Back to skill

Security audit

Curriculum Designer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its curriculum-design purpose, but it tells agents to make generated Google Sheets public and includes optional persistent cleanup jobs that recursively delete checkpoint data.

Review before installing. Do not let it make Google Sheets public unless that is explicitly intended, and avoid adding the cron cleanup job unless you accept recurring deletion of old checkpoints. Use a scoped YouTube API key and confirm the resource language defaults fit your learners.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:545
Finding

Generated curriculum spreadsheets are unconditionally exposed through anonymous public sharing

Content
View full analysis
--to anyone --role reader` ``` ### Technical Analysis The Skill explicitly instructs the agent to change each generated spreadsheet's access-control list to permit anonymous Internet-wide read access. The instruction is unconditional and does not request the user's consent, evaluate the sensitivity of the curriculum, or offer a restricted-sharing alternative. Public access is not required to perform the declared curriculum-design function. A spreadsheet could remain private, be returned to its owner, or be shared with specified users or an approved organization domain. Consequently, the instruction exceeds the minimum permissions necessary for the task. Generated content can include POD names, target-audience details, subject requirements, teacher capability information, and organizational curriculum plans. Although the granted role is read-only, it removes authentication and authorization boundaries for that information. ### Attack Path 1. A user invokes the Skill to create a curriculum. 2. The workflow gathers potentially organization-specific educational and teacher-context information. 3. The Skill creates a spreadsheet using the authenticated user's Google account. 4. The documented command changes the spreadsheet ACL to `anyone` with the `reader` role. 5. The public URL is returned or otherwise distributed. 6. Any party that obtains the URL can read the spreadsheet without ...[truncated 895 chars]
Remediation
View remediation

T06 · System Persistence

Warning
Location
SKILL.md:636
Finding

Optional persistent cleanup jobs perform unattended recursive deletion

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (24)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

Option 1: Specify model when calling agent

bash
# Use glm-5 for research stage
agent.chat --model glm-5 --message "Research YouTube videos for..."

# Use glm-4.7 for design stage
agent.chat --model glm-4.7 --message "Generate lesson structure..."

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

agent.chat --model glm-5 --message "Research YouTube videos for..."

Use glm-4.7 for design stage

agent.chat --model glm-4.7 --message "Generate lesson structure..."

text

**Option 2: Configure in SKILL.md**

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions require public accessibility without warning the user that anyone with the link may access the sheet. Because the sheet may contain requirement data, teacher context, and other operational details, silent public sharing can cause unintended disclosure.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 636)May include surrounding context.

ile - NEVER commit this file to git!**


Future Improvements

  1. Resume from specific stage - Ability to jump to any stage, not just first failed one

Automatic Checkpoint Cleanup (Cron Job)

Purpose

Delete checkpoint directories older than 7 days to prevent disk space bloat while keeping recent sessions for debugging.

Cron Job Configuration

Option 1: Add to User Crontab

bash
# Edit crontab
crontab -e

# Add this line (runs daily at midnight)
0 0 * * * find ~/.openclaw/workspace/curriculum-designer-checkpoints/ -type d -mtime +7 -exec rm -rf {} \;

Option 2: Using OpenClaw Cron

bash
# Create cron job via OpenClaw
openclaw cron create \
  --name "checkpoint-cleanup" \
  --schedule "0 0 * * *" \
  --command "find ~/.openclaw/workspace/curriculum-designer-checkpoints/ -type d -mtime +7 -exec rm -rf {} \;" \
  --description "Delete curriculum-designer checkpoints older than 7 days"

Cron Schedule Options

| Schedule | Crontab Format

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This line defines a direct path to a local .env file and is part of logic that reads a secret API key from disk. Skills that reach into local secret stores are dangerous because they expand access beyond the declared task and can be repurposed to harvest credentials or leak them through logs, outputs, or subsequent network requests.

Content

Scanner excerpt · curriculum-designer.sh (reported line 95)May include surrounding context.

sh
echo ""

    # Load YouTube API key
    local env_file="$HOME/.openclaw/workspace/skills/curriculum-designer/.env"
    local youtube_api_key=""

    if [ -f "$env_file" ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · curriculum-designer.sh (reported line 103)May include surrounding context.

sh
fi

    if [ -z "$youtube_api_key" ]; then
        echo "⚠️  YouTube API key not found in .env file"
        echo "⚠️  Skipping YouTube search, returning empty results"
        echo '{"resources": []}' > "${session_dir}/research-results.json"
        return 0

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · curriculum-designer.sh (reported line 117)May include surrounding context.

sh
local query="$1"
        local api_key="$2"

        local result=$(curl -s "https://www.googleapis.com/youtube/v3/search?part=snippet&q=${query}+tutorial+hindi+beginners&type=video&maxResults=5&videoDuration=medium&key=${api_key}" 2>/dev/null)

        echo "$result" | python3 <<EOF
import sys, json

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly instructs the agent to read local files, write checkpoints, and execute shell commands, but it declares no explicit tool scope or permission boundary. That mismatch increases the chance that an orchestrator grants broader capabilities than necessary, making misuse of filesystem and shell access harder to constrain or audit.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
User message contains:
- **"Design curriculum"** → Start curriculum creation
- **"Create curriculum for [POD name]"** → Start with POD context
- **"Build learning plan"** → Start curriculum creation
- **"Curriculum for [subject/topic]"** → Start with topic context

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's default search queries and parameters consistently prefer Hindi, including relevanceLanguage=hi and Hindi-specific queries, which imposes a language/locale preference. The file does not clearly offer the user a language option or document that the skill is restricted to a Hindi-specific regional use case as a policy exception.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 437)May include surrounding context.

md
"subject": "Skill Development",
  "module": "Module 5: Advanced Spreadsheets",
  "daily_learning_objectives": "Learn Excel formulas and data analysis",
  "daily_assessment": "Create a budget spreadsheet using formulas",
  "youtube_link": "",
  "youtube_title": "",
  "tools_used": "Google Sheets",

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 519)May include surrounding context.

Step 3: Populate with Lessons

bash
# Read curriculum structure and convert to gog format
# For each lesson, create a row array
# Then append all rows at once

# Format each lesson as: [Day, Subject, Module, Objectives, Assessment, URL, Title, Tools, Fallback]

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates sharing generated Google Sheets with 'anyone' regardless of user need, which exceeds the minimum access required to deliver a curriculum. This creates unnecessary public exposure of curriculum content and potentially user-supplied contextual details.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill combines user-provided requirements, teacher capability information, and generated curriculum data, then instructs the agent to publish the resulting sheet via a public link. Even if the data is not highly sensitive, this broad sharing can expose organizational planning details and any included personal or operational context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guideline states 'Hindi or bilingual - accessible for all students,' which enforces a specific language preference in natural-language instructions. Because the skill does not provide an explicit language choice or opt-in, this constitutes a locale policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The curriculum skill includes instructions to create a persistent cron job that survives beyond the user task, which is unrelated to curriculum generation. Persistent scheduled commands enlarge the blast radius of the skill by enabling repeated filesystem actions long after the original session ends.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The automatic deletion workflow instructs irreversible removal of checkpoint directories after a retention window but gives no prominent warning about data loss. Users may rely on checkpoints for recovery or auditability, so silent deletion can destroy needed records or work product.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Editing user crontab introduces persistence outside the task lifecycle, allowing the skill to install recurring behavior on the host. Even though the stated command is cleanup-related, persistence mechanisms are high-risk because they can be repurposed or left behind unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 639)May include surrounding context.

Option 1: Add to User Crontab

bash
# Edit crontab
crontab -e

# Add this line (runs daily at midnight)
0 0 * * * find ~/.openclaw/workspace/curriculum-designer-checkpoints/ -type d -mtime +7 -exec rm -rf {} \;

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

Using OpenClaw cron to create a named scheduled job is an explicit persistence mechanism embedded in a skill that does not need it for its primary function. This can leave behind recurring privileged actions on the environment and expands risk beyond the immediate user request.

Content

Scanner excerpt · SKILL.md (reported line 647)May include surrounding context.

Option 2: Using OpenClaw Cron

bash
# Create cron job via OpenClaw
openclaw cron create \
  --name "checkpoint-cleanup" \
  --schedule "0 0 * * *" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 670)May include surrounding context.

bash
# List cron jobs (crontab)
crontab -l

# List cron jobs (OpenClaw)
openclaw cron list

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says the skill designs customized curricula for PODs, which implies resource selection should be driven by the user's stated needs. Here, the script extracts subject areas from requirements but never uses them, performing searches only for a fixed list of generic topics such as Gmail, Google Docs, and ChatGPT tutorials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The YouTube search query appends the term "hindi" to every search, which forces a specific language choice for returned resources. This is a natural-language locale policy issue because the script does not offer the user a language preference or explain why Hindi is required.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a curriculum designer that produces curricula with real resource links and staged fallback behavior. While earlier stages gather and validate YouTube links, the final output stage does not create an actual Google Sheet and instead writes a fixed placeholder URL, which does not match the claimed deliverable.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill reads a local .env file to obtain a YouTube API key, introducing credential access behavior not described in the skill's stated purpose. Even though it uses the key only for YouTube API requests here, undeclared secret-reading increases the trust boundary and can normalize broader credential harvesting patterns in agent skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.