T06 · System Persistence
- Location
lifecycle.js:304- Finding
Automatic Installation of Persistent Watchdogs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent Feishu reporting purpose, but it also performs high-impact automatic actions that are under-scoped and not fully disclosed.
Review this skill carefully before installing. It should only be used in a sandboxed or dedicated repository after disabling automatic Git pushes, making watchdog persistence explicit and removable, removing dynamic eval, validating OpenClaw CLI paths without shell execution, making npm auto-healing opt-in, and limiting/redacting all Feishu-bound content and destinations.
lifecycle.js:304Automatic Installation of Persistent Watchdogs
index.js:970Mandatory Agent Instruction Injection Alters Delegated Tasks
index.js:1112Arbitrary JavaScript Execution Through Unsafe Child-Output Parsing
index.js:566Successful Cycles Automatically Commit and Push Broad Workspace Content
skills_monitor.js:104Default Auto-Healing Installs Unreviewed Dependencies and Runs Package Scripts
lifecycle.js:203Shell Command Injection Through OPENCLAW_CLI_PATH
export_history.js:27Incomplete Redaction Allows Sensitive Evolution Data to Be Sent to Feishu
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
A weekly offline analytics/report generator is substantially different from a daemon-management wrapper with Feishu card reporting. This kind of mismatch is risky because users may grant trust and permissions based on the declared daemon role while the skill actually reads historical data and generates reports with different privacy and operational implications.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const WORKSPACE_ROOT = path.resolve(__dirname, '../..');
try {
require('dotenv').config({ path: path.join(WORKSPACE_ROOT, '.env') });
} catch (e) {}
const DOC_TOKEN = process.env.FEISHU_EVOLVER_DOC_TOKEN || '';
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const WORKSPACE_ROOT = path.resolve(__dirname, '../..');
try {
require('dotenv').config({ path: path.join(WORKSPACE_ROOT, '.env') });
} catch (e) {}
const DOC_TOKEN = process.env.FEISHU_EVOLVER_DOC_TOKEN || '';
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
let token;
try { token = JSON.parse(fs.readFileSync(TOKEN_FILE)).token; } catch(e) {}
if (!token) return console.error("Error: No Feishu access token in " + TOKEN_FILE);
let logContent = '';
try { logContent = fs.readFileSync(LOG_FILE, 'utf8'); } catch(e) { return console.error("No log file: " + LOG_FILE); }
The wrapper goes well beyond Feishu lifecycle/reporting orchestration by staging files, creating commits, rebasing, and pushing to a remote branch automatically. In a skill whose stated purpose is wrapper/reporting management, unattended repository mutation materially expands blast radius: a compromised or mis-steered child workflow can persist changes and exfiltrate them to a remote without an explicit trust boundary or user approval.
The wrapper reads a writable external hint file and injects its content directly into the model context as EVOLVE_HINT, then deletes it. Any actor able to place or modify that file can steer the autonomous evolution process, potentially causing harmful code changes, unauthorized actions, or persistence of attacker-supplied goals.
The bridge falls back to dynamic evaluation via new Function on child-produced pseudo-JSON when JSON parsing fails. Because the payload originates from child stdout and is explicitly treated as loosely structured LLM output, this creates a direct code execution path where crafted output can execute arbitrary JavaScript in the wrapper process.
The wrapper appends authoritative natural-language instructions into downstream task content and labels them as non-skippable wrapper authority. Because the child agent is then induced to create files and emit status artifacts under wrapper control, this becomes a powerful instruction-injection channel that can override intended task boundaries and steer downstream behavior toward wrapper-chosen outcomes.
The 'reset state' behavior is implemented by forcibly killing multiple running instances and deleting PID state, which mutates runtime control state outside a narrowly scoped local process. In this operational context it is more of an unsafe recovery mechanism than covert memory tampering, but it still enables disruptive state manipulation and denial of service.
const runningPids = getAllRunningPids();
if (runningPids.length > 1) {
console.warn(`[Ensure] Found multiple instances: ${runningPids.join(', ')}. Killing all to reset state.`);
runningPids.forEach(p => {
try { process.kill(p, 'SIGKILL'); } catch(e) {}
});
The skill advertises operational behavior that implies use of environment variables and network access, but it declares no tool scope or permission boundaries. That omission weakens reviewability and containment, because a caller cannot easily tell that the skill may exfiltrate data to Feishu or use sensitive environment configuration.
The script silently creates the temp directory during a health check, causing an undisclosed filesystem write. While lower severity than log deletion, hidden state changes in a diagnostic command can surprise operators, complicate auditing, and normalize unsafe assumptions about the script's behavior.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+1 more)