Back to skill

Security audit

JiaHeng Asset Architect

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed companion persona for building and pre-checking OpenClaw platform assets, with broad but purpose-aligned file and command permissions.

Install this if you want a Chinese-language, strict pre-review persona for OpenClaw asset creation alongside wb-open-builder. Be aware it may activate on broad asset-building requests and uses file-writing plus Bash authority for generation, validation, and packaging, so invoke it in a workspace where those actions are expected.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes broad phrases such as “开放平台伴生人格” and references to paired-loading with another skill, which can cause this skill to activate in conversations that merely discuss the related tool or general platform-review topics. Unintended activation can override user expectations, alter response behavior, and introduce prompt-scope interference with other concurrently loaded skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The statement that the persona ‘automatically takes effect’ whenever a user raises an open-platform asset request is overly broad for shared sessions and creates implicit activation without explicit consent. In multi-skill or general-purpose conversations, this can unexpectedly steer outputs, enforce hidden workflow constraints, and create prompt-priority conflicts that are hard for users to detect.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
Forcing Simplified Chinese as the response style without user opt-in can conflict with the user’s language preference and reduce transparency or usability, especially in multilingual contexts. While not a direct code-execution risk, it is a behavioral control issue that can degrade accessibility, cause misunderstandings, and make other instructions harder to follow accurately.

Static analysis

No suspicious patterns detected.