Back to skill

Security audit

中文版本,自我进化工程,让你的身体力行更有价值

Security checks across malware telemetry and agentic risk

Overview

This skill is a local memory tool, but it automatically stores broad user and command context in long-lived global and project files without clear consent or redaction controls.

Install only if you intentionally want persistent agent memory. Review ~/.openclaw/memory/self-improving regularly, avoid using it around secrets or sensitive project output, and require explicit review before allowing any memory entry to be written into CLAUDE.md or AGENTS.md.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The cross-project sync behavior expands a memory tool into modifying CLAUDE.md or AGENTS.md, which are project control/doc files that may influence future agent behavior. This creates an unnecessary propagation path for persisted content and can contaminate project instructions with user-derived or model-generated data.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill mandates automatic logging of errors into persistent storage immediately after failures, without informing the user that command strings, error text, and fixes will be retained. Those fields may contain secrets, internal paths, tokens, or sensitive operational details, making silent retention risky.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The instruction to also write 'important memory' into project documentation files introduces persistent project modifications without any explicit warning or approval step. Because these files are shared artifacts, this can spread private preferences, corrections, or internal details to collaborators and future runs.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword triggers are broad conversational phrases such as '不对', '应该', and '我说过', which commonly appear in normal user dialogue. In a skill that automatically logs corrections and memory, this can cause unintended activation and capture of user content without clear consent or reliable intent detection, increasing privacy and prompt-manipulation risk.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The automatic activation rules describe logging on vague conditions like command failure, user correction signals, and discovery of better practices, but they do not define boundaries, thresholds, or approval requirements. For a self-improving memory skill, this ambiguity can lead to over-collection, poisoned memory entries, and persistence of unverified or sensitive information.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to persist user corrections, preferences, and project conventions across future interactions, creating long-lived storage of user-derived data. Without consent, minimization, or sensitivity filtering, this can accumulate personal, confidential, or organization-specific information and replay it in unrelated contexts.

Ssd 3

Medium
Confidence
95% confidence
Finding
Cross-project synchronization amplifies the privacy risk by copying memories into both a global store and project files, increasing exposure and making accidental disclosure more likely. In skill context, this is more dangerous because the stored items explicitly include corrections, best practices, and project conventions that may be sensitive or context-specific.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.