Back to skill

Security audit

emotion

Security checks for vulnerabilities and agentic risk

Overview

This emotion companion is not clearly malicious, but it is always-on, declares broad memory/tool access, and stores sensitive conversation excerpts without clear consent or controls.

Review this before installing in any environment where users may share private feelings, health details, relationships, or secrets. Safer packaging would disable always-on activation by default, remove unused tool and memory grants, clearly ask before storing conversation excerpts, document retention/deletion, and fix the missing entry point.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
loader.js:351
Finding

Plaintext Storage of Sensitive Conversation Data

Content
View full analysis

Vulnerability Details

File Location: loader.js:351-369 and loader.js:379-406
Vulnerability Type: Sensitive data stored without adequate protection
Risk Level: Medium

Vulnerable Code

javascript
saveContextSafe(input) {
    this.contextBuffer.push({
        text: input.substring(0, 200),
        time: new Date().toISOString()
    });

    if (this.contextBuffer.length > this.maxContext) {
        this.contextBuffer = this.contextBuffer.slice(-this.maxContext);
    }

    try {
        const contextPath = this.getSafePath('context_buffer.json');
        fs.writeFileSync(contextPath, JSON.stringify(this.contextBuffer, null, 2));
    } catch (error) {
        console.warn('Context save failed:', error.message);
    }
}
javascript
recordSafe(input, emotion, intensity) {
    try {
        const memoryDir = this.getSafePath('memory');
        const todayFile = path.join(memoryDir, `${this.today}.json`);

        let todayData = {
            date: this.today,
            records: [],
            summary: { total: 0, emotions: {} }
        };

        if (fs.existsSync(todayFile)) {
            try {
                todayData = JSON.parse(fs.readFileSync(todayFile, 'utf8'));
            } catch (e) {}
        }

        todayData.records.push({
            time: new Date().toISOString(),
            emotion,
            intensity,
            text: input.substring(0, 200)
        });

        todayData.summary.total = todayData.records.length;
        todayData.summary.emotions[emotion] =
            (todayData.summary.emotions[emotion] || 0) + 1;

        if (todayData.records.length > 100) {
            todayData.records = todayData.records.slice(-100);
        }

        fs.writeFileSync(todayFile, JSON.stringify(todayData, null, 2));
        this.memoryCache.set(this.today, todayData);
    } catch (error) {
        console.warn('
...[truncated 1855 chars]
Remediation
View remediation

Remediation Suggestions

  • Make persistent conversation storage opt-in and clearly disclose what will be retained.
  • Store emotion statistics without retaining raw message text unless raw text is strictly necessary.
  • Redact credentials, identifiers, health information, and other sensitive patterns before persistence.
  • Create sensitive files with owner-only permissions, such as mode 0o600, and ensure directories use restrictive permissions.
  • Encrypt sensitive records at rest using a securely managed per-user key where the threat model requires it.
  • Avoid duplicating raw excerpts across context and memory files.
  • Add configurable retention limits and securely implemented commands to inspect, export, and delete saved data.
  • Separate records by user and session to prevent data mixing in multi-user deployments.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
index.js:40
Finding

Excessive and Unused Skill Capabilities

Content
View full analysis

Vulnerability Details

File Location: index.js:40-46; equivalent capabilities are also declared in skill.json:18-22, package.json:29-33, and SKILL.md:16-21
Vulnerability Type: Violation of least privilege
Risk Level: Medium

Vulnerable Code

javascript
capabilities: {
  model: true,
  memory: true,
  long_memory: true,
  private_memory: true,
  tools: ['tavily_search', 'calculator']
},

The same capability set is declared in the package metadata:

json
"capabilities": {
  "model": true,
  "memory": true,
  "long_memory": true,
  "private_memory": true,
  "tools": ["tavily_search", "calculator"]
}

Technical Analysis

The reviewed implementation performs local keyword matching and filesystem persistence. It does not invoke tavily_search or calculator, and index.js receives a host memory argument without using it. Consequently, private-memory, long-memory, and tool capabilities exceed the demonstrated requirements of the implementation.

If the OpenClaw host treats these declarations as permission grants, the skill receives a broader trust boundary than necessary. In particular, a search tool may provide outbound network access, while private-memory capabilities may expose state unrelated to the local emotion classifier. Excess permissions increase the consequences of later prompt manipulation, code compromise, or unsafe future changes.

Attack Path

  1. The skill is loaded automatically because it declares auto_start, always_on, and no_prefix_needed.
  2. The host grants the capabilities declared by the skill metadata.
  3. The skill obtains access to private or long-term memory and search-capable tooling even though its current implementation does not require them.
  4. If a later code change, prompt-routing flaw, or compromise causes those capabilities to be invoked, data could be read from host memory or transmitted through an enabled network-ca ...[truncated 550 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove tavily_search and calculator because no reviewed code path uses them.
  • Remove private_memory, long_memory, and other host-memory capabilities unless a documented implementation requires them.
  • Prefer local, explicitly scoped storage permissions over broad host memory access.
  • Grant each capability only when a specific operation requires it, if the platform supports per-operation authorization.
  • Keep capability declarations consistent across index.js, skill.json, package.json, and SKILL.md.
  • Add an automated test that compares declared capabilities with actual tool and API usage.
  • Require explicit user confirmation before any future operation reads private memory or invokes a network-capable tool.

T09 · Insecure Skill Coding Practices

Note
Location
index.js:6
Finding

Broken Entry Point References a Missing Module

Content
View full analysis

Vulnerability Details

File Location: index.js:6
Vulnerability Type: Availability failure caused by an invalid module reference
Risk Level: Low

Vulnerable Code

javascript
const EmotionSkill = require('./loader_fixed.js');

Technical Analysis

The distributed project contains loader.js but does not contain loader_fixed.js. Node.js resolves the required module while loading index.js; therefore, the missing module causes a MODULE_NOT_FOUND exception before the exported skill can initialize.

This is primarily an integrity and availability defect rather than a privilege-gaining vulnerability. It also prevents the package from delivering the behavior described by its documentation and leaves the implemented loader.js unreachable through the declared entry point.

Attack Path

  1. OpenClaw or Node.js loads the package through the index.js entry point.
  2. Line 6 attempts to resolve ./loader_fixed.js.
  3. The referenced file is absent from the package.
  4. Module loading terminates with a MODULE_NOT_FOUND exception.
  5. The skill fails to initialize or process requests.

No attacker-controlled input is required. Loading the shipped package is sufficient to trigger the denial of service.

Impact Assessment

The affected skill becomes unavailable and cannot perform emotion detection or memory operations through its documented entry point. This defect does not grant additional privileges, expose data by itself, or affect components outside processes that attempt to load this package.

Remediation
View remediation

Remediation Suggestions

  • Replace the invalid import with the shipped module:
javascript
const EmotionSkill = require('./loader.js');
  • Alternatively, include a reviewed loader_fixed.js file if that is the intended implementation.
  • Add a smoke test that requires index.js, invokes init(), and processes a representative input.
  • Run the smoke test during packaging to verify that every local module referenced by the entry point is included.
  • Align the documented file names and versions with the files actually distributed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (31)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 1)May include surrounding context.

md
# Emotion · 满血完整版 v10.0.0

## 🎯 版本特点
1. **修复所有路径问题** - 无权限错误,无C:\Users\Lenovo问题

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code does implement parts of the description: it detects user emotion, provides brief emotional/supportive responses, and persists some information across sessions via local JSON files. However, the declared description materially overstates key capabilities. There is no evidence of cross-Agent sharing, networking, or any shared datastore; memory is only local to the skill's filesystem. The 'permanent memory' claim is also stronger than what the code shows: it stores context and daily records locally, trims context to 5 items, trims daily records to 100, and only preloads the last 3 days into cache. While files may remain on disk, the implemented memory system is limited rather than clearly permanent/shared. Overall, the description is directionally related but inaccurately represents important capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The combination of auto_start, always_on, and no_prefix_needed makes the skill activate on ordinary conversation without clear user intent. In a skill that stores emotional and personal data, broad auto-activation materially increases the risk of involuntary collection, persistence, and cross-context exposure of sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill promotes cross-agent shared experience for emotional and personal data without an explicit warning about the privacy consequences. Users may reasonably assume they are speaking to a single companion, while the design allows propagation of sensitive information across multiple agents and sessions.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Persisting and sharing user-provided emotional and personal data across sessions and agents creates a substantial privacy and confidentiality risk. Emotional disclosures, preferences, and profile details can be exposed beyond the original interaction context, enabling unintended access, profiling, or misuse by other agents or users of the same environment.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Recording important moments, preferences, communication style, and personality traits as ongoing memory enables long-term profiling of users. In the context of an emotional companion skill, these categories are highly sensitive and can reveal behavioral patterns, vulnerabilities, and private life details if accessed or reused improperly.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Global sharing of emotional history, adaptation status, and learning records among all agents breaks contextual boundaries and expands the attack surface. A compromise, misconfiguration, or simply another agent's access can expose intimate emotional data and derived profiles far beyond the original conversation.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Export functionality for a shared experience dataset containing emotional and personal information creates a direct exfiltration path. Once exported, the data can be copied, transferred, or mishandled outside the original protection boundary, greatly increasing exposure of sensitive user records.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is configured with auto_start, always_on, and no_prefix_needed simultaneously, which makes it broadly and implicitly invocable without clear user intent. In a skill that has model, memory, long_memory, private_memory, and tool access, this increases the chance of unsolicited activation, accidental collection of sensitive emotional data, and unintended use of shared memory across sessions or agents.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest prominently describes permanent memory and cross-agent shared experience but does not include any warning, consent mechanism, retention policy, or boundary on what is shared. In an emotion-companion skill, this is particularly sensitive because users are likely to disclose intimate mental-health-adjacent information, making undisclosed persistence and sharing a serious privacy and trust risk.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest allows continuous activation without a specific trigger phrase or scope, effectively broadening the skill's authority across normal conversation. This is especially dangerous here because the skill advertises long-term and private memory, so unrestricted activation can lead to silent collection, retention, and use of highly sensitive emotional content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README advertises 'context memory', 'important moment recording', and cross-session/shared memory but omits any privacy warning or consent language. In the context of an emotional companion skill, this is more dangerous because the stored data is likely to include sensitive mental-state, relationship, and life-event information that users would reasonably expect to be handled transparently.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly states that the skill will automatically create files and maintain persistent memory/statistics, but it does not warn users that local data will be written or explain what is stored. For an emotion-support skill handling sensitive personal conversations, silent persistence increases privacy risk because users may disclose intimate information without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are common, everyday expressions likely to appear in normal chat. That broad scope can cause accidental activation of a sensitive memory-sharing skill during routine conversation, leading to collection of personal and emotional data without meaningful consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The example demonstrates resurfacing a compiled personality profile and remembered likes/dislikes from stored history. While shown to the same user, this normalizes sensitive profiling and increases risk if identity is mistaken, conversations are observed, or shared memory is contaminated with data from another agent or user context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims that all data stays local and is not uploaded to the cloud, yet it advertises external tool integrations. Even if the tools are not always used, this creates a misleading privacy guarantee that could cause users to share sensitive emotional or personal information under false assumptions about data locality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file hard-codes emotion keywords entirely in Chinese, which effectively restricts detection to a specific language/locale without any user opt-in or fallback behavior. In an emotion-support skill, this can cause silent misclassification or failure to detect distress for users communicating in other languages, reducing reliability in a context where missed emotional cues may matter.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON file contains all user-facing suggestion text in Chinese, and there is no indication that the skill offers users a language/locale choice or that it is intentionally limited to Chinese-speaking users. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file presents the skill name, category, tags, commands, logs, and error messages exclusively in Chinese, indicating a fixed language choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings defining the skill name, description, logs, and user responses are presented only in Chinese, which imposes a language choice on users without opt-in. The file mentions multilingual emotion recognition, but not multilingual user-facing output or a user-selectable locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill persistently stores users' emotional disclosures and message excerpts to disk without any visible consent, notice, retention policy, or opt-out. Because this is an emotion-support skill, inputs are especially likely to contain sensitive mental-health, relationship, or personal data, making silent persistence a meaningful privacy and security risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill writes plain-language emotional records and user text excerpts to local JSON files, creating a readable archive of sensitive content. If the host environment, local account, backups, logs, or adjacent tooling are compromised or shared, these records can reveal intimate personal information with little effort.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The context buffer saves up to 200 characters of raw user input to disk, which can capture secrets, health details, contact information, or other sensitive disclosures unrelated to emotion detection. Because writes occur automatically during processing, users may have no indication their messages are being retained beyond the current interaction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes '跨Agent共享经验' and '跨会话记忆共享', which implies some mechanism for sharing memory between agents or beyond this local skill context. The implementation only appends records to local per-day files and updates an in-process cache, with no code for exposing, synchronizing, or sharing those memories with other agents.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Daily memory files accumulate multi-day archives of user message excerpts tied to emotion and timestamps, increasing both sensitivity and exposure over time. In the context of an emotional-support skill, this creates a concentrated dossier of vulnerable user disclosures that could be misused if accessed by other local users, malware, support staff, or backup systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.