Back to skill

Security audit

Productivity Helper #3

Security checks for vulnerabilities and agentic risk

Overview

This productivity skill is simple and has no embedded malicious code, but it asks for broad shell and file access without a clear need.

Review this skill before installing. It does not contain a visible malicious payload, but a productivity planner should not normally need arbitrary shell and broad file read/write access. Prefer installing only if permissions can be reduced or constrained, and avoid following the unpinned manual GitHub install path unless you verify the exact reviewed version.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:4
Finding

Excessive Tool Permissions for an Advisory-Only Productivity Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 4
Vulnerability Type: Violation of least privilege through unnecessary shell and filesystem capabilities
Risk Level: Medium

Complete Code Snippet:

yaml
allowed-tools: Bash, Read, Write

Technical Analysis

The skill describes task organization, daily planning, time tracking, and workflow advice, none of which inherently require arbitrary shell execution or unrestricted filesystem access. Nevertheless, its manifest authorizes Bash, Read, and Write.

In particular, Bash can expose a broad command-execution surface, while Read and Write may permit access to files unrelated to productivity planning. The exact accessible scope depends on the OpenClaw runtime's sandbox and authorization controls, but the manifest does not define narrower path, command, or operation restrictions.

No malicious command is present in the audited package. The security defect is the unnecessary capability grant, which increases the consequences of future package compromise, malicious instruction updates, prompt injection, or unsafe content obtained from the externally referenced setup guide.

Attack Path

  1. A user installs and activates the skill, causing the runtime to grant the tools declared in allowed-tools.
  2. An attacker compromises a future skill version, influences instructions consumed while the skill is active, or supplies prompt-injection content.
  3. The injected instructions invoke Read to collect accessible local information, Write to alter accessible files, or Bash to run commands.
  4. The commands execute with the operating-system identity and sandbox permissions of the OpenClaw process.

The current audited instructions do not independently execute this path; exploitation requires an additional malicious or compromised instruction source.

Impact Assessment

A successful exploit could disclose files readable by the agent proc ...[truncated 431 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove Bash, Read, and Write if the skill only provides conversational planning and prioritization.
  • If state persistence is required, grant only a narrowly scoped storage interface rather than general filesystem access.
  • Restrict reads and writes to a dedicated skill data directory with canonical-path validation.
  • Replace unrestricted shell access with purpose-built operations that accept structured arguments.
  • Where shell execution is unavoidable, use a strict command allowlist, prohibit shell metacharacters, pass arguments without shell interpolation, and run inside a sandbox with minimal filesystem and network access.
  • Require explicit user approval for sensitive file operations or command execution.
  • Add automated checks that reject future manifest changes introducing capabilities not justified by documented features.

T08 · Insecure Dependencies

Note
Location
README.md:12
Finding

Installation from an Unpinned Mutable Git Repository

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 12-16
Vulnerability Type: Unpinned third-party source and mutable installation input
Risk Level: Low

Complete Code Snippet:

markdown
### Manual Installation
```bash
git clone https://github.com/TobeyRebecca/productivity-helper.git
cp -r productivity-helper ~/.openclaw/skills/productivity-helper
text

### Technical Analysis

The manual installation procedure clones the repository's current default branch without selecting a release tag or verified commit. A default branch is mutable, so the content installed by a user can differ from the content that was previously audited.

The instructions also copy the entire cloned directory directly into the user's OpenClaw skills directory without integrity or signature verification. If the repository, maintainer account, or distribution path is compromised, modified skill instructions or additional executable content could be delivered after this reviewed version.

This is a supply-chain hardening issue rather than evidence that the repository currently contains a malicious payload. The audited project itself contains only `README.md` and `SKILL.md`, and no embedded scripts were identified.

### Attack Path

1. An attacker compromises the referenced GitHub repository, its maintainer account, or the default branch.
2. The attacker publishes a modified skill manifest, hostile instructions, or additional files.
3. A user follows the documented `git clone` command, which retrieves the attacker's current default-branch content.
4. The user copies that unverified content into `~/.openclaw/skills/productivity-helper`.
5. OpenClaw later loads the altered skill. Any resulting impact depends on the malicious content and the tools or permissions granted by the runtime.

### Impact Assessment

Exploitation could replace the reviewed skill with attacker-controlled content under the user's skill directory. Beca
...[truncated 346 chars]
Remediation
View remediation

Remediation Suggestions

  • In installation documentation, pin the source to a specific reviewed commit hash or immutable signed release.
  • Publish checksums for release archives and require users or the installer to verify them before installation.
  • Sign release tags or artifacts and document signature verification using a trusted maintainer key.
  • Prefer a trusted registry installation flow that verifies package provenance and integrity.
  • Avoid copying an unrestricted repository checkout directly into the active skills directory; stage and validate its expected file list first.
  • Add automated release scanning and protect the upstream repository with mandatory review, protected branches, and multi-factor authentication.
  • Clearly identify the exact version corresponding to each security audit.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation guidance is broad enough to match many ordinary user requests such as organizing tasks, planning a day, or reviewing progress. This can cause the skill to activate in situations where the user did not specifically intend to invoke it, increasing the chance of unnecessary tool exposure and unintended file or shell operations because the skill has Bash, Read, and Write permissions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example phrase 'Help me plan my day with 5 tasks' is a highly generic everyday request that many assistants should handle without invoking a privileged skill. Using such a common phrase as a trigger increases accidental activation risk, which is especially relevant here because the skill is allowed to use Bash, Read, and Write tools.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.