Back to skill

Security audit

yoooclaw-hotspot-topic-scout

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent content-research purpose, but it can broadly read private phone notifications and use notification-derived topics in external searches without enough user control.

Review carefully before installing. Only use this skill if you are comfortable granting access to selected notification sources, and prefer explicit app/group/time limits. Avoid using it on internal team chats, private client discussions, confidential projects, or personal notifications unless the skill is updated to require confirmation and sanitized external searches.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:9
Finding

Overbroad Access to Private Mobile Notifications

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9-15 and 27-40
Vulnerability Type: Excessive access to private notification data
Risk Level: High

Vulnerable Code Snippet

The following is an English translation of the complete relevant instruction segment:

text
- Internal signals: Notifications on the user's mobile phone
  (content-platform pushes, industry group chats, team discussions,
  and fan feedback).

Users configure three areas of interest through the installation prompt:
- Whom to follow: benchmark bloggers, peer accounts, competitor creators,
  brand accounts, or content sources explicitly selected by the user.
- What to follow: account vertical, content positioning, audience profile,
  and industry keywords.
- Which groups and applications to follow: monitored source platforms and
  groups, such as Xiaohongshu, Bilibili, Jike, official accounts, WeChat
  industry groups, creator groups, and internal team discussion groups.

1. Query notifications for the specified time range by executing:
command: openclaw ntf search --from START_TIME --to END_TIME
yieldMs: 30000

2. Tasks involving "yesterday," "recently," "just now," or "latest
   notifications" must always perform a new query and must not reuse old results.

3. Read the user's configured people, topics, groups, and applications.
   If the user did not provide them, infer the most likely filtering direction
   from the current request and notification context.

4. Filter notifications for content-platform pushes, creator-related group
   chats, benchmark-blogger updates, industry keyword matches, and fan feedback.

Technical Analysis

The Skill directs the agent to execute a time-range-wide notification search and subsequently inspect notifications originating from personal applications, industry groups, creator communities, and internal team discussions. The documented command does not include an app ...[truncated 2256 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit user consent before the first notification query and clearly identify the applications, groups, time interval, and data fields that will be accessed.
  2. If configuration is missing, ask the user to select permitted sources instead of inferring authorization from notification contents.
  3. Apply an application, group, or sender allowlist inside the notification query so excluded data is never returned to the agent.
  4. Retrieve only the minimum required fields, such as source, timestamp, and a locally generated topic label. Avoid returning full message bodies by default.
  5. Exclude personal applications and sensitive notification categories unless separately authorized.
  6. Redact contact identities, message contents, project names, authentication data, and other sensitive values before they enter the model context.
  7. Display a confirmation prompt before expanding the time range or adding another notification source.
  8. Document retention rules and ensure raw notification data is discarded immediately after local filtering.
  9. Maintain an auditable record of the approved scope without storing notification contents.

other

Warning
Location
SKILL.md:44
Finding

External Search Queries Derived from Private Notification Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 44-53
Vulnerability Type: Privacy data exposure through external search providers
Risk Level: Medium

Vulnerable Code Snippet

The following is an English translation of the complete relevant instruction segment:

text
Stage Two: Search external hotspots online

Supplement external hotspots based on internal signals and user configuration:
- Hermes: use the built-in web_search tool.
- OpenClaw: use byted-web-search.
- If neither method is available, use rss-content-flow to retrieve content
  from preconfigured RSS sources as a fallback.

Search strategy:
- Extract 3-5 groups of industry keywords from "what to follow" and search
  each group.
- Extract benchmark-blogger or competitor names from "whom to follow" and
  search for their recent activity.
- If a high-frequency topic appears in internal signals but the information
  is incomplete, search that topic to obtain the complete background.
- Add the current date to the query and prioritize results from the current
  day and the previous 48 hours.
- Perform no more than 10 searches in total.

Technical Analysis

The Skill explicitly uses internal signals as input for external searches. Those internal signals include mobile notifications, group chats, internal team discussions, and fan feedback. When an incomplete topic appears frequently in these private sources, the agent is instructed to search for that topic through an external provider.

No intermediate sensitivity classification, redaction, anonymization, or confirmation step is required. Consequently, confidential project names, unreleased product details, private identities, client names, internal campaign terminology, or unique phrases from private discussions could be included in queries sent to web_search, byted-web-search, or supporting infrastructure.

Search queries are disclosures to an external service ev ...[truncated 1609 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not automatically submit notification-derived terms to external search providers.
  2. Perform local sensitivity classification before constructing any external query.
  3. Remove personal names, group names, client identifiers, project codenames, message quotations, unique phrases, and unreleased product details.
  4. Convert private signals into broad, non-identifying topic categories whenever external enrichment is necessary.
  5. Present the proposed sanitized query to the user and obtain explicit confirmation before submission.
  6. Maintain strict separation between private notification processing and external search tooling.
  7. Prefer local or privacy-preserving sources for enrichment when a topic originated from private communications.
  8. Configure external providers for minimum logging and retention where supported.
  9. Record whether each result originated from private signals without retaining or reproducing the underlying sensitive text.
  10. If a query cannot be safely generalized without losing its meaning, skip external enrichment and report that the private signal could not be independently verified.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs querying phone notifications, industry group chats, team discussions, and fan feedback, all of which are privacy-sensitive data sources. Although the feature is related to the skill’s purpose, the skill text does not require an explicit just-in-time warning, consent confirmation, or data-minimization step before accessing and processing those messages, which creates a real privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.