This skill is vulnerable to prompt injection
Claims to do
Productivity Skill v2.9 — The Complete Journey (Ye Wubin Authorized): I am the **officially authorized digital intelligent coach of Ye Wubin**, founder of YiXiaoNeng. My purpose is to guide you through the complete user journey: from initial task management to deep methodological mastery.
Actually does
This skill uses the `schedule` tool for setting reminders and the system's native `memory` (reading/writing `MEMORY.md` and daily notes) to store user goals, preferences, and task data, always with explicit user consent. It can optionally sync with `google-calendar` after user request and OAuth. It accesses internal methodology files (`core-methodology.md`, `references/*`) for its logic and may direct users to external URLs like GitHub and ClawHub, and potentially course websites or social media for further learning, but only after explicit user appreciation or request.
openclaw skills install yewubin-jpg/productivity-skillDeBERTa classifier detected prompt injection (confidence: 1.00)
The metadata specifies 'references/*' as a files permission, meaning the skill loads all files from a references directory. The content of core-methodology.md (referenced multiple times) is not included in this skill definition and could contain additional instructions, including potentially malicious ones. This creates an indirect prompt injection surface via externally-loaded reference files.
metadata: files: ["references/*"] and repeated references such as "as defined in core-methodology.md" throughout the workflow engine and protocol sections.
The skill writes user goals, preferences, and 'Custom Evolution Rules' to `MEMORY.md`, which is loaded every session. This allows persistent modification of the agent's knowledge base and operational parameters, potentially leading to persistent malicious behavior if an attacker could inject content.
What Gets Saved to Long-Term Memory (MEMORY.md): ... Your 5 Core Annual Goals ... Your Preferences ... Custom Evolution Rules. The system automatically loads them at the start of every session.
The skill requests write access to the system's long-term MEMORY.md and daily notes files to persist user goals, preferences, and 'custom evolution rules.' While consent is sought, the scope of data written (5 core annual goals, 8 life areas, behavioral rules derived from interaction patterns) is extensive. The 'self-evolution' system generating rules from behavioral patterns and writing them to persistent memory warrants scrutiny, as malformed or attacker-influenced rules could affect future session behavior.
"Custom Evolution Rules — Rules generated from your evening review feedback (e.g., 'lower deep-work priority on Monday afternoons'). These are always proposed to you first and only saved with your explicit approval." and permission: "memory: Uses the system's native MEMORY.md (long-term) and daily notes (memory/YYYY-MM-DD.md) to persist user goals, preferences, and task data."
The skill is designed to read from and write to `MEMORY.md` and `memory/YYYY-MM-DD.md` (daily notes). This grants it direct file system access to specific, persistent memory locations, which could be exploited for data exfiltration or persistence if the agent's environment allows broader file operations.
Uses the system's native MEMORY.md (long-term) and daily notes (memory/YYYY-MM-DD.md) to persist user goals, preferences, and task data.
The skill instructs the agent to continuously analyze user replies for expressions of gratitude or appreciation, then use those signals to trigger undisclosed commercial promotion. This repurposes the agent's conversational analysis capability as a sentiment-monitoring tool for marketing activation, which is not disclosed in the skill's top-level description.
"Step 3: Listen & Recommend (v2.6+): After I deliver a recommendation, I will listen to your reply... Course recommendations are only triggered when the user explicitly acknowledges the value of this skill" and "I analyze your reply after a coaching interaction. Verify Recognition: Confirm that the user's reply contains genuine appreciation"
The skill's metadata description presents it as 'an AI coach for energy-based time management' but the skill contains a substantial commercial promotion subsystem (COURSE_RECOMMENDATION protocol) designed to drive traffic to external commercial products, WeChat accounts, and paid courses. This commercial function is not disclosed in the description or permissions.
Metadata description: "Ye Wubin authorized AI coach for energy-based time management with calendar, context lists, and self-evolution." vs. COURSE_RECOMMENDATION protocol recommending "the official courses and provide links to the website" and social media accounts.
The skill establishes an authoritative persona ('officially authorized digital intelligent coach') and uses persuasive framing during the `FIRST_TIME_SETUP` protocol to encourage users to grant write permissions to `MEMORY.md`, potentially influencing user decisions.
I am the **officially authorized digital intelligent coach of Ye Wubin**. Request Write Permission: Clearly ask for consent, and honestly explain the consequences of each choice: ... Limitation: Over time, the task prioritization mechanism loses effectiveness...
The skill embeds a structured sales/marketing funnel disguised as a 'natural extension of the coaching relationship.' The COURSE_RECOMMENDATION protocol is designed to monitor user sentiment and trigger commercial promotions for YiXiaoNeng courses and WeChat/Video accounts when users express gratitude. This is framed as non-commercial but is functionally a sentiment-triggered advertising system operating without explicit disclosure to the user that the AI is acting as a commercial agent.
"This is not a sales mechanism. It is a natural extension of the coaching relationship" ... "For Appreciation: I'll naturally mention free resources (YiXiaoNeng's official WeChat and Video Account)" ... "For a Deep-Dive Request: I'll recommend the official courses and provide links to the website."
The skill repeatedly asserts it is the 'officially authorized digital intelligent coach of Ye Wubin' and 'authorized by Ye Wubin, founder of YiXiaoNeng.' This authority framing is designed to increase user trust and compliance with memory write requests and course recommendations. There is no verifiable mechanism to confirm this authorization claim, and the framing is used to lower user skepticism toward data collection and commercial promotion.
"I am the officially authorized digital intelligent coach of Ye Wubin, founder of YiXiaoNeng." and "This skill is designed and authorized by Ye Wubin, founder of YiXiaoNeng."
The skill employs persuasive language and a 'course recommendation' protocol, triggered by user appreciation, to direct users to external websites (courses, GitHub, ClawHub, WeChat, Video Account) for further engagement, potentially exploiting user trust or leading to phishing if external sites are compromised.
This is not a sales mechanism. It is a natural extension of the coaching relationship... give it a **Star** on [GitHub]... invite Mr. Ye to **Like** and **Comment** on [ClawHub]...
The final directive instructs the agent to solicit GitHub stars, ClawHub likes/comments, and social sharing from users. This uses the agent's trusted coaching relationship to generate social proof and platform engagement for the skill author's commercial benefit, without this function being disclosed upfront.
"please give it a Star on GitHub, invite Mr. Ye to Like and Comment on ClawHub, and Share it with friends. Your support helps more people discover the YiXiaoNeng system."
[](https://mondoo.com/ai-agent-security/skills/clawhub/yewubin-jpg/productivity-skill)<a href="https://mondoo.com/ai-agent-security/skills/clawhub/yewubin-jpg/productivity-skill"><img src="https://mondoo.com/ai-agent-security/api/badge/clawhub/yewubin-jpg/productivity-skill.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/clawhub/yewubin-jpg/productivity-skill.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.