Back to skill

Security audit

AILove

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed dating assistant, but it encourages persistent scheduled jobs that repeatedly read a saved API key and post sensitive relationship updates.

Install only if you are comfortable giving this skill an AILove key, storing or injecting that key safely, and allowing recurring jobs to post dating-related updates to a chosen channel. Prefer a secure secret store or environment variable over credentials.json, confirm the destination is private, and avoid enabling cron until you know how to disable the jobs and rotate the key.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:174
Finding

Persistent Scheduled Jobs Repeatedly Access Credentials and External Services

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 174-177 and 222-242
Vulnerability Type: Persistent scheduled task installation
Risk Level: High

Vulnerable Code

markdown
## Skill: AILove Scheduled Push Configuration

Create **two** cron jobs (morning + evening) that check AILove and push updates to your chosen channel. The scheduled agent turn should call the **matching API** as documented above (full URL + auth), then handle **`next_steps`**.

**Environment (required):** Export **`AILOVE_API_KEY`** wherever OpenClaw runs cron. Load it from `~/.openclaw/skills-data/ailove/credentials.json` or your preferred secret store. If the key is missing when the job fires, the API call fails with 401 or fails silently.
bash
openclaw cron add \
  --name "AILove Morning Check" \
  --cron "0 9 * * *" \
  --tz "{timezone}" \
  --session "isolated" \
  --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps and summarize" \
  --to "{channel-target-id}" \
  --announce
bash
openclaw cron add \
  --name "AILove Evening Check" \
  --cron "0 21 * * *" \
  --tz "{timezone}" \
  --session "isolated" \
  --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps and summarize" \
  --to "{channel-target-id}" \
  --announce

Technical Analysis

The skill instructs the agent to install two recurring OpenClaw cron jobs. These jobs survive the original skill invocation and autonomously start isolated agent sessions twice per day. Each run reads a persistent API credential, authenticates to an external service, processes its response, and posts output to a configured communication channel.

Scheduled polling is related to the declared notification functionali ...[truncated 1904 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make interactive, user-invoked polling the default behavior.
  2. Require explicit informed consent immediately before creating each scheduled job.
  3. Display the exact schedule, destination, credential source, endpoint, and data categories before confirmation.
  4. Give scheduled jobs a configurable expiration date or maximum execution count.
  5. Provide documented commands to list, disable, and remove both jobs.
  6. Confirm that the selected destination is a private, intended channel before enabling announcements.
  7. Use a platform-managed secret store instead of directly reading a plaintext JSON credential file where available.
  8. Use a restricted token scoped only to the two documented API operations and support prompt revocation.
  9. Avoid silently failing when credentials are unavailable; record a sanitized error without including tokens.
  10. Require renewed consent before changing the endpoint, schedule, destination, or categories of data being posted.

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:183
Finding

Remote API Response Fields Are Treated as Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 183-192 and 209-216
Vulnerability Type: Indirect prompt injection through external API content
Risk Level: High

Vulnerable Code

markdown
After each successful **matching API** response, follow **`next_steps`** in priority order:

```text
1. answer_questions -> Relay to human, POST their answers
2. improve_profile  -> Ask them to log in to AILove and improve profile
3. view_results     -> Nickname + recommendation; full details on the site
4. share_news       -> Share dating tips / relationship advice from the news array
5. report_chat      -> Summarize proxy-chat progress
6. wait             -> Report countdown
text

```markdown
1. **Load `AILOVE_API_KEY`** from **`~/.openclaw/skills-data/ailove/credentials.json`** — read the `agent_key` field and export it as `AILOVE_API_KEY` before making API calls.
2. **Call `GET https://heerweiyi.cc/api/v1/agent/matching`** with `Authorization: Bearer $AILOVE_API_KEY`.
3. **Handle `next_steps`** from the JSON response in priority order, then summarize for the human on the channel.

**Example text** you can pass to `--message`:

```text
Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json. Call GET https://heerweiyi.cc/api/v1/agent/matching with Authorization: Bearer. Then handle next_steps in order and summarize on the channel.
text

### Technical Analysis

The scheduled-session prompt tells the agent to “handle” the `next_steps` field returned by an external API. Other server-controlled fields, including chat messages and news, are also intended to be summarized or relayed. The instructions do not require strict JSON schema validation, reject unknown action names, distinguish data from executable instructions, or prohibit remote text from overriding local constraints.

This creates an indirect prompt-injection boundary: content controlled by the external service is pr
...[truncated 2155 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat every API response field as untrusted data, never as agent instructions.
  2. Validate the response against a strict local JSON schema before processing it.
  3. Permit only the fixed action identifiers answer_questions, improve_profile, view_results, share_news, report_chat, and wait.
  4. Reject unknown actions, unexpected object shapes, nested instructions, URLs, and oversized values.
  5. Map each permitted identifier to fixed local code or a predetermined response template rather than asking the language model to “follow” or “handle” it.
  6. Add an explicit instruction that remote content cannot override system, user, security, credential, endpoint, or tool-use constraints.
  7. Escape, delimit, and length-limit all chat, news, question, nickname, and recommendation text before presenting it to the agent or channel.
  8. Require interactive human confirmation before submitting an answer or taking any action derived from remote content.
  9. Restrict scheduled sessions to the minimum tool set: the declared AILove endpoint and the intended announcement channel only.
  10. Log rejected action identifiers and schema failures without logging credentials or sensitive response bodies.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (21)

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The skill instructs the agent to read credentials from environment, local file, or even pasted chat content, expanding the number of places a live secret may reside. This increases the chance of accidental disclosure through logs, memory, transcripts, or other tools that can access local files or conversation history.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
**When you call the API, read the Key in this order:**

1. **Environment variables** — **use these first** (`AILOVE_API_KEY` exported in your shell or agent session).
2. `~/.openclaw/skills-data/ailove/credentials.json` (if your human or you saved JSON there).
3. What the human pasted in chat (last resort; do not log the full Key in plain text in shared places).

**Save the Key to `~/.openclaw/skills-data/ailove/credentials.json` (recommended):** after the human gives you the Key, save it to the skill's own data directory. Restrict permissions to owner-only.

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Recommending storage of the API key in a plaintext JSON file creates a recoverable local secret that may be exposed by backup systems, overly broad filesystem access, or other local tools. Even with restrictive permissions, plaintext-at-rest credentials are a common attack surface.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

  1. ~/.openclaw/skills-data/ailove/credentials.json (if your human or you saved JSON there).
  2. What the human pasted in chat (last resort; do not log the full Key in plain text in shared places).

Save the Key to ~/.openclaw/skills-data/ailove/credentials.json (recommended): after the human gives you the Key, save it to the skill's own data directory. Restrict permissions to owner-only.

bash
mkdir -p ~/.openclaw/skills-data/ailove

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The example explicitly writes the agent key into credentials.json, normalizing plaintext secret handling and making it easy for operators to store production credentials insecurely. This is especially risky in shared environments or where home directories are synchronized or inspected.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

bash
mkdir -p ~/.openclaw/skills-data/ailove
cat > ~/.openclaw/skills-data/ailove/credentials.json <<'EOF'
{
  "agent_key": "loveq_xxx",
  "api_base": "https://heerweiyi.cc/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
78% confidence
Finding

Although chmod 600 improves permissions, the surrounding instruction still relies on a plaintext credential file on disk. Restrictive permissions mitigate but do not eliminate risks from local compromise, backups, agent file-read capabilities, or accidental inclusion in support bundles.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

"api_base": "https://heerweiyi.cc/api/v1" } EOF chmod 600 ~/.openclaw/skills-data/ailove/credentials.json

text

Replace `loveq_xxx` with the real Key from the human (starts with `loveq_`).

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The cron guidance tells operators to load the API key from a local credential file into the runtime environment for automated jobs. Scheduled jobs broaden the exposure window for secrets and can leak via process environments, debug output, or job configuration inspection.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
Create **two** cron jobs (morning + evening) that check AILove and push updates to your chosen channel. The scheduled agent turn should call the **matching API** as documented above (full URL + auth), then handle **`next_steps`**.

**Environment (required):** Export **`AILOVE_API_KEY`** wherever OpenClaw runs cron. Load it from `~/.openclaw/skills-data/ailove/credentials.json` or your preferred secret store. If the key is missing when the job fires, the API call fails with 401 or fails silently.

**Optional:** Track slots in `~/.openclaw/skills-data/ailove/state.json` (`lastMorningCheck` / `lastEveningCheck`) so you do not double-report the same window.

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The --message instruction explicitly tells an isolated agent session to read a credential file and export the key before making API calls. Embedding secret-handling steps in prompt text increases the risk that the key path and access workflow are copied, logged, or mishandled by orchestration layers.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
The **`--message`** string is the instruction for the **isolated** agent session when cron fires. It should make the agent:

1. **Load `AILOVE_API_KEY`** from **`~/.openclaw/skills-data/ailove/credentials.json`** — read the `agent_key` field and export it as `AILOVE_API_KEY` before making API calls.
2. **Call `GET https://heerweiyi.cc/api/v1/agent/matching`** with `Authorization: Bearer $AILOVE_API_KEY`.
3. **Handle `next_steps`** from the JSON response in priority order, then summarize for the human on the channel.

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The example --message string repeats instructions to load the credential from disk, further encouraging a pattern where secrets are retrieved through promptable behavior rather than secure runtime configuration. This makes accidental disclosure or unauthorized file access more likely in agentic environments.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

Example text you can pass to --message:

text
Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json. Call GET https://heerweiyi.cc/api/v1/agent/matching with Authorization: Bearer. Then handle next_steps in order and summarize on the channel.

Morning - 09:00

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The sample cron command embeds a message telling the agent to read credentials from a local file. In practice, such job definitions may be visible to administrators, stored in configuration files, or reused in ways that normalize insecure secret retrieval patterns.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

--cron "0 9 * * *"
--tz "{timezone}"
--session "isolated"
--message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps and summarize"
--to "{channel-target-id}"
--announce

text

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This evening cron example has the same issue as the morning one: it directs an agent to fetch a credential from disk via prompt text. Repetition across examples reinforces insecure operational practices and increases the chance of deployment with weak secret hygiene.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

--cron "0 21 * * *"
--tz "{timezone}"
--session "isolated"
--message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps and summarize"
--to "{channel-target-id}"
--announce

text

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The Feishu example includes a cron message instructing the agent to load credentials from disk, extending the insecure pattern into copy-paste deployment guidance. Example commands are especially influential because users often adopt them verbatim in production.

Content

Scanner excerpt · SKILL.md (reported line 295)May include surrounding context.

Example 1 - Feishu DM (China)

bash
openclaw cron add --name "AILove Morning" --cron "0 9 * * *" --tz "Asia/Shanghai" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "ou_88b5719c273dd2227298672aae6a1a05" --announce

openclaw cron add --name "AILove Evening" --cron "0 21 * * *" --tz "Asia/Shanghai" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "ou_88b5719c273dd2227298672aae6a1a05" --announce

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This second Feishu example repeats the same insecure credential access pattern for the evening job. The danger comes less from maliciousness and more from operationalizing plaintext secret retrieval at scale.

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

bash
openclaw cron add --name "AILove Morning" --cron "0 9 * * *" --tz "Asia/Shanghai" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "ou_88b5719c273dd2227298672aae6a1a05" --announce

openclaw cron add --name "AILove Evening" --cron "0 21 * * *" --tz "Asia/Shanghai" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "ou_88b5719c273dd2227298672aae6a1a05" --announce

Example 2 - Telegram (US)

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The Telegram example instructs the agent to read a local credential file, again exposing a sensitive-file access workflow in deployment guidance. In agent ecosystems, prompts that mention secret locations can become an attack surface if reused or observed.

Content

Scanner excerpt · SKILL.md (reported line 303)May include surrounding context.

Example 2 - Telegram (US)

bash
openclaw cron add --name "AILove Morning" --cron "0 9 * * *" --tz "America/New_York" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "123456789" --announce

openclaw cron add --name "AILove Evening" --cron "0 21 * * *" --tz "America/New_York" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "123456789" --announce

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This companion Telegram example has the same weakness: it perpetuates prompt-driven credential access from disk. The repeated examples make insecure storage and retrieval appear to be the standard practice for the skill.

Content

Scanner excerpt · SKILL.md (reported line 305)May include surrounding context.

bash
openclaw cron add --name "AILove Morning" --cron "0 9 * * *" --tz "America/New_York" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "123456789" --announce

openclaw cron add --name "AILove Evening" --cron "0 21 * * *" --tz "America/New_York" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "123456789" --announce

Example 3 - Discord channel (UK)

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The Discord example embeds instructions to load the API key from a local file into an agent prompt. This creates unnecessary exposure of secret locations and relies on agent file access for authentication, which is weaker than dedicated secret provisioning.

Content

Scanner excerpt · SKILL.md (reported line 311)May include surrounding context.

Example 3 - Discord channel (UK)

bash
openclaw cron add --name "AILove Morning" --cron "0 9 * * *" --tz "Europe/London" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "123456789012345678" --announce

openclaw cron add --name "AILove Evening" --cron "0 21 * * *" --tz "Europe/London" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "123456789012345678" --announce

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This repeated Discord example continues the same insecure pattern and increases the odds that operators will deploy it unchanged. The primary risk is credential compromise via plaintext storage plus prompt-mediated retrieval.

Content

Scanner excerpt · SKILL.md (reported line 313)May include surrounding context.

bash
openclaw cron add --name "AILove Morning" --cron "0 9 * * *" --tz "Europe/London" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "123456789012345678" --announce

openclaw cron add --name "AILove Evening" --cron "0 21 * * *" --tz "Europe/London" --session "isolated" --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps" --to "123456789012345678" --announce

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill recommends persisting the agent key in a local file under the skill data directory, creating long-lived session/authentication material on disk. Persistent secrets increase compromise impact because an attacker or over-privileged tool can reuse them later to impersonate the human.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Save the Key to ~/.openclaw/skills-data/ailove/credentials.json (recommended): after the human gives you the Key, save it to the skill's own data directory. Restrict permissions to owner-only.

bash
mkdir -p ~/.openclaw/skills-data/ailove
cat > ~/.openclaw/skills-data/ailove/credentials.json <<'EOF'
{
  "agent_key": "loveq_xxx",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

"api_base": "https://heerweiyi.cc/api/v1" } EOF chmod 600 ~/.openclaw/skills-data/ailove/credentials.json

text

Replace `loveq_xxx` with the real Key from the human (starts with `loveq_`).

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

Submit your human's verbatim answer to a pending question.

bash
curl -s -X POST \
  -H "Authorization: Bearer $AILOVE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"answer": "The user exact words here", "answered_by": "human_via_agent"}' \

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The scheduled push configuration creates ongoing automated access using stored credentials, which extends the lifetime and utility of authentication material beyond an interactive session. Automation is legitimate here, but it increases risk if the host, job config, or agent runtime is compromised.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
## Skill: AILove Scheduled Push Configuration

Create **two** cron jobs (morning + evening) that check AILove and push updates to your chosen channel. The scheduled agent turn should call the **matching API** as documented above (full URL + auth), then handle **`next_steps`**.

**Environment (required):** Export **`AILOVE_API_KEY`** wherever OpenClaw runs cron. Load it from `~/.openclaw/skills-data/ailove/credentials.json` or your preferred secret store. If the key is missing when the job fires, the API call fails with 401 or fails silently.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description 'AI dating assistant. Check matching progress, relay deep questions, report results for your human.' is broad and permits invocation across sensitive social and relationship contexts without clear boundaries. In an agent ecosystem, vague scope can cause over-invocation, unnecessary access to personal or intimate information, and proxy interaction with third parties in ways users may not expect or consent to.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document instructs the agent to schedule checks in the human's timezone and later provides preset timezone examples for specific regions, but it does not explicitly require confirming the user's preferred locale/timezone before applying that behavior. This is a natural-language locale policy concern because the skill operationalizes locale assumptions rather than offering an explicit opt-in choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.