Back to skill

Security audit

Summarize Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a local summarization skill with disclosed local history/settings storage and no evidence of network exfiltration or deceptive behavior.

Before installing, understand that the skill keeps local usage history and stats automatically under ~/.openclaw/summarize-pro/. Avoid using it on highly sensitive text if local retained metadata is unacceptable, and periodically review or delete its history/settings files if you do not want that record kept.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description claims it should handle "any long content" and many broad phrasings, which creates an overly permissive activation boundary. In practice this increases the chance of accidental invocation on unrelated user text, and because the skill includes automatic history/stat tracking, unintended activation can also create privacy and persistence risks.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This skill establishes persistent local state on first use by creating a dedicated directory and files under the user's home directory. Persistence itself is not always unsafe, but here it becomes a real issue because summaries, usage history, and preferences are stored automatically, increasing the privacy impact of accidental activation or use on sensitive content.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

First Run Setup

On first message, create data directory:

bash
mkdir -p ~/.openclaw/summarize-pro

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill initializes local storage and later instructs itself to auto-log every summary, but the first-run/setup flow does not obtain clear user consent before retaining content-derived metadata and saved summaries. Even without network exfiltration, silent retention of sensitive meeting notes, emails, or document summaries can create a local privacy exposure and surprise users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrase "summary" is extremely generic and can appear in ordinary conversation, causing the skill to activate when the user did not explicitly request this tool. Unintended activation matters here because the skill is stateful and writes history/settings data locally, so casual mentions could lead to unexpected processing and retention of user content.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

Custom templates are another form of session persistence because user-defined formats are stored and reused across sessions. While less sensitive than raw summaries, these templates can still encode business workflows, project names, or internal structure, and they extend the skill's retained state beyond immediate user expectations.

Content

Scanner excerpt · SKILL.md (reported line 555)May include surrounding context.

md
## FEATURE 19: Custom Templates

When user says **"create template [name]"** or **"my templates"**:

Let users define their own summary format:

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

md
When user says **"summarize in [language]"** or **"hindi mein summarize karo"**:

Supported languages include but not limited to:
Hindi, Spanish, French, German, Japanese, Chinese, Arabic, Portuguese, Italian, Korean, Russian, and more.

Summarize the content and output the summary IN the requested language.

Static analysis

No suspicious patterns detected.