Back to skill

Security audit

Openclaw Diary Setup

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real diary setup guide, but it asks for broad installation, cloud credentials, and personal-data imports in ways that need careful review before use.

Review this skill before installing. Use it only if you are comfortable with global package installation, local storage of diary/profile data, and optional cloud-service credentials. Prefer manual, pinned installs; do not paste long-lived secrets into chat; avoid shell-profile secrets; and do not use broad import options unless you have reviewed each source and destination path.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T08 · Insecure Dependencies

Error
Location
SKILL.md:71
Finding

Unpinned Global Installation of Third-Party Packages and Skills

Content
View full analysis
/dev/null; then echo "Installing ClawHub CLI..." npm install -g clawhub fi # Install dependent skills clawhub install openclaw-diary-core clawhub install openclaw-diary-insights ``` Additional global installation instructions include: ```bash npm install -g @anthropic/google-workspace-mcp npm install -g @notionhq/notion-mcp npm install -g mcp-obsidian npm install -g @anthropic/slack-mcp npm install -g twitter-mcp npm install -g dbx-mcp-server npm install -g mcp-rss-aggregator ``` ### Technical Analysis The onboarding instructions direct the Agent to globally install packages and additional Skills without pinning exact versions, validating package integrity, verifying publisher identity, or presenting the resolved artifacts for user review. Global installation increases the effect of a compromised package because its executables become available throughout the user environment. The behavior of an unpinned package can change after this Skill has been reviewed. A malicious package release, compromised publisher account, dependency-confusion event, or compromised transitive dependency could therefore introduce arbitrary installation or runtime behavior without requiring any change to this repository. The installed MCP packages are particularly sensitive because they are intended to access Gmail, Google Drive, Notion, Slack, Dropbox, Twitter, and local files using user credentials. ### Attack Path 1. An attacker compromises a referenced npm package, ClawHub Skill, publisher account, or transitive dependency. 2. The attacker publishes a malicious version under the sam ...[truncated 1093 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:694
Finding

Cloud Credentials Collected Through Chat and Stored in Plaintext

Content
View full analysis
> "$RC_FILE" echo 'export FEISHU_APP_SECRET="xxx"' >> "$RC_FILE" # Reload source "$RC_FILE" ``` ### Technical Analysis The workflow asks users to submit Feishu App Secrets, Notion integration tokens, and Flomo API tokens directly in the conversation. It then embeds those credentials in a regular JSON configuration file. No restrictive file permissions, encryption, keychain integrat ...[truncated 2074 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
importers/feishu_importer.md:69
Finding

Untrusted Imported Documents Can Poison Persistent Agent Identity and Memory

Content
View full analysis
Click to view original content imported from Feishu # About Me I am a software engineer focused on web development and AI applications. ## Professional Background - Five years of web development experience - Familiar with React and Node.js - Currently exploring AI application development ## Goals - Become a full-stack engineer - Build impactful products ## Interests - Reading technical blogs - Open-source contributions - Running ``` The broader import pipeline is documented as: ```text source data → markdown → memory chunk → memory graph ``` ### Technical Analysis The importer sends externally sourced document text into an AI extraction prompt and persists both structured output and raw source material in identity or memory storage. It does not define a trust boundary between instructions supplied by the Skill and text originating from imported documents. A malicious or compromised document can contain prompt-injection text instructing the model to ignore the extraction task, alter the user's identity, disclose secrets, or create behavioral rules. Because the resulting material is written into identity and memory locat ...[truncated 1870 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
importers/digital_life_import.md:183
Finding

Automatic Cross-Project Memory and Local Knowledge-Store Reconnaissance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (27)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill goes beyond onboarding dialogue and instructs the agent to install software globally (npm install -g clawhub) and fetch additional skills. This expands system modification scope, introduces supply-chain risk from external packages, and allows persistent changes on the host during what users would reasonably expect to be a configuration workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is described as a diary onboarding wizard, but this file expands scope into broad ingestion from email, chat, cloud storage, social media, and other external systems. That mismatch is dangerous because users invoking a low-risk setup flow may unknowingly grant access to large volumes of sensitive personal and organizational data far beyond what is needed for initialization.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document claims the importer is only for profile/identity documents, but later implementation logic searches for and imports diary documents instead. This mismatch can cause the agent to access and persist far more sensitive content than the user expected, creating a scope-creep and consent failure around highly private journal entries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The onboarding skill is supposed to guide setup, but this section instructs importing personal profile data from Feishu and writing it into a local identity file. That expands the skill from configuration into collection and persistence of sensitive user data, increasing privacy and data-handling risk well beyond the declared purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · importers/feishu_importer.md (reported line 220)May include surrounding context.

json
{
  "code": 99991663,
  "msg": "app access token invalid"
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill documentation is entirely in Chinese and the configured trigger phrases are primarily Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented setup goes beyond generating journal configuration by modifying global shell environment state. An onboarding skill should not silently change persistent execution environment for the whole user account, because this creates system-wide side effects unrelated to the minimum function of configuring the diary tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs the onboarding flow to append FEISHU_APP_ID and FEISHU_APP_SECRET directly into the user's shell startup file and reload it. Persisting third-party credentials in global rc files is broader than the stated journal setup task and increases exposure to accidental disclosure, inheritance by unrelated processes, and long-term secret sprawl.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README recommends storing credentials in shell rc files without warning about the security risks. Secrets placed in plaintext startup files can be exposed through backups, dotfile sync, local inspection, shell history workflows, or accidental sharing, making credential compromise more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and all prescribed user-facing prompts are written in Chinese, and trigger/reply expectations such as replying with Chinese terms like 「是」「否」「跳过」 indicate a fixed language mode. There is no indication that users may choose another language or that the locale restriction is intentional and documented as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The stated interaction principle says the skill relies only on plain-text conversation, which implies no tool-dependent operational behavior. Later instructions directly tell the agent to use Bash for system inspection and modification, so the documentation actively understates and contradicts the real implementation approach.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

使用 Bash 工具检查:

bash
ls -la ~/.openclaw/skills/diary 2>&1 && ls -la ~/.openclaw/skills/note-extractor 2>&1

如果任一 skill 不存在:

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · importers/feishu_importer.md (reported line 291)May include surrounding context.

使用 Bash 工具检查:

bash
ls -la ~/.openclaw/skills/diary 2>&1 && ls -la ~/.openclaw/skills/note-extractor 2>&1

如果任一 skill 不存在:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill collects highly sensitive third-party credentials such as App Secret, Integration Token, and API Token directly in chat and plans to store them in local configuration. Secrets entered into conversational flows may be exposed through logs, transcripts, debugging, or accidental redisplay, and the guidance does not require a safer secret-entry mechanism before collection.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 676)May include surrounding context.

使用 Bash 工具创建必要的目录:

bash
mkdir -p ~/.openclaw/workspace/diary/config
mkdir -p ~/.openclaw/workspace/diary/personalities
mkdir -p ~/write_me/00inbox/journal
mkdir -p ~/write_me/01studio/me

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes importing and centralizing highly sensitive personal data from multiple sources, then storing it under a local memory root, but it does not clearly warn users about the privacy, consent, retention, and access risks of aggregating emails, documents, chats, and identity data. In an onboarding/setup skill, this omission is security-relevant because users may authorize broad access without understanding what data will be collected, persisted, and potentially exposed if the host is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs users to install multiple third-party MCP servers and configure tokens, OAuth credentials, secrets, and local integration settings, which exceeds a pure text onboarding role. This increases attack surface by normalizing credential handling and dependency installation in a context where users may not expect security-sensitive setup steps.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · importers/digital_life_import.md (reported line 116)May include surrounding context.

text

**获取 Bot Token**:
1. 访问 [Slack API](https://api.slack.com/apps)
2. 创建新应用
3. 添加 Bot Token Scopes
4. 安装到工作区

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The import commands, especially bulk actions like /import-data --all, can ingest large amounts of personal, corporate, and credential-adjacent data into local directories without strong warnings about scope, sensitivity, or persistence. In an onboarding-related context, that can cause users to over-collect data and create high-value local stores containing emails, documents, chats, and possibly auth artifacts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The privacy claim that sensitive data stays local and is not uploaded to the cloud is misleading in the context of connectors to Gmail, Google Drive, Slack, Notion, Dropbox, Twitter, and similar remote services. Users may make authorization decisions based on a false expectation of locality and privacy, which undermines informed consent and can expose sensitive data to external platforms and connector infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill describes importing deeply personal profile content and later storing it locally, but does not present an upfront privacy warning or explain local persistence before collection begins. Users may consent to search/read access without realizing their identity information will be copied into local storage and retained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide requires Feishu App ID and App Secret handling but does not clearly warn users that these are sensitive credentials that must not be exposed in chat, logs, or generated files. Poor handling of these secrets could enable unauthorized access to Feishu resources beyond the intended import operation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs storing the full original Feishu document content, including personal identity details, inside a local file in addition to extracted structured fields. This increases data retention, duplicates sensitive content, and broadens exposure if the local filesystem is accessed by other tools, users, or backups.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The error-handling and test sections continue to describe diary import behavior, reinforcing the same scope confusion present elsewhere in the file. In practice, this can normalize importing journal data under a profile-import feature and lead operators or future implementers to process unintended sensitive content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file's instructional content is written entirely in Chinese, but there is no indication that the skill is region-specific or that users can choose another language. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.