Back to skill

Security audit

Personas

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local persona switcher with narrow state storage and no evidence of network access, credential use, hidden execution, or destructive behavior.

Install this if you want persona switching, but prefer explicit /persona commands to avoid accidental activation. Remember that the selected persona can persist until you exit or reset it, some personas may respond in German, and medical, legal, fitness, cybersecurity, or career personas should be treated as general guidance rather than professional advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill advertises executable CLI behavior that reads bundled persona files and writes active state to `~/.openclaw/persona-state.json`, yet no permissions are declared. This creates a transparency and policy-enforcement gap: the runtime may perform file reads/writes users and reviewers were not clearly warned about, which can enable unintended state persistence or unsafe assumptions about capability boundaries.

Vague Triggers

Low
Confidence
86% confidence
Finding
The FAQ documents a natural-language exit phrase, "Back to normal," that is broad enough to occur in ordinary conversation and could unintentionally deactivate a persona. In a skill that switches behavior based on active persona state, ambiguous control phrases can be triggered accidentally or by prompt injection embedded in user-visible content, causing unintended state changes.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Triggers such as `use persona`, `switch to`, `activate`, and `exit persona` are broad natural-language phrases likely to appear in ordinary conversation. This can cause unintended skill activation or deactivation, changing assistant behavior without clear user intent and increasing the chance of prompt-routing confusion or abuse through crafted conversation text.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage examples encourage activation via ambiguous conversational phrases like `Use Dev`, `Switch to Chef Marco`, and `Activate Dr. Med`, reinforcing trigger patterns that can be matched accidentally in normal dialogue. In a persona-switching skill, unintended routing is especially risky because it changes the system’s response style and constraints mid-conversation, potentially affecting safety-sensitive topics like medical or legal orientation personas.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The natural-language activation examples are broad enough that ordinary user phrases like "use Dev" or "switch to Chef Marco" could trigger persona changes unintentionally. In a skill that alters agent behavior, ambiguous triggers can cause unauthorized mode switching, change safety posture, or load a less appropriate persona for the current task.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The persona explicitly instructs the agent to respond in German ('Du bist Cami...'), which can override or conflict with the user's preferred language if no locale constraint is documented. This is a policy and UX safety issue because it can reduce accessibility, cause misunderstandings, and make the assistant behave unexpectedly outside the intended audience.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The persona is written entirely in German and explicitly instructs the agent to operate as a German-speaking chef, which can override the user's preferred language without consent. This is primarily a safety and usability issue because it can reduce transparency, cause misunderstanding, and interfere with higher-priority user instructions about language.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The persona definition explicitly instructs the assistant to operate in German ('Du bist Dev'), which can override or conflict with the user's language preference if activated without consent. This is risky because it can degrade usability, cause misunderstandings in technical guidance, and violate expected language or accessibility preferences across a conversation.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to respond in German ('Du bist Flash') without any user opt-in or locale check. This can override user expectations or system behavior, causing confusing, inaccessible, or policy-misaligned responses, especially in multilingual deployments.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The persona definition begins in German and frames the assistant identity and behavior entirely in German, without explicitly offering the user a language choice or opt-in before interaction. In a multi-persona system this can cause unwanted language switching, reduce accessibility, and override user expectations or higher-priority instructions about response language, though it is not a code-execution or data-exfiltration risk.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The persona content is written entirely in German and instructs the assistant to adopt German-language behavior without any user-choice mechanism in the file. This can cause unexpected language switching, reduce transparency, and make the assistant less aligned with user expectations, though it is not directly a code-execution or data-exfiltration risk.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The persona prompt explicitly states 'Du bist Startup Sam' and the rest of the instructions are entirely in German, which strongly steers the agent into German-only interaction without asking for the user's preference. This can reduce usability, misalign responses with user expectations, and create prompt-level rigidity that may interfere with correct task handling in multilingual contexts.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill hard-codes German-language behavior ('Du bist Vibe') without checking the user's preferred language or offering a choice. This can override user expectations, reduce accessibility, and create prompt-level control conflicts where the persona steers interactions in an unintended language.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The persona instructions are entirely in German and implicitly direct the assistant to operate in German without offering user choice. This can override or conflict with the user's preferred language, causing usability, accessibility, and policy-compliance issues in multilingual environments, though it does not appear to introduce code execution or data exfiltration risk.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases include very generic terms such as "switch to" and especially "activate", which are common in normal user conversation and can cause the skill to load unintentionally. In a persona-switching skill, accidental activation can alter model behavior, tone, and response constraints mid-conversation, creating prompt-injection-like control over the assistant without explicit user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description advertises broad capability switching 'on demand' and mid-conversation behavior without embedding clear activation constraints in the metadata. In agent ecosystems that rely on descriptive metadata for discovery or invocation, ambiguous language can cause unintended activation or over-broad routing, increasing the chance that the skill is invoked in contexts the user did not explicitly intend.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.