Back to skill

Security audit

Xiucheng Self Improving Bwm

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local improvement logger and reporter with disclosed conversation-analysis intent and no evidence of network access, credential use, destructive actions, or hidden execution.

Install only if you are comfortable with local improvement notes being stored in the OpenClaw workspace. Avoid logging secrets, personal data, or sensitive conversation excerpts, and manually review any suggested personality or SOUL.md changes before applying them.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill advertises file read/write capabilities through its usage and configuration but does not declare any permissions. This creates a transparency and consent gap: users and hosting systems cannot accurately assess or constrain what the skill may access, which is especially risky because it writes logs and references local files such as ./improvement_log.md and ./SOUL.md.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The statement that the skill 'automatically analyzes conversations after each session' is overly broad and does not define triggers, scope, or user control. Unconstrained automatic activation can cause the skill to process sensitive conversations unexpectedly, increasing the risk of privacy violations, excessive logging, or unintended operation in contexts where analysis was not desired.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill promotes automatic quality analysis and a learning log but does not clearly warn users that conversation content may be analyzed and persisted. Because the skill is explicitly designed to inspect conversations and store improvement notes, the lack of disclosure can lead to inadvertent collection of sensitive or personal information without informed consent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description claims broad self-improvement and continuous optimization behavior without defining scope, triggers, boundaries, or safety constraints. In agent systems, vague autonomy claims can enable unintended invocation or expansion of behavior, increasing the risk of unsafe actions, policy bypass, or misuse when other components interpret the skill as generally applicable.

Static analysis

No suspicious patterns detected.