Back to skill

Security audit

家庭消费意图识别 V4

Security checks for vulnerabilities and agentic risk

Overview

This is a local family finance tracker, but it persists sensitive household financial data in plaintext and uses broad activation wording that could capture data unintentionally.

Install only if you are comfortable storing household spending, income, subscriptions, goals, and family-member details as local plaintext JSON files. Use it deliberately for finance tracking, avoid letting broad phrases automatically record data, and review or delete ~/.openclaw/skills-data/family-expense-intent/ when you no longer need the records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
expense_tracker.py:16
Finding
Sensitive Financial Records Stored in Plaintext Without Enforced Access Restrictions## Vulnerability Details **File Location**: `expense_tracker.py`, lines 16–42 **Vulnerability Type**: Plaintext storage of sensitive data with ambient filesystem permissions **Risk Level**: Medium ### Vulnerable Code ```python # 数据目录 DATA_DIR = Path.home() / ".openclaw" / "skills-data" / "family-expense-intent" PROFILES_FILE = DATA_DIR / "profiles.json" CONVERSATIONS_FILE = DATA_DIR / "conversations.json" INCOME_FILE = DATA_DIR / "income.json" PATTERNS_FILE = DATA_DIR / "patterns.json" BUDGETS_FILE = DATA_DIR / "budgets.json" GOALS_FILE = DATA_DIR / "goals.json" SUBSCRIPTIONS_FILE = DATA_DIR / "subscriptions.json" def ensure_data_dir(): """确保数据目录存在""" DATA_DIR.mkdir(parents=True, exist_ok=True) files = { PROFILES_FILE: {"members": {}, "default_member": None}, CONVERSATIONS_FILE: {"conversations": []}, INCOME_FILE: {"income": []}, PATTERNS_FILE: {"patterns": {}, "insights": []}, BUDGETS_FILE: {"budgets": {}, "monthly_total": 10000}, GOALS_FILE: {"goals": []}, SUBSCRIPTIONS_FILE: {"subscriptions": []}, } for f, default in files.items(): if not f.exists(): with open(f, 'w', encoding='utf-8') as fp: json.dump(default, fp, ensure_ascii=False, indent=2) ``` ### Technical Analysis The application persists household profiles, free-form expense descriptions, income, budgets, savings goals, and subscription records as unencrypted JSON files. The data directory is created without an explicit owner-only mode, and files are opened without explicitly enforcing mode `0600`. Their effective permissions therefore depend on the process umask and permissions inherited from parent directories. On a system with a permissive umask or shared access to the user's data hierarchy, another local user or process may be able to read these records. The application also does not inspect or repair ...[truncated 1788 chars]
Remediation
## Remediation Suggestions 1. Create the data directory with owner-only permissions and repair existing permissions: ```python DATA_DIR.mkdir(parents=True, exist_ok=True, mode=0o700) os.chmod(DATA_DIR, 0o700) ``` 2. Create new data files with mode `0600`, preferably through `os.open` so permissions are specified atomically: ```python fd = os.open(file_path, os.O_WRONLY | os.O_CREAT | os.O_EXCL, 0o600) with os.fdopen(fd, "w", encoding="utf-8") as fp: json.dump(data, fp, ensure_ascii=False, indent=2) ``` 3. Validate and correct permissions on every existing JSON file during initialization: ```python os.chmod(file_path, 0o600) ``` 4. Use atomic writes through a temporary file in the protected data directory, set that file to mode `0600`, flush and synchronize it, and then replace the destination with `os.replace`. 5. Consider authenticated encryption at rest for financial records when the deployment threat model includes local account compromise, shared storage, backups, or device theft. Store encryption keys through an operating-system credential facility rather than beside the encrypted files. 6. Avoid broadly suppressing file-access and JSON errors. Report permission failures safely so users know when secure storage initialization or permission repair did not succeed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Content
---
name: family-expense-intent
description: "家庭消费意图识别 V4 - 智能家庭财务管理,支持收入管理、储蓄目标、消费洞察、定期订阅、趋势分析、购物比价。"
homepage: https://github.com/openclaw/skills
metadata:
  clawdbot:
    emoji: "💰"
    requires:
      bins: ["python3"]
---

# 家庭消费意图识别 V4

智能家庭财务管理助手,整合多款优秀技能功能。

## 功能特性 (V4 新增)

- 🤖 **智能识别** - 自动识别消费金额、类别、意图
- 👨‍👩‍👧‍👦 **多人管理** - 支持家庭成员独立档案
- 💰 **收入管理** - �
Confidence
80% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases are extremely broad words like '买', '花了', and '预算', which overlap heavily with ordinary conversation. This can cause accidental invocation of the skill during unrelated chats, increasing the chance that sensitive household financial data is collected, persisted, or acted on without clear user intent.

Lp3

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding
The skill manifest advertises Python-based functionality and explicitly documents persistent storage under the user's home directory, but it does not declare any tool scope or permissions boundaries. In an agent environment, this creates an authorization ambiguity where file read/write behavior may be broader than users expect, especially given the sensitive financial data the skill stores.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
整个技能描述、命令示例中的意图短语和触发方式均默认要求中文输入,未向用户提供语言选择,也未说明该语言限制的必要性。按照语言/locale 政策,这种未获用户选择的单一语言约束应视为自然语言政策风险。

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill stores and analyzes highly sensitive household financial information, including income, spending, subscriptions, and goals, yet the documentation lacks clear privacy warnings, consent expectations, retention details, or data handling limitations. Users may unknowingly persist intimate financial records locally or expose them to downstream tooling without understanding the privacy consequences.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description advertises a wide set of financial-management capabilities such as income management, savings goals, subscriptions, insights, trend analysis, and price comparison without stating clear activation boundaries or trigger conditions. In an agent-skill context, overly broad scope can cause the assistant to invoke the skill in unintended situations, increasing the chance of over-collection or misuse of sensitive household financial data.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The file-level description is entirely in Chinese and presents the skill as a Chinese-language household expense intent recognizer, while the parser keywords and CLI messaging also assume Chinese inputs. There is no indication that users may choose another language or that the locale restriction is optional or justified as a region-specific tool.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This skill persistently stores sensitive household financial data under the user's home directory in plaintext JSON files, including spending, income, goals, subscriptions, and family-member metadata, without any notice, consent flow, access control, or protective measures. In a shared system, compromised account, or backup/sync scenario, this creates a realistic confidentiality risk because highly sensitive personal financial history can be exposed.

Intent-Code Divergence

Low
Confidence
95% confidence
Finding
The docstring and inline comment state that the feature should call external APIs for Taobao/JD price comparison, but the implementation only returns fixed demo data. This is an active contradiction between the code documentation and the actual behavior, which can mislead users or integrators about the skill's real capability.

Static analysis

No suspicious patterns detected.