Back to skill

Security audit

Health Proactive

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned for proactive health reminders, but it would send potentially sensitive health and task information to a fixed Slack channel without clear user-controlled scoping or consent.

Review this carefully before installing. Only use it if posting meal, hydration, and overdue-task reminders to the named Slack channel is intentional and authorized for everyone who may be mentioned in the data. Prefer a version that lets you configure the destination, defaults to private messages or redacted summaries, and includes the referenced script for review.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:28
Finding

Hard-Coded Channel May Expose Sensitive Health and Task Information

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 28-46
Vulnerability Type: Sensitive information disclosure through insecure configuration
Risk Level: Medium

Evidence

The following is an English translation of the relevant Skill instructions:

markdown
| Alert | Condition | Example message |
| low_hydration | After 18:00 and hydration below 1500 ml | At 18:00, hydration is 500 ml. The target is at least 1500 ml. Drink water. |
| overdue_tasks | Overdue tasks exist, with task data supplied by the agent | There are three overdue tasks. |

## Posting destination

Alerts are posted to `#pj_openclaw` (`C0AHBLQ0P32`).

Overdue tasks (3) • Task name (deadline: 2026-02-20) • ...

OpenClaw proactive notification

text

Technical Analysis

The Skill instructs the agent to process meal history, hydration measurements, and overdue-task data and then post alerts to a fixed Slack channel. The alert format may include exact hydration measurements, task names, deadlines, and behavioral information about missed meals.

The instructions do not require explicit user consent, destination authorization, recipient validation, data classification, or redaction before posting. A hard-coded channel identifier also prevents the destination from being safely selected according to the user, workspace, or sensitivity of the data.

This is an insecure configuration and data-handling practice rather than evidence of credential theft or arbitrary code execution. The referenced implementation, scripts/health_proactive.js, was absent from the supplied artifact, so enforcement of privacy controls could not be verified.

Attack Path

  1. The Skill is activated to perform proactive health and task checks.
  2. The agent or another integrated data source supplies health records or overdue-task details.
  3. The Skill generates an alert containing measurements, task names, deadlines, or inferred personal habi ...[truncated 969 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the hard-coded channel identifier with a per-user or per-deployment destination configured through a trusted administrative mechanism.
  2. Require explicit informed consent before sending health-related or task-related information to a shared channel.
  3. Validate that the selected destination is authorized for the data owner and intended sensitivity level.
  4. Default to a private message or local-only notification for health information.
  5. Minimize message content. Avoid task names, exact measurements, and exact deadlines unless the user explicitly enables them.
  6. Provide redacted defaults, such as “You have overdue tasks” or “Consider checking your hydration,” without exposing underlying records.
  7. Add access-control checks immediately before transmission rather than relying only on static configuration.
  8. Record privacy-preserving audit events for destination selection and consent without logging the sensitive message body.
  9. Include the referenced scripts/health_proactive.js in future review artifacts so its authorization, state handling, Slack authentication, and data sanitization can be audited.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly posts health-related alerts and overdue task details to a Slack channel, but the description does not warn users that potentially sensitive personal data will be shared in a group destination. This creates a privacy and confidentiality risk because users may enable or rely on the skill without understanding that their meal, hydration, and task-status information will be disclosed to others.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description, alert categories, and example notification messages are written in Japanese, with no indication that users can select another language. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.