T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
Hard-Coded Channel May Expose Sensitive Health and Task Information
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 28-46
Vulnerability Type: Sensitive information disclosure through insecure configuration
Risk Level: MediumEvidence
The following is an English translation of the relevant Skill instructions:
markdown | Alert | Condition | Example message | | low_hydration | After 18:00 and hydration below 1500 ml | At 18:00, hydration is 500 ml. The target is at least 1500 ml. Drink water. | | overdue_tasks | Overdue tasks exist, with task data supplied by the agent | There are three overdue tasks. | ## Posting destination Alerts are posted to `#pj_openclaw` (`C0AHBLQ0P32`).Overdue tasks (3) • Task name (deadline: 2026-02-20) • ...
OpenClaw proactive notification
text Technical Analysis
The Skill instructs the agent to process meal history, hydration measurements, and overdue-task data and then post alerts to a fixed Slack channel. The alert format may include exact hydration measurements, task names, deadlines, and behavioral information about missed meals.
The instructions do not require explicit user consent, destination authorization, recipient validation, data classification, or redaction before posting. A hard-coded channel identifier also prevents the destination from being safely selected according to the user, workspace, or sensitivity of the data.
This is an insecure configuration and data-handling practice rather than evidence of credential theft or arbitrary code execution. The referenced implementation,
scripts/health_proactive.js, was absent from the supplied artifact, so enforcement of privacy controls could not be verified.Attack Path
- The Skill is activated to perform proactive health and task checks.
- The agent or another integrated data source supplies health records or overdue-task details.
- The Skill generates an alert containing measurements, task names, deadlines, or inferred personal habi ...[truncated 969 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the hard-coded channel identifier with a per-user or per-deployment destination configured through a trusted administrative mechanism.
- Require explicit informed consent before sending health-related or task-related information to a shared channel.
- Validate that the selected destination is authorized for the data owner and intended sensitivity level.
- Default to a private message or local-only notification for health information.
- Minimize message content. Avoid task names, exact measurements, and exact deadlines unless the user explicitly enables them.
- Provide redacted defaults, such as “You have overdue tasks” or “Consider checking your hydration,” without exposing underlying records.
- Add access-control checks immediately before transmission rather than relying only on static configuration.
- Record privacy-preserving audit events for destination selection and consent without logging the sensitive message body.
- Include the referenced
scripts/health_proactive.jsin future review artifacts so its authorization, state handling, Slack authentication, and data sanitization can be audited.
