Back to skill

Security audit

Summarize Pro 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This is a local summarization skill with disclosed local history, stats, saved-summary, and template storage, and no artifact evidence of network access, hidden execution, or destructive behavior.

Install only if you are comfortable with the skill keeping local summary metadata, stats, saved summaries, and custom templates under ~/.openclaw/summarize-pro/. Avoid summarizing sensitive content if local history records of topics, timestamps, and word counts would be a problem, or periodically review/delete that directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description advertises an extremely broad scope covering many content types and summary styles, increasing the chance the orchestrator routes loosely related requests to this skill. In context, that matters because the skill also persists history and stats, so mistaken activation can create unexpected local data retention.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The skill instructs creation of a persistent directory and files on first run, establishing stateful storage automatically. Persistent local storage is not inherently malicious, but it increases privacy risk because user activity and saved summaries can survive beyond the current session without explicit consent.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

First Run Setup

On first message, create data directory:

bash
mkdir -p ~/.openclaw/summarize-pro

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation rules include very broad phrases such as 'summary', 'compare', and 'bullet points' that can match common user speech outside the intended task. Over-broad triggers can cause unintended activation, leading the skill to process and persist user content when the user did not clearly request this specific tool behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill auto-logs every summary to persistent history, but the user-facing description emphasizes local-only processing without clearly warning that content metadata will be retained by default. This can mislead users into believing summarization is ephemeral when it is not.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic history logging creates a retention path for user-derived data such as topic, timestamps, format, and word counts without explicit consent. Even if full source text is not stored, this metadata can still reveal sensitive activity patterns and document subjects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

Custom templates are user-defined and stored persistently, which extends retention of user-authored structures and preferences across sessions. In this context the risk is privacy and unbounded state accumulation rather than code execution, but it still expands stored user data without explicit lifecycle controls.

Content

Scanner excerpt · SKILL.md (reported line 555)May include surrounding context.

md
## FEATURE 19: Custom Templates

When user says **"create template [name]"** or **"my templates"**:

Let users define their own summary format:

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

md
When user says **"summarize in [language]"** or **"hindi mein summarize karo"**:

Supported languages include but not limited to:
Hindi, Spanish, French, German, Japanese, Chinese, Arabic, Portuguese, Italian, Korean, Russian, and more.

Summarize the content and output the summary IN the requested language.

Ssd 3

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Persistent stats tracking after every summary records usage behavior over time, including counts and processed word totals. While lower risk than storing content, it still creates a behavioral profile tied to the user's document-processing activity without a clear consent flow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and privacy section repeatedly state that all processing happens locally and that the skill does not access any external service, API, or URL. However, the file includes an external hyperlink to x.com in the built-by line, which conflicts with the stated 'does NOT access any external service, API, or URL' positioning, even though it is documentation rather than runtime behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.