Back to skill

Security audit

Self-Improving Plus

Security checks for vulnerabilities and agentic risk

Overview

This skill openly implements self-improvement logging, but it also encourages persistent agent-instruction changes and external skill publishing without enough review or redaction controls.

Review this skill carefully before installing. Use it only if you are comfortable with persistent learning files and generated skills, and require manual review, redaction of sensitive data, and explicit approval before anything is promoted to agent instruction files or published externally.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:24
Finding

Untrusted conversation content can be promoted into persistent Agent instructions

Content
View full analysis
/` 3. **Write SKILL.md**: Use standard skill format with YAML frontmatter 4. **Update learning**: Set status to `promoted_to_skill`, add `Skill-Path` 5. **Publish to ClawHub**: Share with community ``` `SKILL.md:129-139`: ```markdown Review `.learnings/` at natural breakpoints: - Before starting a new major task - After completing a feature - When working in an area with past learnings - Weekly during active development ### Review Actions - Resolve fixed items - Promote applicable learnings - Link related entries - Escalate recurring issues - Extract recurring patterns as skills ``` `SKILL.md:151`: ```markdown 7. **Promote aggressively** - if in doubt, add to CLAUDE.md or .github/copilot-instructions.md ``` ### Technical Analysis The Skill instructs the Agent to record user corrections, error output, and other conversation-derived material in persistent `.learnings/` files. It then directs the Agent to promote those records into reusable Skills and persistent Agent instruction files such as `CLAUDE.md` and `.github/copilot-instructions.md`. Conversation content is an untrusted input bo ...[truncated 2715 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The skill contains an explicit self-modification workflow: creating new skill directories, writing SKILL.md files, and promoting learned behavior into reusable agent instructions. In this context, that is dangerous because it enables autonomous persistence and propagation of new behavior without strong review boundaries, potentially amplifying mistakes, insecure patterns, or maliciously influenced instructions across future runs.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
1. **Identify candidate**: Learning meets extraction criteria
2. **Create skill directory**: `skills/<skill-name>/`
3. **Write SKILL.md**: Use standard skill format with YAML frontmatter
4. **Update learning**: Set status to `promoted_to_skill`, add `Skill-Path`
5. **Publish to ClawHub**: Share with community

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill tells the agent to log user corrections and operational learnings but provides no warning about excluding secrets, personal data, or confidential user content. Because corrections and operational context often contain copied prompts, snippets, credentials, or business logic, this creates a realistic risk of storing sensitive information in persistent files.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quick-reference workflow normalizes persistent logging of user corrections and related context into local markdown files. In the context of an agent skill, that makes retention of conversation-derived content a default behavior, increasing the chance that sensitive user inputs or internal operational details are stored indefinitely and later committed or shared.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The learning-entry template explicitly requests 'Full context' and metadata sourced from conversation, error, and user feedback. That structure strongly encourages copying large amounts of raw interaction content into files, which is dangerous because the context may include secrets, sensitive business logic, or other data unrelated to the long-term learning objective.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The error-entry template directs the agent to save raw error output plus inputs and parameters, which often exposes sensitive data in plain text. This is especially risky because logs are persistent, easy to commit accidentally, and may later be used as source material for generated skills or external sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The error template instructs recording inputs, parameters, and environment details without any safety constraint. Those fields commonly contain API keys, file paths, hostnames, customer data, stack traces, or command-line secrets, so this guidance can persist sensitive data directly into repository files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs publishing extracted skills to an external community service ('ClawHub'), which introduces an outbound data-sharing capability not necessary for local self-improvement. If learnings or generated skills contain proprietary code, internal practices, or sensitive operational details, this can cause unintended data exfiltration beyond the repository boundary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The recommendation to 'add to CLAUDE.md or .github/copilot-instructions.md' encourages modification of project-wide instruction files outside the skill's stated purpose of learning logs and skill extraction. This broadens the skill into persistent instruction tampering, which can alter future agent behavior across unrelated tasks and create an unsafe self-propagation channel.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.