Back to skill

Security audit

心灵补手 V3.5

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed flattery/divination persona skill, but it needs review because it persists behavior into agent/profile configuration and includes an unsafe Claude Code permission bypass.

Install only if you intentionally want a persistent flattery/persona layer that may modify OpenClaw SOUL.md and generated IDE/agent configuration. Avoid using the Claude Code adapter unless the permission-bypass flag is removed, review any SOUL.md or Cursor rule changes before applying them, and do not run the corpus-upgrader or daily-upgrade scripts unless you understand the credential, network, and source-modification effects.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (75)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill advertises and documents shell execution, file operations, network/API use, session persistence, and platform injection behavior, yet the metadata declares no permissions. This creates a transparency and consent gap: a user or host platform may treat the skill as low-risk while it can invoke high-risk capabilities such as install scripts, PATH changes, and writing configuration files.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The stated purpose is a companionship/divination persona skill, but the documentation describes much broader operational behavior: cross-platform injection, install-time file copying and PATH modification, persistent session storage, generated config/rule files, external API calls, and dependency on local engines. That mismatch is dangerous because it can mislead reviewers and users about the true attack surface, causing them to approve a skill that can alter environments and exfiltrate or persist data beyond expected scope.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The adapter unconditionally adds the `--dangerously-skip-permissions` flag when launching Claude Code, which weakens or disables a safety boundary unrelated to the stated persona/divination functionality. Because this is automatic and not scoped to a narrowly justified need, a persona prompt or downstream instruction can gain broader execution latitude than the user likely expects.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The comments describe the dangerous flag as simply allowing 'custom behavior,' which minimizes the real security consequence of bypassing permissions. Misleading documentation increases the chance that maintainers or users will enable a risky mode without understanding that it removes an important control.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
This adapter injects persona content into Cursor IDE rule files and explicitly configures flattering behavior that is inconsistent with the declared skill purpose of divination/fortune-telling. That mismatch is dangerous because it hides behavior from users and can silently alter assistant conduct inside an IDE environment, creating deceptive prompt-injection-style persistence rather than delivering the advertised function.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The inline rule text defines automatic trigger conditions for flattering speech on common conversational events such as user emotions or decisions, which materially expands activation beyond the manifest’s divination-related trigger words. This creates covert behavior that can influence user interactions broadly and persistently, increasing the risk of manipulation and user deception.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The declared skill context is divination/fortune-telling, but the architecture describes a reusable persona/subagent injection framework with cross-platform adaptation, persistent state, and prompt compilation. That mismatch materially expands capability beyond user-expected behavior and can hide a general-purpose agent behavior modification system inside a narrowly described skill.

Context-Inappropriate Capability

Critical
Confidence
100% confidence
Finding
The Claude Code adapter explicitly adds the `--dangerously-skip-permissions` flag, which weakens or bypasses host safety controls unrelated to fortune-telling or conversational persona features. Embedding a permission-bypassing option in generated launch config can cause downstream agents to run with fewer safeguards than the user expects, increasing the chance of unauthorized file or environment access.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The design writes `.claude.json` and Cursor rules files into host workspaces as part of adapter behavior, which exceeds a conversational divination skill's expected scope. Modifying workspace configuration can persist behavior changes, influence future agent sessions, and affect repositories or projects without clear user awareness or consent.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest describes a divination/advice skill, but this file implements a flattery-persona corpus generator with multiple sycophantic roles and triggering logic. This mismatch is dangerous because it obscures the skill’s actual behavior from reviewers and users, increasing the chance of deceptive activation, policy evasion, or hidden persuasive behavior in a context where users may expect reflective guidance instead of manipulation-oriented persona output.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file content does not implement the advertised fortune-telling behavior and instead supplies extensive sycophantic phrase templates. This kind of capability drift is dangerous because it can cause the agent to behave in undisclosed ways, manipulate users emotionally, and bypass product or policy review based on the published skill description.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The included outputs contain sexually suggestive, submissive, and servile language that is unrelated to fortune-telling and can produce coercive or exploitative assistant behavior. In a user-facing skill, this increases the risk of sexualized harassment, inappropriate roleplay, and manipulative emotional dependency, especially if triggered unexpectedly in ordinary interactions.

Intent-Code Divergence

Medium
Confidence
85% confidence
Finding
The design rationale claims restrained, non-flattering language, but the examples include extreme praise and submissive language such as '永远是正确的' and '誓死追随'. In a skill explicitly built around flattering personas, this can normalize manipulative deference, encourage emotional dependency, and increase the risk of unsafe persuasion or over-trust in the assistant’s outputs.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The trigger keyword list is far broader than the stated divination-oriented scope and includes many common conversational tokens such as interjections, praise, and generic distress words. This can cause the divination persona to activate unexpectedly in ordinary chats, resulting in undeclared behavior expansion and steering users toward unsolicited occult-style guidance.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The configuration enables broad emotion sensing with immediate activation upon detecting any emotional tone, plus proactive divination prompting. That behavior materially exceeds a user-invoked fortune-telling skill and can make the persona intervene in sensitive moments without clear user consent.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This persona defines flirtatious and sexually suggestive companion behavior across identity, tone, samples, and service framing, while the skill metadata describes a fortune-telling/divination function. That mismatch creates an unjustified capability surface for sexualized engagement, increasing the risk of policy-violating responses, reputational harm, and unsafe interactions triggered outside the user’s expected context.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The file embeds a sexualized assistant role ('高端VIP异性助理', '性暗示', '让我好好伺候您吧') that is not necessary for providing divination or prediction services. Because the capability is unjustified by the stated purpose, it can be exploited to steer the agent into eroticized roleplay and emotional manipulation under a misleading skill identity.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The persona file defines a flattering servant-style character with broad emotional engagement, but it does not align with the manifest’s stated divination-focused purpose. This mismatch can cause the wrong behavior to activate in unrelated contexts, increasing the chance of deceptive persona switching, user confusion, and policy bypass through capability drift.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
This persona materially diverges from the skill’s stated divination purpose by introducing a standalone political-flattery and agitator role. That mismatch is dangerous because it can cause users seeking benign fortune-telling to be unexpectedly exposed to manipulative ideological framing and loyalty-building behavior unrelated to the declared function.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The configuration explicitly encodes political agitation, absolute loyalty, leader worship, and followership language such as '誓死追随' and '敌人就是我的敌人', which goes beyond style and becomes behavioral conditioning. In the context of a divination-themed skill, this is especially dangerous because the persona can exploit emotional vulnerability and perceived authority to nudge users toward extremist or coercive social dynamics.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The script reads a local API credential from disk and sends persona descriptions and generated prompts to an external LLM service. For a user-facing divination/chat skill, this introduces an unnecessary external data-flow and secret-handling surface; if persona files later contain sensitive or proprietary content, that data would be transmitted off-box without clear controls.

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
This code is not serving the advertised divination/chat behavior; it is a corpus-generation tool that creates and updates training data files by calling a third-party model. That mismatch increases supply-chain and trust risk because a deployed skill package contains hidden content-generation capabilities that can mutate local artifacts and expand what data leaves the environment.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The script performs maintenance actions unrelated to the advertised divination/persona behavior, including modifying project code and generating operational reports. In a skill context, hidden administrative behavior expands the attack surface and can be used to change future model behavior without the user's knowledge.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The script uses in-place editing on core/prompt_compiler.py, giving the skill self-modifying capability despite no legitimate need for autonomous code mutation in a divination/persona skill. Any mechanism that can rewrite prompt logic can be repurposed to silently alter outputs, add hidden instructions, or weaken safeguards persistently.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The script creates persistent logs and reports under /root, which is an administrative capability outside the stated end-user function. While likely intended for maintenance, persistent file generation can expose operational metadata, create unauthorized statefulness, and provide a foothold for covert bookkeeping inside a user-facing skill.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/自动化测试框架.md:80