Back to skill

Security audit

Workflow Note(流程笔记)

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese workflow-note writing template with some publication and example-memory cautions, but no hidden execution or malicious behavior was found.

Before using this skill to publish notes, review any copied cron prompts, AGENTS.md, HEARTBEAT.md, or similar configuration for secrets, personal data, internal addresses, and private instructions. Treat build/commit/push as actions that should require your explicit intent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/example.md (reported line 31)May include surrounding context.

md
## 整体架构

​\`\`\`
交互发生
  ├─→ memory/YYYY-MM-DD.md              情形记忆(发生了什么)
  └─→ .learnings/LEARNINGS.md           反思记忆(学到了什么)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/example.md (reported line 43)May include surrounding context.

md
## 整体架构

​\`\`\`
交互发生
  ├─→ memory/YYYY-MM-DD.md              情形记忆(发生了什么)
  └─→ .learnings/LEARNINGS.md           反思记忆(学到了什么)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/example.md (reported line 49)May include surrounding context.

md
## 整体架构

​\`\`\`
交互发生
  ├─→ memory/YYYY-MM-DD.md              情形记忆(发生了什么)
  └─→ .learnings/LEARNINGS.md           反思记忆(学到了什么)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/example.md (reported line 51)May include surrounding context.

md
## 整体架构

​\`\`\`
交互发生
  ├─→ memory/YYYY-MM-DD.md              情形记忆(发生了什么)
  └─→ .learnings/LEARNINGS.md           反思记忆(学到了什么)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/example.md (reported line 55)May include surrounding context.

md
## 整体架构

​\`\`\`
交互发生
  ├─→ memory/YYYY-MM-DD.md              情形记忆(发生了什么)
  └─→ .learnings/LEARNINGS.md           反思记忆(学到了什么)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/example.md (reported line 60)May include surrounding context.

md
## 整体架构

​\`\`\`
交互发生
  ├─→ memory/YYYY-MM-DD.md              情形记忆(发生了什么)
  └─→ .learnings/LEARNINGS.md           反思记忆(学到了什么)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/example.md (reported line 64)May include surrounding context.

md
## 整体架构

​\`\`\`
交互发生
  ├─→ memory/YYYY-MM-DD.md              情形记忆(发生了什么)
  └─→ .learnings/LEARNINGS.md           反思记忆(学到了什么)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/example.md (reported line 74)May include surrounding context.

md
## 整体架构

​\`\`\`
交互发生
  ├─→ memory/YYYY-MM-DD.md              情形记忆(发生了什么)
  └─→ .learnings/LEARNINGS.md           反思记忆(学到了什么)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
## 写作流程

1. **先读** `~/.openclaw/skills/note-taking/SKILL.md`(全局规范:命名、语言、侧边栏等)
2. **先查重**:搜索已有 workflows/ 笔记,同主题不重复创建
3. **先想主题**:提炼一个明确的技术主题,不是按时间堆砌做了什么
4. **按模板写**:使用下方模板

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction "所有正文内容使用中文" forces a specific language for all body content. This is a natural-language policy concern because the file does not offer the user a language choice or explain a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The rule "正文必须中文" bars English for the main content and imposes a fixed language policy. Because no opt-in, alternative, or justified compliance context is provided, this matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example explicitly promotes persistent file-based memory and an automatic nightly review process that can copy, retain, and modify user-derived information over time. Without privacy, retention, consent, and scope warnings, users may unknowingly store sensitive data or allow automated changes to long-lived files, increasing confidentiality and integrity risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup instructions direct users to create persistent files under the home directory for long-term memory and error tracking, but do not warn that these files can accumulate secrets, personal data, or other sensitive operational context. Because they are persistent and centrally located, they become an attractive source of data leakage or unintended reuse.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The instructions create a persistent session-like memory store under the user's home directory, including files for learnings, errors, and feature requests. In an agent context, this enables durable accumulation of conversation-derived state across sessions, which can expose sensitive data, propagate stale or harmful context, and expand the blast radius of compromise.

Content

Scanner excerpt · references/example.md (reported line 56)May include surrounding context.

md
安装后必须手动初始化:

​\`\`\`bash
mkdir ~/.openclaw/workspace/.learnings
touch ~/.openclaw/workspace/.learnings/LEARNINGS.md
touch ~/.openclaw/workspace/.learnings/ERRORS.md
touch ~/.openclaw/workspace/.learnings/FEATURE_REQUESTS.md

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language content appears to assume Chinese as the required language for the skill example, and there is no indication that users may choose another language or that the locale is intentionally restricted. This can be a language-policy issue under SQP-3 when a skill forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.