Back to skill

Security audit

Lawyer Assistant

Security checks for vulnerabilities and agentic risk

Overview

This legal-assistant skill is purpose-related but needs review because it can present synthetic legal cases as external results and handles sensitive legal data without adequate controls.

Review carefully before installing. Use only redacted or public case summaries, independently verify every cited case and legal authority, avoid enabling external API modules unless HTTPS and consent controls are added, and treat the local case/rating files as sensitive plaintext data that should not be committed or shared.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

other

Error
Location
enhanced_api.py:115
Finding

Fabricated Case Records Are Presented as External API Results

Content
View full analysis
List[Dict]: """Try OpenLaw.""" self._check_daily_limit('openlaw') if self.sources['openlaw']['used_today'] >= self.sources['openlaw']['free_limit']: return [] start_time = time.time() try: cases = self._generate_mock_cases(keyword, limit, 'OpenLaw') elapsed = time.time() - start_time self._update_stats('openlaw', elapsed, len(cases) > 0) self.sources['openlaw']['used_today'] += 1 return cases except Exception as e: self._update_stats('openlaw', time.time() - start_time, False) return [] ``` ```python def _generate_mock_cases(self, keyword: str, limit: int, source: str) -> List[Dict]: cases = [] if '劳动' in keyword or '辞退' in keyword: cases = [ { '案号': f'(2024) {source[:1]}01 民终 1234 号', '法院': f'{source}示例法院', '日期': '2024-01-15', '案由': '劳动合同纠纷', '争议焦点': '违法解除劳动合同', '裁判要旨': '公司未提供培训或调岗证据,构成违法解除...', '判决结果': '支付赔偿金', 'source': source } ] elif '消费' in keyword or '假货' in keyword: cases = [ { '案号': f'(2024) {source[:1]}02 民终 5678 号', '法院': f'{source}示例法院', '日期': '2024-02-20', '案由': '网络购物合同纠纷', '争议焦点': '假货三倍赔偿', '裁判要旨': '商家销售假货构成欺诈...', '判决结果': '退一赔三', 'source': source } ] elif '离婚' in keyword: cases = [ { '案号': f'(2024) {source[:1]}03 民终 9012 号', '法院': f'{source}示例法院', '日期': '2024-03-10', ...[truncated 2746 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
external_api.py:21
Finding

Legal Search Terms and API Credentials Are Sent over Plaintext HTTP

Content
View full analysis
Dict: url = f"{self.base_url}/case/{case_id}" try: response = requests.get(url, timeout=self.timeout) if response.status_code == 200: return { 'success': True, 'data': response.json() } ``` The scraper uses the same insecure scheme: ```python self.base_url = "http://openlaw.cn" self.search_url = "http://openlaw.cn/search" ``` ```python params = { 'keyword': keyword, 'page': page, 'pageSize': page_size } response = self.session.get( self.search_url, params=params, timeout=self.timeout ) ``` ### Technical Analysis The OpenLaw clients use HTTP rather than HTTPS. Search keywords are placed in the URL query string, and the optional API key is also placed in that query string. HTTP provides neither confidentiality nor transport integrity. Any network intermediary can inspect or modify requests and responses. In addition, query-string credentials may be retained in server logs, proxy logs, browser or debugging history, and monitoring infrastructure. Legal search terms can reveal dispute categories or facts derived from a user's case. Although the currently active enh ...[truncated 1157 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
user_contribution.py:26
Finding

Sensitive Legal Records and Personal Identifiers Are Persisted in Plaintext

Content
View full analysis
Dict: if not user_id: user_id = f"anonymous_{datetime.now().timestamp()}" required_fields = ['纠纷类型', '案情描述', '裁判结果'] missing = [f for f in required_fields if not case_data.get(f)] if missing: return { 'success': False, 'error': f'缺少必填字段:{", ".join(missing)}', 'case_id': None } case_id = self._generate_case_id() case_record = { 'case_id': case_id, 'user_id': user_id, 'submit_time': datetime.now().isoformat(), 'status': 'pending', 'review_note': '', 'data': case_data, 'source': 'user_contribution', 'views': 0, 'likes': 0, 'useful_count': 0 } self.cases.append(case_record) self._save_json(self.cases_file, self.cases) if user_id not in self.users: self.users[user_id] = { 'user_id': user_id, 'register_time': datetime.now().isoformat(), 'total_submissions': 0, ...[truncated 1750 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
user_contribution.py:182
Finding

Case Moderation and Reputation Operations Lack Authorization Controls

Content
View full analysis
Dict: case = None case_index = -1 for i, c in enumerate(self.cases): if c['case_id'] == case_id: case = c case_index = i break if not case: return { 'success': False, 'error': '案例不存在' } if case['status'] != 'pending': return { 'success': False, 'error': f'案例已审核(状态:{case["status"]})' } case['status'] = 'approved' if approved else 'rejected' case['review_note'] = review_note case['review_time'] = datetime.now().isoformat() self.cases[case_index] = case self._save_json(self.cases_file, self.cases) self.stats['pending'] -= 1 if approved: self.stats['approved'] += 1 user_id = case['user_id'] if user_id in self.users: self.users[user_id]['approved_count'] += 1 self.users[user_id]['points'] += 20 self._update_user_level(user_id) else: self.stats['rejected'] += 1 self._save_json(self.stats_file, self.stats) self._save_json(self.users_file, self.users) ``` ```python def like_case(self, case_id: str) -> Dict: for case in self.cases: if case['case_id'] == case_id: case['likes'] += 1 self._save_json(self.cases_file, self.cases) return { 'success': True, 'likes': case['likes'] } return { 'success': False, 'error': '案例不存在' } def mark_useful(self, case_id: str) -> Dict: for case in self.cases: if case['case_id'] == case_id: case['useful_count'] += 1 if case['useful_ ...[truncated 2054 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
openlaw_scraper.py:261
Finding

Caller-Controlled Filenames Permit Path Traversal and Arbitrary JSON File Access

Content
View full analysis
List[Dict]: filepath = self.output_dir / filename with open(filepath, 'r', encoding='utf-8') as f: return json.load(f) ``` ### Technical Analysis Both methods join a caller-controlled filename directly to `output_dir`. `pathlib.Path` does not automatically enforce containment. A relative value containing parent components, such as `../../target.json`, can resolve outside the intended test-case directory. An absolute path can also replace the base path semantics. `save_cases` can overwrite any writable target with JSON content. `load_cases` can read and parse any accessible file containing valid JSON. No canonicalization, basename restriction, extension enforcement, symlink check, or containment validation is present. ### Attack Path 1. An attacker gains control over the `filename` argument through code that exposes `OpenLawScraper`. 2. For reading, the attacker supplies a traversal path such as `../../sensitive.json`. 3. `load_cases` opens the resolved path outside `output_dir` and returns its parsed contents if it is valid JSON. 4. For writing, the attacker supplies a traversal or absolute path naming a writable target. 5. `save_cases` opens the target in write mode and replaces it with attacker-selected JSON data. 6. If the targeted file controls another application component, the overwrite can corrupt state or influence subsequent behavior. ### Im ...[truncated 473 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (79)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

示例直接鼓励输入案情、裁判结果、案号、法院、日期等真实案件信息,却未明确警告不要上传保密材料、律师工作底稿、受保护的证据或律师—客户特权信息。该技能属于法律场景,用户可能是律师、当事人或学生,误提交受保密义务约束的内容会带来严重的隐私、职业伦理和法律合规后果。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document explicitly instructs users to create a GitHub repository with either Public or Private visibility and then push the local skill repository, but it does not warn that this action may upload code, prompts, test data, embedded secrets, or other project artifacts to an external hosting service. In the context of an agent skill, this can lead to accidental disclosure of proprietary logic or sensitive data, especially if users choose a public repository or do not review contents before pushing.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

方法二:手动安装

bash
# 创建技能目录
mkdir -p ~/.openclaw/skills/lawyer-assistant

# 复制文件
cp SKILL.md ~/.openclaw/skills/lawyer-assistant/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README instructs users to provide detailed case facts, identities, evidence, and dispute information, which are highly sensitive personal and legal data. Without an explicit privacy warning, data-minimization guidance, or handling/storage disclosure, users may expose confidential information to the agent environment or logs unintentionally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

标题和全文说明均以中文固定呈现,文件中未说明用户可选择其他语言或根据用户偏好切换输出语言。按规则,若技能强制特定语言而无用户选择或地区性正当说明,属于自然语言策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad and include common legal/help-seeking terms such as “律师”, “法律咨询”, “案件分析”, “案例”, and “纠纷”, which can cause the skill to activate in contexts where the user did not intend to invoke a legal-analysis workflow. In a legal-advice context, unintended activation is more sensitive because it may prompt collection of personal case details or generate quasi-legal guidance inappropriately.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains module docstrings, class/function docstrings, and runtime print messages in Chinese only, which imposes a specific language on users. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module-level description and all user-facing analysis perspectives are written as fixed Chinese-language behavior, with no indication that users can choose another language or that the tool is limited to a Chinese-only compliance context. This creates a natural-language locale policy issue because the skill appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This Python file is a code file, so SQP-3 applies to its natural-language strings. The top-level and class documentation are entirely in Chinese and present the skill as Chinese-only, with no indication that users may choose another language or that the locale restriction is required for a region-specific compliance purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring claims an 'enhanced case data API integration' with prioritized data sources such as OpenLaw, 无讼, and 中国法院网. However, the search flow ultimately uses _generate_mock_cases and comments at L126-L127, L151, L169, and L185-L187 acknowledge that real API calls are not implemented, so the documentation materially overstates what the code does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code sends user-provided search keywords, and optionally an API key, to an external third-party service over plain HTTP without any user disclosure or consent mechanism. This can expose sensitive legal search terms and credentials to the remote service and to network observers, making the privacy risk materially worse in a legal-case search context where queries may contain confidential matters.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sends user search keywords and an API key to a third-party paid API without any user-facing warning. In this skill's context, legal search terms may contain highly sensitive dispute details, and sharing them with an external provider creates privacy, compliance, and credential-exposure risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This Python file is a code file, so only SQP-2 and SQP-3 apply. The module docstring, class docstring, method docstrings, and test output strings are entirely in Chinese, which constitutes a natural-language locale constraint with no opt-in or explanation that the skill is China-specific or intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file advertises case analysis, legal retrieval, and strategy suggestions, but also initializes and uses a rating system for submitting ratings, viewing statistics, trends, and tags. In the absence of a manifest declaring service analytics or feedback collection, this is additional product telemetry/engagement functionality beyond the obvious legal-assistant role.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code constructs a query from dispute type and case cause, then sends it to an external API without any user-facing warning, consent step, redaction, or minimization. Legal case descriptions often contain highly sensitive personal, employment, family, financial, or medical details, so silent transmission to third parties creates a significant privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill recommends lawyers and outputs contact details without any visible consent, provenance, or policy checks around how those profiles are sourced and whether disclosure is authorized. In a legal-assistance context, this can enable inappropriate sharing of personal/professional contact data, biased steering, or undisclosed referral behavior that users may mistake for neutral advice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level docstring says the tool retrieves real cases from OpenLaw and is only for validation testing. However, the HTML parser explicitly returns no real parsed results and states that mock data is used instead, while the main execution path generates simulated cases and writes them to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The HTTP header hard-codes 'Accept-Language' to prefer 'zh-CN', and the surrounding comments/docstrings are entirely Chinese-language without any opt-in or documented region-specific requirement. This matches the policy concern for language/locale constraints being imposed by the skill rather than selected by the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Natural-language strings in the module description, API messages, form labels, and test output are presented only in Chinese, which can amount to forcing a specific language without user choice. The file does not indicate that this is a region-specific tool or provide any mechanism for locale selection or opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code stores user-submitted ratings, replies, user_id, session_id, and free-text comments/suggestions in local JSON files without any visible consent flow, retention controls, access controls, or minimization. This creates a privacy and data-protection risk because personal or sensitive information can be collected and persisted indefinitely, and free-text fields may contain additional confidential data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The JSON dataset uses exclusively Chinese field names and Chinese-language values throughout, with no indication that another language or locale is supported or that Chinese is an intentional opt-in. Under the policy for natural-language violations, a file that imposes a single language without documented user choice or justification should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The user-facing comments and echoed messages are entirely in Chinese, indicating the skill is designed around a single language experience. Under the policy rule, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code persists user-submitted case content, user identifiers, and review metadata to local JSON files with no privacy controls, minimization, access restrictions, encryption, retention policy, or user consent flow. Because the stored content may include sensitive legal facts and personal identifiers, unauthorized local access, backup leakage, or accidental sharing of the workspace could expose confidential personal or case information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill adds compensation estimation formulas for legal disputes but presents them as functional outputs and tested results without a clear disclaimer that they are only preliminary, non-authoritative references requiring lawyer review. In a legal-assistance context, users may rely on these figures for settlement, litigation, or claims decisions, and simplified formulas can be materially wrong when statutory caps, evidentiary issues, jurisdictional rules, or case-specific facts apply.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill prompts users to provide detailed legal dispute facts, including employment history, family matters, infidelity, child custody, salaries, accident injuries, and financial amounts, but does not include a privacy warning or data-minimization guidance. This increases the risk that users overshare highly sensitive personal data, creating unnecessary privacy exposure and potential downstream handling risks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.