Back to skill

Security audit

每日日报生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill generates daily reports from local OpenClaw task memory and can export files, with no evidence of hidden network access, persistence, or destructive behavior.

Install this only if you are comfortable with it reading OpenClaw daily memory files and including matching task/list items in generated reports. Review reports before sharing or exporting them, especially DOCX files saved to the Desktop, because local memory may contain confidential work details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
scripts/generate_report.py:25
Finding

Unredacted Agent Memory Content May Be Disclosed Through Generated Reports

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The description omits meaningful resource access: the skill pulls content from local workspace files like memory/YYYY-MM-DD.md and PROJECTS.md, which may contain sensitive work data. Users may invoke a seemingly simple 'daily report' skill without realizing it will automatically inspect local files, creating a risk of unintended data exposure in generated reports or exports.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description omits meaningful resource access: the skill pulls content from local workspace files like memory/YYYY-MM-DD.md and PROJECTS.md, which may contain sensitive work data. Users may invoke a seemingly simple 'daily report' skill without realizing it will automatically inspect local files, creating a risk of unintended data exposure in generated reports or exports.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises behavior that reads from local memory files and can export reports, but it does not declare any explicit tool scope or permissions. That creates an authorization transparency gap: users and the hosting system may not understand that local files can be read and written when the skill is invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation phrases are broad enough that ordinary requests like '帮我写个日报' or '今天的日报' may trigger the skill automatically. Because the skill reads local memory/task files and may generate exports, accidental activation can cause unreviewed access to local data and unintended disclosure in the output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description highlights convenience features but does not warn that it automatically reads local memory/task files and can export reports to the desktop. This weakens informed consent and increases the chance that sensitive project information is gathered or written to a shared location without the user's awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example trigger phrase is generic and likely to overlap with common conversational requests. In this skill's context, that matters because a casual request can kick off local file access and report generation without the user clearly opting into those side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration sets "language": "zh-CN" and the documentation is written as if Chinese output is the default behavior, but the file does not present this as an optional user-selected setting. This can violate language/locale policy when a skill forces a specific language without explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema hard-codes a default locale of "zh-CN" in the language setting, which can force a specific language unless the user explicitly overrides it. The policy allows locale constraints only when users are given an opt-in choice or the restriction is clearly justified, neither of which is expressed here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow explicitly says the agent will automatically read memory files to generate a report, but provides no notice, consent step, or scoping guidance about what memory data may be accessed. Because memory may contain sensitive personal or work information, this pattern can lead to over-collection and unintended disclosure in the generated report.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This example describes saving the generated report directly to the Desktop without warning that a local file will be created in a potentially visible location. If the report contains sensitive work summaries, this can expose data to other local users, backup/sync services, or accidental sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to generate a Word document on the Desktop without any warning about file creation or local exposure. Word documents are easily forwarded or indexed by local/cloud software, so silently placing a report there can increase the chance of confidential information leaking.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sets the default language to "zh-CN", and the generated output strings throughout the script are hard-coded in Chinese. Because the file is a code file and there is no user-facing option to choose another language or opt into this locale, it violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code includes user-facing documentation and CLI help/output in Chinese, such as the module docstring and multiple argparse/help strings, but does not provide an opt-in language selection or justify a locale-specific restriction. That creates a natural-language locale policy issue because the skill effectively assumes a specific language for users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The packaging logic recursively includes every non-hidden file under the skill directory, with only minimal exclusions for dotfiles and pycache. This can unintentionally bundle sensitive or unrelated local artifacts such as test data, temporary exports, credentials stored in plain files, or large generated documents, causing unintended disclosure when the archive is shared or published.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

All user prompts and assistant responses in the workflow documentation are presented exclusively in Chinese, with no indication that users may choose another language. This may amount to a language-policy issue if the skill is expected to support broader audiences unless the Chinese-only scope is explicitly documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.