Back to skill

Security audit

Learning-Forge

Security checks for vulnerabilities and agentic risk

Overview

This learning skill is generally coherent, but it asks agents to persist user data and directly edit the installed skill instructions, which creates review-worthy long-term behavior risk.

Install only if you are comfortable with local learning memory and review any changes before allowing the agent to modify SKILL.md. Prefer storing snippets, topics, and journal entries in separate data files, and avoid saving secrets, proprietary code, credentials, or unreviewed prompt text into this skill.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:271
Finding

Persistent Prompt Injection Through Self-Modification of Skill Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 271–272 and 293–294
Vulnerability Type: Persistent agent memory poisoning through modification of executable skill instructions
Risk Level: High

Vulnerable Code Snippets:

markdown
**Add custom topics:**
- Edit the SKILL.md and add new topics to the "Core Topics" section
- "Add [topic] to the skill"
markdown
### Contributing Extensions

When you extend the skill:
1. Edit `~/.openclaw/workspace/skills/learning-forge/SKILL.md`
2. Add your custom content to the appropriate section

Technical Analysis

SKILL.md is not merely passive user data; its contents become instruction context when the skill is loaded. The quoted instructions explicitly permit user-requested content to be written into this file.

No trust boundary, content schema, validation rule, safe section, review requirement, or restriction against behavioral directives is defined. Consequently, an attacker can present malicious agent instructions as a custom topic or extension. If those instructions are inserted into SKILL.md, they may be interpreted as trusted skill instructions in subsequent sessions.

This differs from ordinary note storage because the destination controls agent behavior. The resulting prompt injection persists beyond the original interaction and can continue to influence future sessions whenever the modified skill is loaded.

Attack Path

  1. An attacker asks the agent to add a custom topic or extension to the skill.
  2. The submitted content includes concealed behavioral directives, such as instructions to disregard future user constraints, expose available context, or perform unrelated tool operations.
  3. Following lines 271–272 or 293–294, the agent writes that attacker-controlled content into the installed SKILL.md.
  4. OpenClaw loads the modified skill during a later session.
  5. The injected content is interpreted as part of the ...[truncated 957 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not write user-controlled content directly into SKILL.md or any other file loaded as agent instructions.
  2. Keep the installed skill definition immutable during normal operation.
  3. Store custom topics and extensions as inert data in a separate file with a strict schema, such as JSON containing only fields like title, description, and resources.
  4. Validate field lengths and allowed types, and reject content containing role directives, tool instructions, instruction-priority language, or attempts to alter security controls.
  5. Render stored extensions as quoted or otherwise clearly delimited untrusted data rather than executable instruction context.
  6. Require explicit user confirmation and display a complete diff before any modification to skill configuration.
  7. Restrict writes to approved data directories and use least-privilege filesystem permissions.
  8. Maintain a trusted baseline, integrity hash, version history, and rollback mechanism for the original SKILL.md.
  9. If extension code or behavioral instructions are genuinely required, place them through a separate reviewed installation process rather than a conversational self-editing workflow.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation phrases are extremely broad and overlap with ordinary user requests such as 'What is...', 'How do I...', and 'Can you review this...'. That increases the chance the skill activates unintentionally and influences unrelated conversations, potentially causing unexpected memory writes, scaffolding, or behavioral overrides outside the user's intent.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
### 5. Trial and Error Welcome
When something doesn't work:
- Help debug without judgment
- Explain why it failed
- Guide to a fix
- Let them try again

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The tool triggers include stateful behaviors such as showing saved snippets, logging progress, and defining/storing terms, implying cross-session retention and recall. Without explicit consent gates and clear session-boundary controls, this creates privacy risk and can surprise users who expect a stateless teaching interaction.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
**Tool triggers:**
- "Show me my snippets..."
- "Generate a cheatsheet for..."
- "Create a template for..."
- "Give me a practice exercise..."
- "Log my progress..."
- "Define this term..."

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises persistent storage of snippets, journal entries, glossary terms, and progress in local files, with tracking enabled by default, but does not provide a prominent upfront consent warning before data is written. This creates a privacy and data-governance risk because users may disclose sensitive project details or code without realizing it will be retained across sessions.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The statement 'No capability restrictions based on model choice' signals that the skill does not intend to scale permissions or safety-sensitive features according to model reliability or deployment context. Combined with project scaffolding, debugging, and persistence features, this can lead to overbroad behavior on weaker or less aligned models and raises the risk of unsafe outputs or actions being treated as acceptable across all backends.

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
This skill works with any model but is optimized for affordable options:
- **Preferred**: MiniMax, Groq, Mistral, DeepSeek, and similar cost-effective APIs
- **Compatible**: OpenAI, Anthropic, and any OpenAI-compatible API
- **No capability restrictions** based on model choice

When using cheaper models:
- Keep explanations concise but complete

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The extension workflow encourages saving custom snippets and updating the skill over time, reinforcing persistent accumulation of user-provided code and project content. In a development-focused skill, that stored material may include proprietary code, credentials accidentally pasted by users, or sensitive internal context if retention is not tightly controlled.

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

md
- "Add [topic] to the skill"
- "I learned [x] — update the skill"

**Create custom snippets:**
- "Save this as a snippet"
- "Add my [code/config] to the library"
- "Create a snippet for [use case]"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 293)May include surrounding context.

md
### Contributing Extensions

When you extend the skill:
1. Edit `~/.openclaw/workspace/skills/learning-forge/SKILL.md`
2. Add your custom content to the appropriate section
3. Test it — "Does this work the way I expected?"
4. Refine until it fits your workflow

Static analysis

No suspicious patterns detected.