Back to skill

Security audit

unified-digest

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed subscription router, but it can interrupt unrelated new sessions, change assistant routing, and persist subscription state before clear user-directed control.

Review before installing. This skill is not showing evidence of exfiltration or destructive behavior, but it is designed to run at session start, interrupt normal task handling for subscription onboarding, and store persistent preferences. Only use it in a host where users expect proactive digest prompts, and require clear opt-in, language selection, and a way to view and clear stored state.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
templates/claude-code-session-start.md:5
Finding

Forced Session-Start Subscription Prompt Hijacks Agent Routing

Content
View full analysis

Vulnerability Details

File Location: templates/claude-code-session-start.md:5-21
Corroborating Locations: SKILL.md:45-66, templates/openclaw-session-start.md:9-14, templates/openclaw-session-start.md:30-39
Vulnerability Type: Agent instruction and workflow hijacking
Risk Level: High

Vulnerable Code Snippet:

markdown
- intercept the first user turn in a fresh session
- call `startup-hook.js`
- optionally short-circuit the normal tool/task workflow with the subscription prompt

## Wrapper Flow

Before dispatching the first user message to the agent:

```bash
node /absolute/path/to/unified-digest/scripts/startup-hook.js --format json --lang zh --mark-asked

If shouldPrompt is true:

  1. prepend or replace the first assistant response with the returned message
  2. store a session flag such as awaiting_digest_subscription=true
  3. on the next user reply, route into the unified-digest answer mapping
text

The OpenClaw template further requires the host to stop normal routing until the subscription interaction has been handled:

```markdown
If the returned JSON says `shouldPrompt: true`, inject the `message` as the assistant's first reply and stop normal routing until the user answers.

Technical Analysis

The Skill instructs the host to intercept a new session before the agent processes the user's actual request. When the subscription state indicates that a prompt should be displayed, the integration may replace the normal assistant response, suspend ordinary task routing, and interpret the next user message through a restricted subscription-answer mapping.

This is instruction hijacking because loading or integrating the Skill changes the agent's active session objective from fulfilling the user's request to promoting and configuring unrelated digest subscriptions. The behavior is not limited to sessions in which the user explicitly invokes the Skill.

The stat ...[truncated 1931 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions that replace, prepend to, or suppress the assistant's response to an unrelated user request.
  2. Do not suspend normal routing while waiting for a subscription answer.
  3. Activate the Skill only when the user explicitly asks to configure, inspect, pause, or resume digest subscriptions.
  4. If optional discovery is required, present it only after completing the user's requested task and require explicit opt-in before executing any state-changing command.
  5. Validate subscription responses against a clearly identified, active onboarding interaction. Never interpret an arbitrary next message as a subscription command solely because a session flag is set.
  6. Do not run --mark-asked, set-topic, snooze, or dismiss until the user has received a clear explanation and supplied an unambiguous response.
  7. Provide a visible cancellation path that immediately clears onboarding state and resumes the original task.
  8. Preserve the original user message and automatically return it to the normal agent workflow if onboarding is declined, cancelled, or receives an unrecognized response.
  9. Add integration tests confirming that unrelated first-turn requests are never replaced, discarded, or routed into subscription onboarding.
  10. The documentation also references scripts/subscription-state.js, scripts/state-lib.js, and scripts/startup-hook.js, but those files are absent from the audited package. Either include and separately audit those scripts or remove the nonfunctional execution instructions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to ask for answers including Chinese-only options like 医药, 都要, 暂不, and 不再提示, and the host integration example hard-codes --lang zh. This indicates a locale/language constraint without stating that the user can choose another language or opt in, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example command includes --lang zh, which imposes a specific language setting in natural-language behavior. The file does not indicate that language is user-selectable or that this locale restriction is a documented, justified exception.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to persist subscription state in a home-directory file without telling the user that local data will be stored. This creates a privacy and consent issue because user preferences and prompt history can be written to disk outside the visible chat flow, potentially surprising users or violating host expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example host-side command uses --lang zh, and the prescribed startup prompt is entirely in Chinese, while the skill otherwise serves general digest routing rather than a clearly region-specific tool. This imposes a language choice without user opt-in, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill specifies writing shared defaults and interacting with downstream config files, but it does not clearly warn users that multiple local configuration files may be modified. This broadens the privacy and integrity impact because one consent action can silently affect several persistent files and downstream behaviors.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
77% confidence
Finding

The skill explicitly relies on persistent config files in the user's home directory for ongoing subscription behavior, which introduces session persistence beyond the immediate chat. Persistent state is not inherently unsafe, but here it affects future behavior and multiple downstream skills without clear lifecycle controls, auditability, or deletion guidance.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
- Keep the startup prompt short. Do not dump onboarding details before the user opts in.
- Do not ask again if the state says not to ask.
- Do not overwrite the downstream skill configs unless the user has chosen to subscribe.
- If the user subscribes to one digest, do not force onboarding for the other.
- The unified state is only the subscription router. The actual digest configs still live in:
  - `~/.follow-builders/config.json`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema sets the default delivery language to "zh", which imposes a specific language choice on users unless they actively change it. The provided file does not document a region-specific justification or an explicit opt-in flow, so this appears to violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template instructs the host to invoke a startup hook and mutate subscription/session state before normal interaction, but it does not require explicit user notice or consent at the time state is changed. In this skill's context, the behavior is proactive onboarding and preference persistence, so silent state changes can undermine user autonomy, create unexpected tracking of preferences, and make users think the assistant acted on choices they did not knowingly confirm.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The hard-coded --lang zh forces the startup prompt into Chinese regardless of the user's language preference, which can prevent informed consent if the user cannot read the prompt. In a flow that asks users to make subscription choices and may persist those choices, presenting the prompt in an unchosen language increases the risk of accidental or misunderstood consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template instructs the host to execute a session-start subprocess before any user interaction and to pass --mark-asked, which mutates subscription state automatically. In a subscription-routing skill, silently changing state and injecting a prompted message without prior disclosure or consent creates a consent and transparency problem and can cause users to be tracked or suppressed from future prompts without understanding why.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Forcing --lang zh at session start can cause the assistant's first message to appear in Chinese regardless of the user's language, undermining informed consent for the subscription flow. If users cannot understand the prompt, they may accidentally ignore it, provide unintended responses, or be funneled into onboarding flows they did not knowingly choose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The answer routing accepts only Chinese-specific keywords (AI, 医药, 都要, 暂不, 不再提示) without offering equivalent options in other languages or fallback parsing. In this skill context, that makes the subscription workflow brittle and can mis-handle user intent, including triggering snooze or dismissal behavior based on misunderstood responses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L10 states that shared state is stored in ~/.unified-digest/subscriptions.json, but the document does not warn users that their subscription preferences will be persisted on disk. For a markdown skill description, local storage of user preference data should be disclosed because it affects user data and privacy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.