Credential Access
- Category
- Privilege Escalation
- Confidence
- 60% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
text *.log # 环境变量 .env .env.local # 测试
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent Obsidian setup helper with disclosed AI and memory workflow guidance, but users should be careful before enabling chat sync or memory features.
Review the AI workflow before enabling it: chat imports may copy private Telegram/WeChat or Feishu content into Obsidian and memory files, and AI tools may process that content depending on your setup. Limit synced chats, avoid regulated or confidential data unless you have permission, and confirm where memory files are stored and how to delete them.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
*.log
# 环境变量
.env
.env.local
# 测试
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 环境变量
.env
.env.local
# 测试
coverage/
Advertising automatic ingestion of Telegram/WeChat messages into Obsidian without a privacy warning is risky because it may collect private conversations, third-party data, and sensitive content into a local knowledge base or memory system. This becomes more dangerous in this skill because it also promotes AI integration and persistent memory storage, increasing the chance of retention, secondary processing, or unintended disclosure.
The document instructs users to run clawhub publish to upload the skill to a remote service, but it does not clearly warn that publishing may transmit the full package contents, metadata, and possibly embedded secrets or internal files. In a skill repository context, this omission can lead to accidental public disclosure if users follow the steps without reviewing what will be uploaded.
The README explicitly advertises automatic Telegram/微信 message organization and automatic writes into a memory/ directory, but it does not clearly warn users what data may be collected, persisted, or retained. In a note-taking and AI-integration skill, this creates a real privacy and data-handling risk because users may enable automation without understanding that personal conversations or sensitive content could be stored locally or processed by external services.
The skill's descriptive content, commands examples, and operational guidance are presented entirely in Chinese, effectively forcing a specific language experience. There is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience for compliance or regional reasons.
The skill explicitly states it will generate multiple files in the user's workspace, including personal preference and memory-related files, but does not warn the user that local data will be created or modified. Silent workspace writes can overwrite existing notes, create sensitive profile data, or persist information the user did not intend to store.
The natural-language description is entirely in Chinese and presents the skill as such, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy because it imposes a specific language without user opt-in or justification.
This markdown template is written entirely in Chinese and includes fixed Chinese field values such as "阅读中" and section headings, which imposes a specific language/locale on users by default. The file does not offer a language choice or explain that it is intended only for a Chinese-language or region-specific context.
The integration instructions tell users to configure Feishu/Telegram and enable automatic sync, but omit any discussion of what data leaves the source platform, where it is stored, who can access it, or whether AI services process it. In a productivity skill centered on note capture and AI integration, that omission increases the chance of accidental leakage of confidential conversations.
The workflow guidance explicitly recommends automatic ingestion of Telegram/WeChat messages into Obsidian and AI-based organization, but provides no warning about sensitive personal, business, or regulated data being copied into local notes or onward to third-party AI tools. This can lead users to enable broad message capture without understanding privacy, consent, retention, or cross-system data exposure risks.
The clawhub unpublish obsidian-master instruction triggers a destructive remote action, but the guide provides no warning about permanence, scope, or the need to verify the target skill first. Users could remove the wrong published skill or unexpectedly disrupt availability if they execute the command casually.
Nearly all user-facing instructional content and example prompts are presented only in Chinese, which can amount to a language-policy issue when no user opt-in or alternative language option is provided. The README does not explain that the skill is intentionally region- or language-specific.
The manifest declares a broad peer dependency on openclaw (>=2026.3.2) even though the package reportedly has multiple known advisories. Because the version is not pinned or constrained away from vulnerable releases, consumers may install an affected version through the surrounding environment, creating supply-chain exposure that depends on how this skill is deployed.
This markdown template uses Chinese labels and a Chinese-formatted date by default, which imposes a specific language/locale on all users of the skill. The file does not offer any language choice or explain that it is intentionally region-specific.
The template content is written in Chinese throughout, including status values and section headings such as "进行中", "项目目标", and "会议记录". Under the policy rule for language or locale, this is a natural-language constraint that does not offer the user any language choice or opt-in.
Across comments, titles, descriptions, and returned help content, the skill consistently uses Chinese only. There is no opt-in, language selection, or documented reason that this skill must be Chinese-only, which fits the language/locale policy violation category.
No suspicious patterns detected.