Back to skill

Security audit

TESP

Security checks for vulnerabilities and agentic risk

Overview

This task-tracking skill is not malicious, but it should be reviewed because it directs agents to persist task metadata in hard-coded files outside the current project with broad triggers and limited user control.

Review before installing. Use this only if you are comfortable with agents creating or updating persistent task queue and archive files, and prefer configuring project-local paths plus rules for what task details must not be recorded.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/protocol.md:54
Finding

Hard-Coded Persistent Task Records Outside the Active Project

Content
View full analysis

Vulnerability Details

File Location: references/protocol.md:54-63
Related Locations: SKILL.md:43-44, references/templates.md:35-52
Vulnerability Type: Hard-coded external storage path and unsafe persistent state handling
Risk Level: Medium

Vulnerable Code

markdown
## Layer 3 rule
Active work lives in:
- `/Users/weweclaw/.openclaw/workspace/TASK_QUEUE.md`

Completed work lives in:
- `/Users/weweclaw/.openclaw/workspace/TASK_ARCHIVE.md`

Rule:
- active board keeps only in-progress / blocked / waiting-for-confirmation work
- completed work should be removed from active view and archived promptly

Technical Analysis

The protocol instructs the agent to persist task records at absolute, user-specific paths outside the skill and active project directories. These destinations are used regardless of the current user, workspace ownership, project context, or sensitivity of the task.

The task-board schemas can contain task descriptions, status information, timestamps, output paths, and links. The skill provides no requirements to:

  • Obtain user approval before writing persistent records.
  • Confirm that the destination belongs to the current user or project.
  • Restrict file permissions.
  • Prevent concurrent or conflicting updates.
  • Separate records belonging to different projects or users.
  • Redact credentials, private URLs, sensitive paths, or confidential task details.
  • Use atomic writes or preserve unrelated existing records.

This violates least-privilege and safe-storage principles. Progress reporting does not inherently require writing potentially sensitive metadata into a fixed external workspace.

Attack Path

  1. The skill is activated for a non-instant or multi-step task.
  2. The task includes sensitive metadata, such as a confidential project name, internal output path, private link, or operational status.
  3. The agent follows the mandatory Layer 3 rule ...[truncated 1294 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace absolute user-specific paths with a caller-provided location or a path relative to the active project.
  2. Require explicit user approval before creating or modifying persistent task-board files.
  3. Verify that the selected destination is within an authorized workspace by resolving and validating its canonical path.
  4. Default to session-only progress messages when persistent storage is not necessary.
  5. Define a data-minimization policy that excludes credentials, tokens, private URLs, confidential task content, and unnecessary local paths.
  6. Apply restrictive file permissions appropriate to the current user and workspace.
  7. Use atomic writes, locking, and conflict detection to prevent corruption or lost updates during concurrent agent activity.
  8. Namespace records by project and task identifier to prevent cross-project state mixing.
  9. Define retention and deletion rules for archived task metadata.
  10. Before modifying an existing board, preserve unrelated records and confirm that the file format and ownership match the active workflow.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description and trigger scope are broad enough to match ordinary task-management or follow-up requests, which can cause the skill to activate outside its intended niche. In practice, this increases the chance of unintended workflow steering, unnecessary protocol enforcement, or conflicts with other more specific skills and user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rule 'Apply TESP whenever silence would create coordination risk' relies on subjective judgment and does not define what counts as coordination risk. That ambiguity can lead to over-application of the protocol, creating unnecessary logging, status signaling, or process overhead in cases where the user did not ask for it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listed trigger phrases are common, everyday requests that overlap heavily with general assistant behavior, making accidental invocation likely. Because this skill changes execution behavior and introduces tracking/audit mechanics, broad triggers can silently alter how user requests are handled without clear consent or need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The required Layer 1 format hard-codes Chinese text and field labels (已接收, 预计 X 分钟可完成, 场景, 目标). This is a natural-language policy concern because the document imposes a specific language on executions without any opt-in, alternative locale, or stated region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template specifies all user-facing status messages in Chinese, which can impose a fixed language on downstream skill behavior. The file does not indicate that Chinese is optional, user-selectable, or required for a region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
64% confidence
Finding

The instruction to use GLM / MiniMax by default imposes a default operational choice in natural language without documenting user choice or contextual justification in this file. While this is not a language setting, it is a policy-like default that could conflict with organizational requirements for explicit selection or region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.