Back to skill

Security audit

Ai Intelligent Content Generation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple, disclosed AI content-generation listing, with no embedded executable code or hidden behavior in the submitted files.

Before installing, review the external GitHub repository and its requirements file because the submitted artifact does not include that code. The listed OpenClaw Skills Team attribution should be treated as unverified because the package metadata names a different author.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The manifest and top-level description state the skill is for article and image generation, but the documented features expand into video generation, title optimization, and content moderation. This creates a scope mismatch that can mislead users, reviewers, and policy controls about what the skill actually does, increasing the chance of unauthorized or insufficiently reviewed capabilities being invoked.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is high-level and lacks clear activation boundaries, inputs, and limits for when each capability should be used. In agent settings, overly broad descriptions can cause inappropriate triggering, unintended handling of sensitive content, or use of moderation/generation functions outside the user's intent.

Static analysis

No suspicious patterns detected.