understates the actual behavior by omitting fixed-path storage in the user's home directory and more advanced query and metadata handling. When a skill's documented purpose does not accurately match its effective capabilities, users may authorize or invoke it without understanding the extent of persistent data processing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill performs file reads and writes to a persistent path but does not declare any tool scope or permissions boundary. This weakens reviewability and user consent, and can lead to unexpected persistent modification of local data when the skill is invoked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The display name, description, trigger phrases, and command examples are all presented only in Chinese, with no indication that users may interact in other languages or that the skill is intentionally limited to a Chinese-only context. This can constitute a language policy issue when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description mentions storage and deletion but does not clearly warn that actions persistently modify a local JSON file. Users may treat interactions as ephemeral and unintentionally create, alter, or remove records on disk without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad trigger phrases like common everyday words can cause accidental activation in unrelated conversations. Because this skill writes and deletes persistent local data, unintended invocation can result in unauthorized or mistaken changes to the user's todo store.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code's description and all user-facing CLI messages are written in Chinese, which imposes a specific language on users. Under the policy, locale-specific behavior should either provide user opt-in/choice or be clearly documented as a justified regional constraint, neither of which is present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring says 'notebook - 待办事项管理脚本', and the usage text later refers to 'notebook.py' rather than the actual todos skill/file. This is an active documentation mismatch that can mislead users or integrators about what component they are invoking, even though the underlying behavior is still todo management.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The help output repeatedly tells users to invoke 'notebook.py', while the analyzed file is 'scripts/todos.py'. This is a direct intent/documentation mismatch in user-facing guidance, not just an omission, and may cause incorrect integration or execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.