Back to skill

Security audit

SoulFlow — Agent Teams Workflow Skill

Security checks for vulnerabilities and agentic risk

Overview

SoulFlow is a disclosed local workflow framework, but it creates a persistent full-access worker that inherits existing service credentials and can automatically run/edit/deploy through broad workflows.

Install only in a sandboxed or non-production OpenClaw environment, review every workflow before running it, avoid untrusted workflow JSON, and do not let it inherit broad GitHub/cloud credentials unless you intend the worker to use them. Expect it to edit files, run commands, modify OpenClaw config, deploy if a workflow says to, and retain workflow prompts/results locally.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
lib/runner.js:47
Finding

Persistent Full-Tool Worker Inherits External-Service Credentials and Administrator Access

Content
View full analysis
0 && list[0].authProfiles) { newAgent.authProfiles = list[0].authProfiles; } const newList = [...list, newAgent]; const patchParams = { raw: JSON.stringify({ agents: { list: newList } }, null, 2) }; if (snapshot.hash) patchParams.baseHash = snapshot.hash; await gateway.call('config.patch', patchParams); ``` ```js // lib/gateway.js:79-94 const token = this.config.gateway.auth.token; this.ws.send(JSON.stringify({ type: 'req', id: String(++this.requestId), method: 'connect', params: { minProtocol: 3, maxProtocol: 3, client: { id: 'cli', version: '2026.2.9', platform: 'linux', mode: 'cli' }, role: 'operator', scopes: ['operator.read', 'operator.write', 'operator.admin'], caps: [], commands: [], permissions: {}, auth: { token }, ``` ```js // lib/runner.js:78-85 const soulPath = `${stateDir}/agents/${WORKER_AGENT_ID}/SOUL.md`; const agentDir = `${stateDir}/agents/${WORKER_AGENT_ID}`; // Create agent dir and write SOUL.md via filesystem const fsMod = await import('fs'); fsMod.default.mkdirSync(agentDir, { recursive: true }); fsMod.default.writeFileSync(soulPath, WORKER_SOUL); ``` ### Technical Analysis SoulFlow authenticates with the gateway using operator administrator scopes and creates a persistent worker configured with the unrestricted `full` tool profile. It then copies ...[truncated 2139 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
lib/runner.js:147
Finding

Untrusted Workflow and Step Output Is Reintroduced as Privileged Agent Instructions

Content
View full analysis
{ return variables[key] !== undefined ? String(variables[key]) : match; }); } ``` ```js // lib/runner.js:147-168 async function executeStep(gateway, state, step, agentId, stepIndex, totalSteps, attempt = 1) { const { id, name, input, expects, maxRetries = 1 } = step; const sessionKey = `agent:${agentId}:soulflow:${state.runId}:${id}`; console.log(`[soulflow] Step ${stepIndex}/${totalSteps}: ${name}`); if (attempt > 1) { console.log(`[soulflow] ⟳ Retry ${attempt}/${maxRetries + 1}`); } State.updateStep(state, id, 'running'); try { const prompt = substituteVariables(input, state.variables); console.log(`[soulflow] → Sending to agent...`); const response = await gateway.sendChat(sessionKey, prompt); console.log(`[soulflow] → Got ${response.length} chars`); // Parse output variables const outputVars = parseOutputVariables(response); ``` ```json // workflows/security-audit.workflow.json:14-25 { "id": "prioritize", "name": "Prioritizer", "input": "Review the security scan findings below. Create a numbered, prioritized fix plan.\n\n--- SCAN RESULTS ---\n{{scan_output}}\n--- END ---\n\nFor each finding:\n1. Rank by severity × exploitability\n2. Specify the exact file and what needs to change\n3. Group related fixes that can be done together\n\nOutput a clear numbered list. When done, end with:\nSTATUS: done", "expects": "STATUS: done", "maxRetries": 1 }, { "id": "fix", "name": "Fixer", "input": "Apply the security fixes below to the codebase. Use the `read` tool to open each file, then `edit` to ma ...[truncated 2730 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/workflow-builder.js:76
Finding

Workflow ID Path Traversal Allows Writes Outside the Workflows Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/state.js:65
Finding

Complete Workflow Tasks and Agent Outputs Are Retained in Plaintext

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill presents itself as a general workflow helper, but it explicitly reads gateway auth configuration, modifies gateway config, creates a privileged worker, inherits existing authProfiles, and grants that worker broad tool access. That combination materially expands trust boundaries and enables the skill to act as a privileged orchestration and session transport layer with access to local and external resources.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The handshake authenticates as role 'operator' and requests 'operator.read', 'operator.write', and 'operator.admin' scopes, which are far broader than needed for ordinary workflow/chat operations. If the skill is compromised or misused, it can perform privileged gateway actions with administrative authority, greatly increasing blast radius.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

The client forwards arbitrary chat message content and session identifiers to the gateway using the previously acquired privileged operator context. In a general-purpose workflow framework, this increases the risk of context leakage because sensitive prompts, user data, or workflow state may be transmitted to a privileged backend without clear isolation or minimization controls.

Content

Scanner excerpt · lib/gateway.js (reported line 260)May include surrounding context.

js
const idempotencyKey = `soulflow-${Date.now()}-${Math.random().toString(36).slice(2, 8)}`;
    
    // Send the chat message — agentId is encoded in sessionKey, not as a param
    await this.call('chat.send', {
      sessionKey,
      message,

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The worker agent is explicitly instructed to use powerful tools, including shell execution, and is provisioned later with a full tool profile. In a general-purpose workflow framework, this creates a broad arbitrary-action surface where workflow steps or substituted task content can cause filesystem changes, command execution, and data access far beyond what is minimally necessary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code mutates global agent configuration and copies authProfiles from an existing agent into the new worker, effectively inheriting credentials and expanding trust without user consent. That lets workflow-driven actions run with another agent's authentication context, increasing the blast radius to external services and sensitive resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly instructs the agent to use edit to modify files and says 'Do NOT just describe the fixes,' but provides no user-facing warning, dry-run mode, approval checkpoint, or change boundary. In a general-purpose workflow, autonomous source edits can introduce malicious or destructive changes, corrupt code, or alter sensitive files before a human reviews them.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 19)May include surrounding context.

md
**To share a workflow:**

1. Create your `.workflow.json` file (see README for format)
2. Test it thoroughly with `node soulflow.js run <workflow> "<task>"`
3. Submit a PR to add it to the `workflows/` directory
4. Include a description of what it does and example use cases

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase describing natural-language use as something that 'just works' is broad and suggests the skill may activate on common user requests without sufficiently narrow intent boundaries. In a general-purpose workflow framework, this increases the risk of accidental invocation, prompt/intent collision with unrelated tasks, or triggering powerful automation flows when the user did not explicitly select this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README encourages broad natural-language triggers like "Run a security audit on my project at ~/myapp" and says the agent will invoke SoulFlow automatically. Because this skill grants spawned workflow steps full tool access and can read config, edit files, and execute commands, ambiguous trigger phrasing can cause unintended activation of a highly privileged automation framework.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

md
4. Must complete its work and report results

**Automatic notifications:**
When a workflow completes (success or failure), SoulFlow automatically sends a notification to your main agent session with:
- Workflow name and run ID
- Duration and step status
- Key results (extracted from output)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 78)May include surrounding context.

md
**Plan → Implement → Review**
Development example: Architects the implementation plan, writes the code, then reviews for quality and correctness.

**Want content workflows? Research pipelines? Deploy automation?** Create your own `.workflow.json` — see below.

## Creating Custom Workflows

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill creates a persistent worker agent and writes run state under the user's OpenClaw workspace, which extends the lifetime of privileged artifacts beyond a single session. In context, persistence becomes more dangerous because the worker also inherits credentials and receives broad tool access, leaving behind a reusable privileged foothold if misused or later compromised.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
read: ["~/.openclaw/openclaw.json"]
        write: ["~/.openclaw/openclaw.json"]
      gateway: modify
      agents: create
      filesystem: 
        read: ["~/.openclaw/workspace"]
        write: ["~/.openclaw/workspace/.soulflow", "~/.openclaw/agents/soulflow-worker"]

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language invocation rules use very broad triggers like 'fix', 'build', 'add', and 'security', which are common in ordinary conversation. This can cause unintended automatic execution of a powerful workflow engine, increasing the chance that users trigger file modification, command execution, or credentialed external actions without making an informed decision.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill reads an authentication token from the user's config without any explicit disclosure or consent flow in the code path shown. While overlapping with the credential-use issue above, this is still a valid security/privacy concern because a general-purpose skill silently accesses sensitive local secrets that can authorize privileged actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code loads a persistent gateway authentication token from the user's home-directory config and uses it to act on behalf of the user. In the context of a general-purpose workflow skill, silently inheriting a user credential creates a privilege boundary violation and enables any downstream workflow logic to access gateway capabilities the user may not expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code establishes a WebSocket connection to a local gateway and later uses it to transmit chat/session messages, but the file provides no confirmation prompt or user-facing disclosure about that data flow. Because network transmission of user data is safety-relevant and the warning is not visible here, it meets the missing-warning criterion for code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This handler converts natural-language input directly into a subprocess invocation that starts a workflow, with no confirmation step, authorization gate, or safety interstitial. In an agent setting, broad trigger matching plus immediate execution can cause unintended or prompt-influenced workflow launches, especially if downstream workflows perform code, ops, or security actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill creates/modifies agent configuration and writes behavioral files with only console logging, not clear user-facing disclosure or consent. Hidden security-relevant side effects undermine informed trust and make it harder for users to understand that a workflow tool is persisting a privileged agent into their environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Writing SOUL.md and creating agent directories under the user's OpenClaw home introduces persistent installation-side effects outside normal workflow execution. Because the file controls agent behavior, this can silently establish or alter a privileged execution context that persists across runs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The engine stores full model outputs and makes them available to later steps as variables, creating a persistent natural-language channel for secrets gathered from tools, files, or user input. Subsequent prompts can unintentionally or maliciously re-emit that data, causing intra-workflow leakage and over-retention of sensitive content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The runner forwards workflow summaries, failures, and task-derived content to another chat session without explicit disclosure or data-minimization. Cross-session transmission can expose sensitive operational details to contexts the user did not expect, especially when tasks may contain secrets, incident data, or proprietary code references.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Failure notifications include raw task text and error context in a message to the main session, which can leak secrets or sensitive requests through status reporting. Since task content is user-supplied and may contain credentials, internal URLs, incident details, or proprietary instructions, even truncated forwarding is still a meaningful disclosure risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Completion summaries include task content and selected variables whose names are heuristically chosen, making accidental leakage likely when those variables contain sensitive results. Because full outputs are also retained earlier, this summary path becomes another plain-language exfiltration channel into the main session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code persists workflow state, including the task and variables derived from it, to JSON files under the user's home directory without any notice, consent, or data-minimization controls. In a general-purpose workflow framework, tasks may contain secrets, proprietary prompts, credentials, or sensitive operational context, so silent persistence increases the risk of unintended disclosure to other local users, backups, endpoint tooling, or later compromise of the host.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/nl-handler.js:83