Back to skill

Security audit

Smart Surprise

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly designed to send recurring surprise messages, but it needs Review because it creates an indefinite self-renewing cron chain, stores learned preferences, and may read sensitive calendar credentials.

Install only if you intentionally want an autonomous companion that can message you indefinitely. Before enabling it, set your own timezone, location, channel, and target; consider disabling calendar unless you have a safer brokered integration; review the topics file because it stores learned preferences; and make sure you know how to stop all Smart Surprise cron jobs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T06 · System Persistence

Error
Location
SKILL.md:79
Finding

Indefinite Self-Renewing Cron Persistence

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:155
Finding

Raw OAuth Credentials and Local Helper Script Exposed to Agent Context

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:62
Finding

Unvalidated Generated Content Interpolated into a Shell-Like Command

Content
View full analysis
--target --message "" ``` ``` The target is also documented as direct command input: ```markdown ### channelTarget **Type:** string **Required:** Yes Recipient ID on your configured channel. Used for `openclaw message send --target `. ``` ### Technical Analysis The delivery instruction represents free-form generated content and configuration values as substitutions in a command-line template. It does not require an argument-array execution API, prohibit shell evaluation, define escaping rules, or validate the target. A generated message can contain quotation marks, command substitutions, shell metacharacters, or newline characters. If the agent implements the documented template through a shell, such content may terminate the quoted message argument and alter command parsing. An attacker-influenced `channelTarget` or `channel` value can similarly introduce extra arguments or shell syntax. The vulnerability is conditional on the execution method: invoking the CLI directly with a correctly separated argument array would prevent shell metacharacter interpretation. The Skill does not require that safe method. ### Attack Path 1. An attacker influences conversation content, preference data, or configuration used to compose a future message. 2. The generated message or configured target contains quote-breaking text or shell metacharacters. 3. The agent substitutes the value into the documented command template. 4. If the command is executed through a shell, the shell parses attacker-controlled syntax rather than treating it solely as message data. 5. The injected syntax adds unintende ...[truncated 606 chars]
Remediation
View remediation

other

Warning
Location
references/config.md:42
Finding

User Location Disclosed to an External Weather Service Without Explicit Per-Integration Consent

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (20)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description authorizes proactive outreach in broad terms and ties execution not only to initial setup but also to whenever the agent 'wants' to reach out. In a messaging skill with cron-based automation, that ambiguity weakens user consent boundaries and can result in repeated unsolicited contact without a clear, user-scoped trigger condition.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description emphasizes surprise-driven, indefinite automatic messaging but does not prominently warn that it will continue sending messages forever unless stopped. For a proactive skill that can message external channels automatically, missing disclosure undermines informed consent and raises spam, harassment, and trust risks.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/setup.md (reported line 194)May include surrounding context.

md
openclaw cron rm <job-id>   # repeat for each job found

# Step 2: Remove the skill directory
rm -rf ~/.openclaw/workspace/skills/smart-surprise

# Step 3: Optionally remove runtime state
rm -f ~/.openclaw/workspace/skills/smart-surprise/next_run.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/setup.md (reported line 194)May include surrounding context.

md
openclaw cron rm <job-id>   # repeat for each job found

# Step 2: Remove the skill directory
rm -rf ~/.openclaw/workspace/skills/smart-surprise

# Step 3: Optionally remove runtime state
rm -f ~/.openclaw/workspace/skills/smart-surprise/next_run.json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/setup.md (reported line 197)May include surrounding context.

rm -rf ~/.openclaw/workspace/skills/smart-surprise

Step 3: Optionally remove runtime state

rm -f ~/.openclaw/workspace/skills/smart-surprise/next_run.json

text

This fully removes Smart Surprise from your system.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill explicitly persists behavioral state across runs via topics/preferences and a self-perpetuating cron chain that learns from conversation history. Persistent autonomy and memory increase risk because the system can continue acting on accumulated user data without fresh consent at each run, especially in a background messaging context.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
Smart Surprise transforms a passive AI assistant into a **proactive companion** that reaches out to users at unpredictable moments — with greetings, care, tips, news, or just a friendly chat. Over time it learns what the user likes and tailors content accordingly, making every interaction feel more personal.

Unlike fixed scheduled tasks that feel mechanical, Smart Surprise uses a **chain of self-deleting one-shot cron jobs** to create organic, surprise-driven interactions. The chain runs indefinitely and **learns continuously** from what the user responds to.

## How the Core Loop Works

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill records preference signals from user behavior and conversation responses, including non-response, but does not provide a clear privacy notice or retention policy. This creates covert profiling risk because users may not realize their interactions are being persistently analyzed and stored to shape future outreach.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Defaulting to a specific timezone/locale without user opt-in can lead to messages being sent at inappropriate local times and can mis-handle quiet hours. In a proactive messaging skill, that context makes the issue more consequential because incorrect locale assumptions directly affect when unsolicited messages are delivered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The config sets "timezone": "Asia/Shanghai" and "location": "Hangzhou", which imposes a specific locale context. Under the policy, forcing a locale is a finding unless the skill offers user choice or clearly documents a justified region-specific scope, which is not evident in this file.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup.md (reported line 12)May include surrounding context.

md
---

## Step 1: Create the Config File

Create `~/.openclaw/workspace/skills/smart-surprise/config.json`:

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The setup explicitly instructs the user to create an initial cron trigger that starts a self-perpetuating chain, establishing durable automated execution beyond the initiating session. This kind of persistence is security-relevant because it continues acting without further user confirmation and can be abused for repeated messaging, data collection, or stealthy long-term operations.

Content

Scanner excerpt · references/setup.md (reported line 49)May include surrounding context.

md
---

## Step 2: Create the Initial Cron Trigger

Run this **once** to start the self-perpetuating chain. The initial trigger should be **~5 minutes after setup** so the agent has time to initialize. Generate the UTC timestamp dynamically:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/setup.md (reported line 62)May include surrounding context.

--session isolated
--delete-after-run
--at "$INIT_TIME"
--message "Read ~/.openclaw/workspace/skills/smart-surprise/SKILL.md and execute Phase 2: Runtime workflow. Deliver a greeting message to the user, then schedule the next random trigger and delete this job."
--timeout-seconds 900

text

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/setup.md (reported line 85)May include surrounding context.

--session isolated
--delete-after-run
--at "$INIT_TIME"
--message "Read ~/.openclaw/workspace/skills/smart-surprise/SKILL.md and execute Phase 2: Runtime workflow. Deliver a greeting message to the user, then schedule the next random trigger and delete this job."
--timeout-seconds 900

text

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/setup.md (reported line 166)May include surrounding context.

--session isolated
--delete-after-run
--at "$INIT_TIME"
--message "Read ~/.openclaw/workspace/skills/smart-surprise/SKILL.md and execute Phase 2: Runtime workflow. Deliver a greeting message to the user, then schedule the next random trigger and delete this job."
--timeout-seconds 900

text

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The documented design intentionally creates a self-perpetuating cron chain that repeats forever, giving the skill indefinite execution persistence and ongoing access to messaging and preference-update behavior. Even without overtly malicious payloads, this can lead to unwanted resource consumption, spam, hard-to-notice long-term automation, and increased blast radius if the skill logic is later modified or compromised.

Content

Scanner excerpt · references/setup.md (reported line 142)May include surrounding context.

md
1. The initial cron fires at the scheduled time
2. The agent reads config + topics.md, composes a message, sends it, updates preferences, schedules the next random trigger, then deletes itself
3. The next trigger fires at the random time (between `minIntervalMinutes` and `maxIntervalMinutes`)
4. Repeat forever

The agent continuously learns your preferences over time by updating topics.md after each interaction.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The troubleshooting instructions reinforce recreating the persistent cron-based execution path, further normalizing long-lived autonomous operation. This increases risk because users are encouraged to restore persistence whenever the chain breaks, preserving continuous execution with minimal oversight.

Content

Scanner excerpt · references/setup.md (reported line 160)May include surrounding context.

md
openclaw cron list | grep -i surprise
openclaw cron rm <job-id>   # repeat for each job found

# Recreate with correct session target (isolated)
openclaw cron add \
  --name "Smart Surprise" \
  --session isolated \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown file provides uninstallation commands using rm -rf and rm -f to remove the skill directory and runtime state. While the commands are clearly shown, the section does not explicitly warn users that these deletions are irreversible and will permanently remove local skill data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file explicitly instructs the agent to silently update user preference data after each interaction and stores those updates in a persistent file, while providing no clear upfront notice or consent mechanism in the skill itself. This creates a privacy and transparency issue: users may be profiled or have behavioral inferences recorded without meaningful awareness, and the persistence of those updates increases the risk of misuse, surprise, or unauthorized modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file documents that each run writes next_run.json, which is a user-data-affecting file operation. Although it says 'Do not edit manually,' it does not clearly frame the write as a behavioral warning to users in the broader skill description, so the persistence side effect may be easy to miss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The sample configuration hard-codes Asia/Shanghai and Beijing, which can be read as prescribing a specific locale by default. The document does not explicitly tell users to choose their own timezone/location in that example block, creating a mild locale-policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/setup.md:194