Back to skill

Security audit

Chat Ask

Security checks for vulnerabilities and agentic risk

Overview

This is a simple local chat/Q&A skill with some privacy and clarity rough edges, but no evidence of hidden execution, exfiltration, persistence, or destructive behavior beyond its disclosed in-memory history action.

Install only if you want a simple local demo-style chat tool. Do not send secrets or sensitive business data through it unless you are comfortable with that text being echoed in responses and written to local stderr logs. Treat the history feature as non-durable and basic, not as a real conversation archive.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

  1. Manage history:
    text
    Use chat-history to review or clear conversations
    

How to Call Tools

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
# Get last 10 messages
python3 scripts/chat_history_tool.py 'get' 10

# Clear history
python3 scripts/chat_history_tool.py 'clear'

# Get summary

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file describes using chat-history to review or clear conversations, but it does not include any warning that the clear action removes stored chat history. For a data-affecting operation, the documentation should explicitly disclose the deletion impact so users understand the consequence before invoking it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool description 'Start or continue a chat conversation' is broad and maps to common user phrasing, which increases the chance of accidental invocation by an agent or router. Because the tool can send arbitrary user-provided messages into a chat workflow, unintended triggering could expose conversation content or cause unplanned actions in downstream systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description 'Ask a question to OpenClaw' is highly generic and could be matched by ordinary conversational requests, making unintended tool selection more likely. In agentic environments, this can redirect user content into the tool unexpectedly, potentially leaking sensitive prompts or causing incorrect workflow execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest exposes a destructive 'clear' action for chat history without any warning, confirmation requirement, or indication of data loss. If selected accidentally or manipulated through ambiguous prompting, it could erase user conversation history and undermine auditability, continuity, or recovery of prior context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The tool writes the full user message to stderr, which can expose sensitive or private user input to logs, consoles, process supervisors, or centralized log collectors without the user's awareness. In a chat skill, users may reasonably submit secrets, personal data, or internal business information, so indiscriminate logging increases the chance of unintended disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The response templates and optional context handling reflect user-supplied message and context verbatim back in the output, which can reveal sensitive information the user entered and propagate it to downstream systems, transcripts, or UIs. Because this is a chat/ask skill, users may paste confidential content, making echoing especially risky and unnecessary for many use cases.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description says only "Chat and ask functionality for OpenClaw," which is very broad and does not clarify when this skill should be invoked versus general conversation features. In a manifest file, this kind of generic wording can overlap with common user intent and makes the trigger scope insufficiently specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest and module docstrings describe a chat/ask tool, which fits simple Q&A behavior. However, the built-in help text says it can help with 'system status' and 'files', while the implementation only performs keyword matching and returns static strings, including a fabricated system status response. This creates a mild description-behavior mismatch about the actual capability level.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

At L099, the comment says the field would contain the count before clearing, but len(chat_history) is evaluated after clear_chat_history() resets the list at L094-L099. This is an active contradiction between the inline documentation and the actual behavior of the code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.