Back to skill

Security audit

Clawdbot Personas

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed persona switcher that reads bundled persona prompts and saves only local persona state, with some usability cautions around broad triggers and German-language personas.

Install only if you want an assistant that can switch into persistent persona modes. Prefer explicit /personas commands, check the active persona if responses seem unusual, and be aware that several personas may answer in German and that medical/legal personas are educational only.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises local file read/write behavior via its CLI and state handling (--show reads persona files and --activate/--reset write ~/.openclaw/persona-state.json), but no permissions are declared in the manifest. That creates a transparency and policy-enforcement gap: users or the platform may treat the skill as low-privilege while it performs filesystem operations, increasing the risk of unintended file access if the implementation is looser than documented.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The exit phrase "Back to normal" is a broad natural-language trigger that can easily appear in ordinary conversation, making accidental deactivation of persona mode plausible. In a skill that switches behavior based on active persona state, ambiguous exit triggers can be exploited through prompt injection or incidental phrasing to alter system behavior without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Examples like "Use Dev," "Switch to Chef Marco," and "Activate Dr. Med" suggest broad free-form activation language without clear command scoping. This increases the risk that normal dialogue, quoted text, or attacker-supplied content could trigger unintended persona activation and change the assistant's behavior or response style.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that trigger matching is based on phrases in the skill description, with examples including generic words like "activate" and "switch to." Broad natural-language triggers without explicit boundaries can cause unintended persona activation during ordinary conversation, changing assistant behavior without clear user intent. In a persona-switching skill, that can indirectly affect safety posture, tone, or domain guidance presented to the user.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description registers very generic trigger phrases such as activate, switch to, and exit persona, which can plausibly appear in ordinary conversation. This can cause unintended skill activation or persona switching, leading to prompt/context changes the user did not intend and making the assistant easier to steer through accidental or adversarial phrasing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented activation phrases are very generic terms such as "use", "switch to", and "activate", which can appear in ordinary user conversation. If the host system binds these phrases directly to persona switching, an unrelated prompt or quoted text could unintentionally change the agent's behavior, causing context confusion, bypass of user expectations, or activation of a higher-risk persona such as medical, legal, or cybersecurity guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The persona definition hard-codes German-language behavior ("Du bist Cami...") without asking the user for their preferred language or preserving the conversation language. This can cause accessibility, usability, and policy-compliance issues by unexpectedly forcing responses into German, especially in multilingual or enterprise contexts where clarity and user choice matter.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill content is entirely in German and instructs the assistant to act in that language without any user language choice or opt-in. This can override a user's preferred language, reduce comprehension, and cause misleading or inaccessible guidance, especially in a career-advice context where nuanced understanding matters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill opens with a hard instruction in German ('Du bist...') and all subsequent operating guidance is written as mandatory behavior in German, without indicating that the assistant should respect the user's language preference. This can override or conflict with the surrounding system/application expectations, causing unintended language switching, degraded usability, and possible misunderstanding of safety-critical instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The persona is written entirely in German and explicitly instructs the assistant to act in that language/style, which can override a user's preferred language if the orchestration layer injects the skill without consent. This is not inherently malicious, but it can cause confusing or inaccessible responses and reduce user control over output behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The phrase describing when this persona should activate is broad and maps to ordinary user requests such as asking for brainstorming help or to think differently. In a multi-persona skill, overly generic activation language can cause unintended persona switching, which may override the expected assistant behavior without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The persona content is written entirely in German and instructs the assistant in that language without any indication that the user requested a language change. This can cause the assistant to respond in an unexpected language, reducing usability and potentially causing misunderstanding or loss of important safety context for users expecting another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The persona is written entirely in German and directly instructs the assistant to adopt that mode, which can override the user's preferred language without explicit opt-in. In a multi-persona skill, this can cause confusing or inaccessible responses and may interfere with higher-priority user intent, even though the content itself is otherwise harmless.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill content is written entirely in German and frames the assistant as 'Du bist Wordsmith', which can steer interactions into German without explicit user opt-in. This is not a code-execution risk, but it can degrade usability, override user language preferences, and cause confusing or inaccessible behavior in multilingual environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.