Back to skill

Security audit

test1123123

Security checks for vulnerabilities and agentic risk

Overview

The skill is not deceptive or destructive, but it encourages broad persistent agent memory and optional hooks that can affect future sessions without enough review controls.

Review this skill before installing. Keep learning logs project-local where possible, do not enable global hooks unless you really want every future prompt to receive reminders, and require manual diff review before anything is promoted into AGENTS.md, CLAUDE.md, SOUL.md, TOOLS.md, or copilot instructions. Never store secrets, raw transcripts, credentials, or full command output in the learning files, and prefer a pinned version or reviewed local copy.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:282
Finding

Untrusted Conversation Content Can Be Promoted into Persistent Agent Instructions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:52
Finding

Installation Instructions Retrieve Mutable, Unpinned Skill Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/extract-skill.sh:101
Finding

Output Path Validation Can Be Bypassed Through Pre-Existing Symbolic Links

Content
View full analysis
"$SKILL_PATH/SKILL.md" << TEMPLATE --- name: $SKILL_NAME description: "[TODO: Add a concise description of what this skill does and when to use it]" --- # $(echo "$SKILL_NAME" | sed 's/-/ /g' | awk '{for(i=1;i<=NF;i++) $i=toupper(substr($i,1,1)) tolower(substr($i,2))}1') [TODO: Brief introduction explaining the skill's purpose] ## Quick Reference | Situation | Action | |-----------|--------| | [Trigger condition] | [What to do] | ## Usage [TODO: Detailed usage instructions] ## Examples [TODO: Add concrete examples] ## Source Learning This skill was extracted from a learning entry. - Learning ID: [TODO: Add original learning ID] - Original File: .learnings/LEARNINGS.md TEMPLATE ``` ### Technical Analysis The script attempts to confine writes to the current workspace by rejecting absolute paths and literal `..` ...[truncated 2303 chars]
Remediation
View remediation
` redirection. 6. Use no-follow file-opening semantics where the platform supports them. 7. Minimize time-of-check/time-of-use races by performing validation and file creation through directory file descriptors in a safer implementation language. 8. Add tests covering: - A symlinked output directory - Nested symlink components - A destination that resolves outside the workspace - An existing symlink named `SKILL.md` - Replacement of a validated directory with a symlink during execution ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a learning-capture and continuous-improvement skill focused on recording failures, corrections, outdated knowledge, and better approaches. The actual code does something materially different: it is a shell utility for scaffolding a new skill folder and template file from a skill name. While the generated template references extraction from a learning entry, the script itself neither captures learnings nor reviews them; it only creates files for a new skill. This is a primary-purpose mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
94% confidence
Finding

The guide recommends installing persistent hooks in the user-level agent configuration directory, which affects all future sessions rather than a single project. Because these hooks execute commands automatically with the agent's permissions, global placement materially increases blast radius if the script is modified, replaced, or behaves unexpectedly.

Content

Scanner excerpt · references/hooks-setup.md (reported line 48)May include surrounding context.

Option 2: User-Level Configuration

Add to ~/.claude/settings.json for global activation:

json
{

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 181)May include surrounding context.

sessions_send

Send message to another session:

text
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

This skill instructs creation and persistent use of ~/.openclaw/workspace/.learnings, enabling cross-session retention of user interactions, failures, and operational context. Even though it warns against storing secrets, persistent session data in a shared workspace increases the chance of sensitive information, internal paths, or behavioral context being retained longer than intended and later accessed by other sessions or agents.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Phrases such as "Actually, it should be..." and "You're wrong about..." are common conversational feedback patterns and are presented here as automatic logging triggers without clear boundaries. The lack of negative examples or trigger constraints makes it unclear when routine clarification should be logged versus ignored.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The listed feature-request triggers include broad phrases like "Can you also...", "I wish you could...", and "Is there a way to...", which commonly appear in ordinary conversation outside the narrow context of logging a missing capability. Because the file presents these as automatic detection triggers, the activation scope is not sufficiently constrained and may cause unintended invocations.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/examples.md (reported line 301)May include surrounding context.

When the above learning is extracted as a skill, it becomes:

File: skills/docker-m1-fixes/SKILL.md

markdown
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The project-level settings create persistent automatic behavior that survives across sessions and can influence future agent interactions without per-session review. In the context of a self-improvement skill, persistence makes the behavior more dangerous because it continuously injects reminders and can normalize background processing of prompts and tool outputs.

Content

Scanner excerpt · references/hooks-setup.md (reported line 15)May include surrounding context.

Option 1: Project-Level Configuration

Create .claude/settings.json in your project root:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The empty matcher causes the hook to run on every prompt, which broadens activation scope beyond error/debug scenarios and increases exposure to prompt content on all interactions. In a self-improvement skill, this creates unnecessary collection and processing of user inputs, raising privacy and overreach concerns even if the script only emits reminders.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The instructions create a persistent .learnings directory in the workspace or skill directory, enabling retention of operational and conversational artifacts across sessions. In the context of a self-improvement skill, this persistence becomes risky because it can accumulate sensitive data, influence future model behavior, and survive longer than users expect.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 57)May include surrounding context.

openclaw hooks enable self-improvement

text

### 3. Create Learning Files

Create the `.learnings/` directory in your workspace:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide tells users to promote learnings from ephemeral notes into persistent workspace files such as SOUL.md, TOOLS.md, and AGENTS.md, but it does not prominently warn that these files may retain sensitive operational details across sessions. Because OpenClaw injects workspace files into future sessions, over-collection can amplify privacy leakage and make accidental disclosure more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The detection triggers are broad enough to fire on normal user corrections, tool errors, and vague 'knowledge gaps', which can cause excessive or unintended logging of conversational content into persistent memory. In a self-improvement skill, this increases the chance that sensitive prompts, mistakes, or context from unrelated tasks are captured without sufficient minimization or consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Conditions like "User provides information you didn't know" and "Unexpected output or behavior" depend on broad judgment calls and do not clearly define the threshold for invoking the skill. This ambiguity increases the chance of inconsistent or excessive activation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.