Back to skill

Security audit

Productivity Helper #2

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple productivity helper, but it asks for broad shell and file authority and points users to mutable external setup instructions that do not fit the stated purpose.

Review before installing. The local artifact does not show malicious code or automatic execution, but it grants broader agent tools than its productivity features explain and relies on unpinned external setup material. Install only if you are comfortable with the skill being able to read/write accessible files and potentially run shell commands, and prefer a pinned reviewed version with local setup instructions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:4
Finding

Excessive Bash and Filesystem Tool Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:4
Vulnerability Type: Excessive tool permissions that violate least privilege
Risk Level: Medium

Vulnerable Code Snippet:

yaml
allowed-tools: Bash, Read, Write

Technical Analysis

The Skill requests shell execution and filesystem read/write capabilities, although its documented functions are limited to conversational task organization, time tracking, daily planning, and workflow optimization. No functionality in the audited files demonstrates a legitimate need to execute system commands or access arbitrary local files.

Granting these tools unnecessarily expands the Skill's authority. If its behavior is subsequently influenced by malicious user content, untrusted task text, or mutable external instructions, the Agent could use these permissions for operations unrelated to productivity planning.

Attack Path

  1. A user activates the Skill for a routine planning task.
  2. The Skill is granted Bash, Read, and Write capabilities.
  3. The session receives attacker-controlled content, such as a malicious task description or instructions obtained from an external resource.
  4. The influenced Agent invokes the granted tools.
  5. Commands may be executed, local files may be read, or accessible files may be modified within the Agent runtime's permission boundary.

Impact Assessment

Exploitation could allow command execution and unauthorized access to files available to the Agent process. The precise scope depends on runtime sandboxing and operating-system privileges, but could include disclosure or modification of user data and execution of additional local commands.

Remediation
View remediation

Remediation Suggestions

Remove Bash, Read, and Write from allowed-tools because the documented conversational features do not require them. If a future feature genuinely requires a tool, grant only that tool and constrain it to explicitly approved commands, directories, and file types. Enforce runtime sandboxing, deny access to secrets and sensitive directories, and require user confirmation before consequential operations.

other

Warning
Location
SKILL.md:9
Finding

Security-Critical Setup Guidance Delegated to Mutable External Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9
Vulnerability Type: Mutable external instruction dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
> 📖 **Complete setup guide**: https://skillboss.co/skill.md

Technical Analysis

The package delegates its complete setup guidance to a remotely hosted Markdown document that is not included in the audited artifact and is not pinned by a content hash or immutable version. The owner of the remote resource—or an attacker who compromises it—can change the instructions after this package has been reviewed.

The audited local files do not explicitly retrieve or execute the remote document, so this is not classified as remote payload execution. The risk arises when a user or Agent follows the link and treats its mutable contents as trusted setup instructions, especially because the Skill has broad Bash, Read, and Write permissions.

Attack Path

  1. A user or Agent opens SKILL.md and follows the advertised “Complete setup guide.”
  2. The external document is changed by its operator or compromised by an attacker.
  3. The modified guide presents unsafe commands or malicious instructions as required setup steps.
  4. The user executes those commands, or a tool-enabled Agent follows the remote instructions.
  5. Actions occur under the user's or Agent's local privileges.

Impact Assessment

Depending on the remote instructions and the privileges available to the user or Agent, the impact could include installation of unreviewed software, command execution, disclosure of local information, or modification of files. The remote content itself was not available in the audited project, so no specific malicious payload can be confirmed.

Remediation
View remediation

Remediation Suggestions

Include the complete setup procedure in the reviewed repository. If external documentation is unavoidable, reference a versioned, immutable resource and publish a cryptographic hash or signature for verification. Clearly state that remote content must not be treated as authoritative Agent instructions, and require explicit user review before executing any setup command.

T08 · Insecure Dependencies

Warning
Location
README.md:5
Finding

Installation Instructions Retrieve Unpinned Upstream Content

Content
View full analysis

Vulnerability Details

File Location: README.md:5-14
Vulnerability Type: Unpinned third-party installation sources
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## Installation

### Via ClawHub
```bash
clawhub install toby-productivity-helper

Manual Installation

bash
git clone https://github.com/TobeyRebecca/productivity-helper.git
cp -r productivity-helper ~/.openclaw/skills/productivity-helper
text

### Technical Analysis
Both installation methods retrieve mutable upstream content without specifying an immutable package version, Git commit, release tag with verification, checksum, or signature. Consequently, the material installed by these commands may differ from the artifact covered by this audit.

The `git clone` command obtains the repository's current default branch, while the ClawHub command does not identify a reviewed version. If either distribution source or its maintainer account is compromised, later users may install altered Skill instructions or additional files.

### Attack Path
1. An attacker compromises the upstream repository, registry entry, publishing account, or distribution process.
2. The attacker replaces or augments the upstream Skill content.
3. A user runs one of the documented installation commands.
4. The command retrieves the latest mutable upstream state rather than the audited artifact.
5. The modified content is copied into the OpenClaw Skill directory and becomes available to the Agent.

### Impact Assessment
A successful supply-chain compromise could install arbitrary Skill instructions or other attacker-controlled project files. Subsequent impact depends on the installed content and the Agent's permissions, potentially including instruction hijacking, local command execution, or unauthorized file access. No such payload was present in the artifact reviewed here.
Remediation
View remediation

Remediation Suggestions

Pin installation to a reviewed immutable release or Git commit. For manual installation, use a specific commit identifier and verify the repository or release signature. For registry installation, specify an exact version and provide a trusted checksum or signature. Document verification steps and ensure the verified content matches the artifact that underwent security review.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation guidance is very broad and maps to common, everyday requests such as organizing tasks or planning a day. In systems that auto-select skills based on user phrasing, this can cause the skill to trigger too often, unnecessarily granting it access to Bash/Read/Write in situations where those tools are not needed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example phrase, 'Help me plan my day with 5 tasks,' is a highly generic request that many assistants should handle without invoking a privileged skill. If routing relies on semantic similarity, this example increases the chance of over-triggering and tool exposure, especially because the skill is allowed to use Bash, Read, and Write.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.