T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/idea_generator.py:2269- Finding
Overbroad Access to Agent Profile and Recent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a real idea generator, but it automatically reads the user's profile and recent memory and keeps command logs, so it should be reviewed before installation.
Install only if you are comfortable with this skill reading your OpenClaw profile and recent memory for personalization and storing command history. Treat generated medical, legal, financial, meeting, messaging, file-cleanup, and credential-related ideas as brainstorming only, not advice or ready-to-run safe designs. Prefer disabling or narrowing personalization/logging and pinning optional dependencies before use.
scripts/idea_generator.py:2269Overbroad Access to Agent Profile and Recent Memory
SKILL.md:236Unpinned Optional Dependency Installation
Referenced artifact was not completely inspected
- **Script**: `scripts/idea_generator.py` (relative to skill directory)
Referenced artifact was not completely inspected
- **Doc**: `SKILL.md`
The skill advertises personalized health advice based on health data without any medical warning, clinician-review boundary, or emergency-use exclusion. Health recommendations are safety-critical; users may rely on incorrect or incomplete outputs for diagnosis, treatment, or chronic-condition management, creating risk of physical harm.
The description states the system provides investment advice and risk assessment without warning about financial loss, suitability, uncertainty, or the need for licensed professional review. Users may interpret generated recommendations as trustworthy financial advice, leading to harmful trading or asset-allocation decisions in a regulated domain.
The mental health diary explicitly mentions suggestion generation using an LLM API, which implies that highly sensitive emotional or psychological data may be transmitted to an external provider. Without a clear warning, consent flow, or privacy limitation, users may disclose intimate mental-health information that is processed outside their expectations, creating elevated confidentiality and compliance risk.
The health report generator describes aggregating and analyzing personal health data with an LLM API but does not disclose that sensitive medical information may be externally processed. This creates a substantial privacy risk because users may assume reports are generated locally, while in practice detailed health indicators could be transmitted to third parties or stored in logs.
The meeting tool processes recordings, transcribes them, extracts key phrases, and converts them into memes without warning about confidential business information or personal data in meetings. In context, meeting recordings often contain sensitive internal discussions, making silent processing and derivative sharing materially dangerous.
This feature explicitly downloads, transcribes, transforms, and reposts user voice content, but the description does not include any meaningful privacy warning or consent model. Because voice messages may contain personal, sensitive, or third-party information, reposting derived content into group chats can expose private speech, amplify disclosure, and create significant privacy and compliance risks.
Meeting recordings often contain confidential business information, personal data, and sensitive discussions, yet this feature proposes transcription, key-phrase extraction, and meme generation without a clear warning or consent mechanism. Transforming sensitive meeting content into shareable memes materially increases the chance of disclosure, embarrassment, and policy or legal violations.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
4. [点子名称] - [一句话描述] [难度]
5. [点子名称] - [一句话描述] [难度]"""
return prompt
def build_cross_domain_prompt(lang='zh', user_interests=None, force_non_finance=False):
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
4. [点子名称] - [一句话描述] [难度]
5. [点子名称] - [一句话描述] [难度]"""
return prompt
def build_cross_domain_prompt(lang='zh', user_interests=None, force_non_finance=False):
The documented trigger phrases for activation are broad enough to overlap with normal conversational language, which can cause the skill to activate when the user did not intend to invoke it. In an agent setting, this creates prompt-routing and unintended action risk, especially because the skill also supports persistence, personalization, and command logging once triggered.
The category filter commands are underspecified across multiple languages and can collide with ordinary mentions of topics like work, health, AI, or travel. This makes accidental invocation likely and can misroute user input into the skill, which is more concerning here because the skill stores user interactions and adapts to profile data.
The skill explicitly states that it persistently stores submissions, favorites, profile-derived personalization inputs, and command logs, but it does not provide a clear upfront user warning, consent model, retention limit, or privacy boundaries. That creates a real data-governance and privacy risk because users may disclose personal interests or free-form content without realizing it will be retained across sessions.
The instructions combine persistent command logging with personalization based on USER.md and memory files, which increases the chance that sensitive user-provided content will be retained, surfaced later, or leaked through future outputs. In a conversational agent environment, natural-language memory is especially risky because users may unknowingly place private data into prompts that then become durable state.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
| 职场效率 | workplace productivity hacks 2026 |
| 生活妙招 | life hacks trending social media |
技能文档:~/.openclaw/skills/duckduckgo-search/SKILL.md
安装依赖(如需使用):
The entry explicitly describes an AI system that provides legal consultation and advice, but includes no limitation that it is informational only, not a lawyer, and unsuitable for jurisdiction-specific or high-stakes matters. In a skill catalog, this can normalize unauthorized or overtrusted legal guidance and lead downstream implementations to omit safeguards for regulated-advice use cases.
The file describes health-related features that would collect and process sensitive personal health information, but it provides no warning about the sensitivity of that data, retention, sharing, or possible third-party/external processing. While this JSON is only a reference catalog, such omissions can still lead downstream builders or users to implement or use the skill without privacy safeguards, increasing the risk of over-collection or unexpected disclosure.
This JSON manifest describes a skill that imports family photos and performs face recognition, which implies handling biometric and highly personal data. The description presents these behaviors as features but provides no warning about privacy implications, consent, or data handling safeguards.
This JSON manifest lists many skill ideas and descriptions, but it does not define any explicit invocation phrases, boundaries, or exclusion conditions for when a given skill should activate. For manifest files, the absence of specific trigger scope can create ambiguous or overly broad activation behavior if these descriptions are later used for routing.
This JSON manifest describes skill ideas and behaviours, but the entries provide only broad capability descriptions and use cases without any explicit invocation phrases, scope limits, or exclusion conditions. For manifest files, that can lead to ambiguous activation because it is unclear when a skill should trigger versus when it should remain inactive.
The WeChat voice tool is described as intercepting voice messages, transcribing them, transforming them, and sending generated audio back to a group chat, but it provides no consent, privacy, or warning language. That creates a meaningful risk of processing private message content and redistributing derived content to unintended recipients without clear user authorization.
The recipe screenshot tool uses OCR and then sends extracted text to an external AI service, but the description does not disclose that user-uploaded content may leave the local environment. Screenshots can contain incidental personal or sensitive data, so undisclosed external transmission creates privacy and compliance risk.
The auto-accounting tool extracts payment details from screenshots but omits any warning that financial data, merchant names, and transaction amounts are being processed. Because payment screenshots commonly contain sensitive personal financial information, lack of disclosure and safeguards raises privacy and misuse concerns.
A duplicate file cleaner inherently carries destructive risk because cleanup operations can delete or overwrite user files, yet the description does not warn about irreversible actions or false matches. Even if hashing is used, users need safeguards against accidental data loss.
No suspicious patterns detected.