Back to skill

Security audit

Amazing Idea Generator

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real idea generator, but it automatically reads the user's profile and recent memory and keeps command logs, so it should be reviewed before installation.

Install only if you are comfortable with this skill reading your OpenClaw profile and recent memory for personalization and storing command history. Treat generated medical, legal, financial, meeting, messaging, file-cleanup, and credential-related ideas as brainstorming only, not advice or ready-to-run safe designs. Prefer disabling or narrowing personalization/logging and pinning optional dependencies before use.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/idea_generator.py:2269
Finding

Overbroad Access to Agent Profile and Recent Memory

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:236
Finding

Unpinned Optional Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (55)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 320)May include surrounding context.

md
- **Script**: `scripts/idea_generator.py` (relative to skill directory)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
- **Doc**: `SKILL.md`

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises personalized health advice based on health data without any medical warning, clinician-review boundary, or emergency-use exclusion. Health recommendations are safety-critical; users may rely on incorrect or incomplete outputs for diagnosis, treatment, or chronic-condition management, creating risk of physical harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description states the system provides investment advice and risk assessment without warning about financial loss, suitability, uncertainty, or the need for licensed professional review. Users may interpret generated recommendations as trustworthy financial advice, leading to harmful trading or asset-allocation decisions in a regulated domain.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The mental health diary explicitly mentions suggestion generation using an LLM API, which implies that highly sensitive emotional or psychological data may be transmitted to an external provider. Without a clear warning, consent flow, or privacy limitation, users may disclose intimate mental-health information that is processed outside their expectations, creating elevated confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The health report generator describes aggregating and analyzing personal health data with an LLM API but does not disclose that sensitive medical information may be externally processed. This creates a substantial privacy risk because users may assume reports are generated locally, while in practice detailed health indicators could be transmitted to third parties or stored in logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The meeting tool processes recordings, transcribes them, extracts key phrases, and converts them into memes without warning about confidential business information or personal data in meetings. In context, meeting recordings often contain sensitive internal discussions, making silent processing and derivative sharing materially dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This feature explicitly downloads, transcribes, transforms, and reposts user voice content, but the description does not include any meaningful privacy warning or consent model. Because voice messages may contain personal, sensitive, or third-party information, reposting derived content into group chats can expose private speech, amplify disclosure, and create significant privacy and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Meeting recordings often contain confidential business information, personal data, and sensitive discussions, yet this feature proposes transcription, key-phrase extraction, and meme generation without a clear warning or consent mechanism. Transforming sensitive meeting content into shareable memes materially increases the chance of disclosure, embarrassment, and policy or legal violations.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/idea_generator.py (reported line 1329)May include surrounding context.

python
4. [点子名称] - [一句话描述] [难度]
5. [点子名称] - [一句话描述] [难度]"""
    
    return prompt


def build_cross_domain_prompt(lang='zh', user_interests=None, force_non_finance=False):

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/idea_generator.py (reported line 1521)May include surrounding context.

python
4. [点子名称] - [一句话描述] [难度]
5. [点子名称] - [一句话描述] [难度]"""
    
    return prompt


def build_cross_domain_prompt(lang='zh', user_interests=None, force_non_finance=False):

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented trigger phrases for activation are broad enough to overlap with normal conversational language, which can cause the skill to activate when the user did not intend to invoke it. In an agent setting, this creates prompt-routing and unintended action risk, especially because the skill also supports persistence, personalization, and command logging once triggered.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The category filter commands are underspecified across multiple languages and can collide with ordinary mentions of topics like work, health, AI, or travel. This makes accidental invocation likely and can misroute user input into the skill, which is more concerning here because the skill stores user interactions and adapts to profile data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly states that it persistently stores submissions, favorites, profile-derived personalization inputs, and command logs, but it does not provide a clear upfront user warning, consent model, retention limit, or privacy boundaries. That creates a real data-governance and privacy risk because users may disclose personal interests or free-form content without realizing it will be retained across sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions combine persistent command logging with personalization based on USER.md and memory files, which increases the chance that sensitive user-provided content will be retained, surfaced later, or leaked through future outputs. In a conversational agent environment, natural-language memory is especially risky because users may unknowingly place private data into prompts that then become durable state.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

| 职场效率 | workplace productivity hacks 2026 | | 生活妙招 | life hacks trending social media |

技能文档:~/.openclaw/skills/duckduckgo-search/SKILL.md

安装依赖(如需使用):

bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entry explicitly describes an AI system that provides legal consultation and advice, but includes no limitation that it is informational only, not a lawyer, and unsuitable for jurisdiction-specific or high-stakes matters. In a skill catalog, this can normalize unauthorized or overtrusted legal guidance and lead downstream implementations to omit safeguards for regulated-advice use cases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file describes health-related features that would collect and process sensitive personal health information, but it provides no warning about the sensitivity of that data, retention, sharing, or possible third-party/external processing. While this JSON is only a reference catalog, such omissions can still lead downstream builders or users to implement or use the skill without privacy safeguards, increasing the risk of over-collection or unexpected disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON manifest describes a skill that imports family photos and performs face recognition, which implies handling biometric and highly personal data. The description presents these behaviors as features but provides no warning about privacy implications, consent, or data handling safeguards.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON manifest lists many skill ideas and descriptions, but it does not define any explicit invocation phrases, boundaries, or exclusion conditions for when a given skill should activate. For manifest files, the absence of specific trigger scope can create ambiguous or overly broad activation behavior if these descriptions are later used for routing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON manifest describes skill ideas and behaviours, but the entries provide only broad capability descriptions and use cases without any explicit invocation phrases, scope limits, or exclusion conditions. For manifest files, that can lead to ambiguous activation because it is unclear when a skill should trigger versus when it should remain inactive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The WeChat voice tool is described as intercepting voice messages, transcribing them, transforming them, and sending generated audio back to a group chat, but it provides no consent, privacy, or warning language. That creates a meaningful risk of processing private message content and redistributing derived content to unintended recipients without clear user authorization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The recipe screenshot tool uses OCR and then sends extracted text to an external AI service, but the description does not disclose that user-uploaded content may leave the local environment. Screenshots can contain incidental personal or sensitive data, so undisclosed external transmission creates privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The auto-accounting tool extracts payment details from screenshots but omits any warning that financial data, merchant names, and transaction amounts are being processed. Because payment screenshots commonly contain sensitive personal financial information, lack of disclosure and safeguards raises privacy and misuse concerns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A duplicate file cleaner inherently carries destructive risk because cleanup operations can delete or overwrite user files, yet the description does not warn about irreversible actions or false matches. Even if hashing is used, users need safeguards against accidental data loss.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.