Back to skill

Security audit

yoooclaw-daily-morning-brief

Security checks for vulnerabilities and agentic risk

Overview

The skill is meant to summarize notifications, but it deserves review because it can broadly read sensitive personal and work notifications without clear per-run confirmation or tight source limits.

Review this skill before installing. It is not clearly malicious, but you should only use it if you are comfortable with an agent querying recent notifications across connected work and personal apps. Configure the narrowest sources possible, use explicit time windows, and require confirmation before broad notification searches.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:25
Finding

Unquoted User-Controlled Time Values in an Exec Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25-34
Vulnerability Type: Command injection through unsafe command construction
Risk Level: Medium

Vulnerable code snippet:

text
1. Query notifications for the specified time range using exec:
If the user does not provide a corresponding time, query notifications from yesterday to the current time:
```text
command: openclaw ntf search --from start-time --to end-time
yieldMs: 30000

Example:

text
command: openclaw ntf search --from 2026-03-01T00:00:00+08:00 --to 2026-03-09T23:59:59+08:00
yieldMs: 30000
text

### Technical Analysis

The Skill instructs the Agent to place a user-selected start and end time directly into a shell-style command executed through `exec`. It does not require strict timestamp validation, shell escaping, quoting, or argument-array invocation.

If the execution backend passes the resulting command through a shell, metacharacters embedded in either time value may be interpreted as additional shell syntax rather than as part of a timestamp. This creates a command-injection boundary between untrusted request data and local command execution.

The static Skill text does not establish whether the underlying `exec` implementation uses a shell, so successful exploitation depends on the host runtime. Nevertheless, the documented construction is unsafe because it does not constrain values to the expected ISO-8601 format or require a shell-independent invocation method.

### Attack Path

1. An attacker submits a morning-brief request containing a crafted start or end time with shell metacharacters and an additional command.
2. The Agent follows the Skill and substitutes the supplied value into the `openclaw ntf search` command.
3. The Agent sends the assembled command string to `exec`.
4. If `exec` invokes a command shell, the shell interprets the metacharacters and executes the injected command.
5. The injecte
...[truncated 564 chars]
Remediation
View remediation

Remediation Suggestions

  1. Accept only strict ISO-8601 timestamps, including an explicitly supported timezone format.
  2. Reject values containing whitespace, shell metacharacters, control characters, unexpected flags, or trailing content.
  3. Parse each timestamp with a trusted date-time library and serialize it back into a canonical form before execution.
  4. Invoke the CLI without a shell, using a structured argument array equivalent to:
    text
    ["openclaw", "ntf", "search", "--from", validatedStart, "--to", validatedEnd]
    
  5. If the platform only supports command strings, apply platform-appropriate shell escaping and quote each validated value; validation must remain the primary control.
  6. Add tests covering command separators, command substitution, embedded newlines, additional CLI flags, malformed timestamps, and oversized input.
  7. Run the notification query under least privilege and restrict the execution environment's filesystem and network access to reduce impact if command handling fails.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are very broad and overlap with common requests like '帮我整理早报' or '今天有什么重要信息和待办', which can cause the skill to activate in contexts where the user did not explicitly intend notification access. Because this skill queries aggregated notifications from potentially sensitive work and personal sources, overbroad activation increases the chance of unnecessary access and summarization of private data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow instructs the agent to run a notification search command across mixed sources including team chats, private chats, email, calendars, and family/life messages, but it provides no explicit warning or consent step before accessing that sensitive content. This creates a privacy and data-minimization risk: a user asking for a generic 'morning brief' may not realize the skill will retrieve and process broad personal and workplace communications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.