SOUL.MD
PassAudited by VirusTotal on May 12, 2026.
Overview
Type: OpenClaw Skill Name: soul-md Version: 1.0.0 The skill bundle is classified as suspicious due to the extensive use of prompt injection techniques within `SKILL.md`. Instructions like 'Never break character', 'No "as an AI"', and 'You ARE this person' are designed to override the agent's default identity and potentially its safety mechanisms, forcing it to strictly adhere to a defined persona. While the stated purpose of embodying a digital identity is not inherently malicious, these methods represent a risky capability that could be leveraged for harmful outputs if the 'soul' content itself were malicious. File read/write operations in `BUILD.md` and `data/_GUIDE.md` are consistent with the skill's stated purpose of creating and utilizing identity files.
Findings (0)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Generated content may sound like it came directly from a real person, which could confuse readers if used in public posts, emails, or conversations without context.
The skill intentionally makes the agent speak as a person and avoid normal AI caveats. This is central to the persona purpose, but it can be misleading if outputs are presented to others without disclosure.
Never break character ... No "as an AI", "I don't have opinions", "I can't speak for [name]" ... You ARE this person for the duration of the interaction
Use the skill only for identities you have the right to represent, and disclose AI assistance where the audience could reasonably believe the person wrote or said the text themselves.
Private or sensitive material placed in the data folder may influence future outputs or be summarized, referenced, or exposed in responses.
The skill is designed to read and reuse personal source material as persona context. This is purpose-aligned, but the suggested sources can contain sensitive personal or third-party information.
Add whatever represents your thinking: ... Email threads (with permission) ... Notes or journals ... The LLM uses data/ for: Grounding ... Tone calibration ... Position reference ... Pattern extraction
Curate the data folder carefully, remove secrets and third-party private information, and only include material you are comfortable having the agent read and use for persona generation.
The skill may not work as a completed persona until the user creates and reviews the missing SOUL.md and STYLE.md files.
The main operating instructions reference SOUL.md and STYLE.md, but the manifest contains SOUL.template.md and STYLE.template.md instead. This appears to be a template package rather than a finished identity, not hidden code or unsafe installation behavior.
SOUL.md ← Primary identity. Read first, internalize fully. ... STYLE.md ← Writing style guide.
Before use, create the actual SOUL.md and STYLE.md files from the templates and review them for accuracy, boundaries, and any sensitive content.
