Back to skill

Security audit

employee-off-duty-detection-2

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed workplace camera-monitoring tool, but it handles sensitive surveillance credentials and employee images with weak scoping and incomplete privacy safeguards.

Install only if you have clear legal authority to monitor the covered workplace, have notified or obtained consent from affected people where required, and can protect camera tokens. Prefer a version that stores tokens in a secret manager, restricts config file permissions, avoids generic exec for capture, documents image retention and external sharing, and scopes alert recipients and camera devices explicitly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:40
Finding

Camera Access Token Stored in a Plaintext Configuration File Without Enforced Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a complete intelligent inspection system with guided setup, configurable tasks, image capture, AI analysis, and alerting. In contrast, the supplied code is mostly a scaffold: it reads/writes config.json, initializes placeholder settings, generates a timestamp-based fileId, and logs that capture/analysis/alerting will be handled elsewhere. There is no implementation of camera access, no calls to AI services, no alert delivery logic, and no Feishu integration. Because the primary described capabilities are not actually present in this code chunk, the description materially overstates what the code does.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- Custom HTTP-based capture endpoints

### Authentication Requirements
- Camera API access tokens or credentials
- Feishu bot permissions (if using Feishu alerts)

### OpenClaw Requirements

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The setup flow instructs collection and local storage of access tokens in a workspace JSON file. Storing sensitive camera/API credentials in plaintext under a predictable path can expose them to other local processes, users, backups, or accidental disclosure, potentially enabling unauthorized camera access or further compromise.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
### 1. Initial Setup (First Run)
When the skill runs for the first time:
1. Prompt user for camera system type
2. Collect API endpoint, access token, device serial, channel number
3. Ask for default inspection prompt template
4. Confirm alert channel preferences
5. Save configuration to `~/.openclaw/workspace/intelligent-inspection-config.json`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly describes camera-based workplace monitoring, snapshot capture, AI analysis, and Feishu alerting, but provides no warning about privacy, consent, retention, or data-sharing implications. In a workplace surveillance context, missing privacy and data-handling disclosures can lead to covert monitoring, unauthorized collection of employee images, and compliance violations, making the skill materially riskier than a generic image-processing tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is designed for employee surveillance, image capture, AI analysis, and alerting, but it lacks an explicit warning about monitoring, consent, and regulatory obligations. In this context, omission of clear notice increases the risk of misuse, noncompliant workplace surveillance, and unauthorized collection or sharing of employee images.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The privacy section states there is no data retention beyond immediate execution, but earlier sections explicitly say the skill saves configuration, including camera access tokens and device details, to ~/.openclaw/workspace/intelligent-inspection-config.json. This is an active contradiction between the documentation's privacy claim and the documented behavior of persistent local storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Documenting use of a generic exec tool for camera capture expands the skill's effective power beyond narrowly scoped image acquisition. If implemented without strict command allowlisting and argument validation, this could enable arbitrary command execution, especially because camera endpoints and parameters are user-supplied during setup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The defaultPrompt is written entirely in Chinese and does not indicate that language selection is optional, user-configurable, or justified by a region-specific requirement. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The config contains natural-language instructions and alert messages only in Chinese, including mandated response terms ('离岗'/'在岗'). This forces a specific language/locale behavior without any indication that users can choose another language or that the skill is restricted to a Chinese-language deployment context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill persists its configuration to a local config.json file, and the configuration structure explicitly includes sensitive camera credentials such as an accessToken. Storing such secrets on disk without encryption, permission hardening, or an explicit warning increases the risk of credential disclosure through local file access, backups, logs, or accidental sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The embedded natural-language prompt instructs the model to respond only with the Chinese outputs "离岗" or "在岗". This imposes a specific language/locale in the skill behavior without any user opt-in or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Natural-language policy requires avoiding forced language or locale constraints unless users are given a choice or the limitation is clearly justified. This README is written entirely in Chinese and does not indicate that other languages are supported or that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The default prompt template requires the model to reply with specific Chinese terms ('离岗' or '在岗'), and the examples are also Chinese-only. This imposes a language choice in the skill content without indicating that users can opt into another language or locale.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON manifest/config file includes a natural-language prompt but provides no surrounding constraint or alternative language handling. In a manifest-like file, hard-coding the interaction text without scope clarification can make the intended usage less specific and may contribute to ambiguous behavior in multilingual environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.