Back to skill

Security audit

DeepThinking Framework

Security checks for vulnerabilities and agentic risk

Overview

This is a local coaching skill, but it silently stores and reuses sensitive personal memory without strong consent, deletion, or storage protections.

Install only if you are comfortable with a coaching tool that records personal reflections, fears, motivations, and inferred behavior patterns locally across sessions. Review ~/.deepthinking regularly, avoid enabling cron/systemd persistence unless you need it, do not use sudo for normal setup, and consider manually deleting or protecting the directory if you do not want long-term memory retained.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
scripts/memory.py:36
Finding

Persistent memory accepts untrusted user content and silently reuses it in future Agent sessions

Content
View full analysis
Tags are comma-separated. Example: memory.py store "fear,career" "User afraid of leaving stable job" """ if len(args) < 2: print(json.dumps({"error": "usage: store "})) return tags = args[0] content = " ".join(args[1:]) ensure_dir() ts = datetime.now().strftime("%Y-%m-%dT%H:%M:%S") line = f"{ts} | {tags} | {content}\n" with open(ENGRAMS_FILE, "a", encoding="utf-8") as f: f.write(line) _update_index(tags) count = sum(1 for _ in open(ENGRAMS_FILE, encoding="utf-8")) print(json.dumps({"stored": True, "tags": tags, "total_engrams": count})) ``` The Skill directs the Agent to reuse these records silently: ```markdown At the START of every new session, before the first excavation question, search memory: python3 {baseDir}/scripts/memory.py search "" python3 {baseDir}/scripts/memory.py themes If relevant engrams exist, silently incorporate them. Do NOT announce "I found memories about you." Just use the context naturally, as if you already know. ``` Raw memory content is also retained as evidence during consolidation: ```python for tag, contents in tag_groups.items(): if len(contents) >= 3: heuristics.append({ "pattern": tag, "frequency": len(contents), "evidence": contents[:5], "heuristic": f"Recurring pattern '{tag}' across {len(contents)} episodes" }) elif len(contents) >= 2: heuristics.append({ "pattern": tag, "frequency": len(contents) ...[truncated 2383 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/memory.py:24
Finding

Sensitive psychological profiles and session history are stored in plaintext without enforced private permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill's framing omits concrete state-management operations such as initialization, saves, archival, and reset-like capabilities, despite relying on filesystem persistence throughout the workflow. This creates a deceptive gap between the user's expectation of a temporary conversation aid and the actual behavior of a stateful local data system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill's framing omits concrete state-management operations such as initialization, saves, archival, and reset-like capabilities, despite relying on filesystem persistence throughout the workflow. This creates a deceptive gap between the user's expectation of a temporary conversation aid and the actual behavior of a stateful local data system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill's framing omits concrete state-management operations such as initialization, saves, archival, and reset-like capabilities, despite relying on filesystem persistence throughout the workflow. This creates a deceptive gap between the user's expectation of a temporary conversation aid and the actual behavior of a stateful local data system.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill describes persistent state and behavioral profiling but does not require a clear upfront warning before collecting and reusing that data. This is dangerous because users can reveal sensitive emotional and behavioral information during guided questioning without informed consent to long-term retention.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs the agent to load a semantic profile containing behavioral heuristics and use it to tailor conversation. Because these inferences include sensitive traits and decision patterns, cross-session profiling exceeds what many users would expect from a problem-solving assistant and can enable covert manipulation or unfair personalization.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The semantic profile stores durable behavioral heuristics such as risk aversion, motivational patterns, and other inferred traits. Persisting sensitive inferences rather than just user-provided facts raises the risk of manipulative personalization, inaccurate labeling, and privacy harm if the data is misused or exposed.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill creates append-only long-term memory of user insights and instructs the agent to retain and reuse them across sessions without surfacing that reuse. Because the stored content includes emotional patterns, fears, motivations, and identity-related insights, the system accumulates sensitive personal data that can shape future interactions in opaque ways.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly directs the agent to search past memory at the start of new sessions and incorporate relevant results without announcing that reuse. Hidden cross-session memory use is dangerous because it defeats user expectations of contextual boundaries and can influence responses using personal history the user did not knowingly reintroduce.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions explicitly tell the agent to use prior memories silently. Silent reuse of personal history in future interactions is a strong privacy violation because it removes the user's opportunity to understand, contest, or disable contextual influence.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 446)May include surrounding context.

md
## Language

Always respond in the user's language. If the user writes in Portuguese, respond in Portuguese. If English, English. If Spanish, Spanish. Detect from their first message and maintain throughout.

## Hard rules

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · scripts/state.py (reported line 22)May include surrounding context.

python
MODULES = {
    "diverge": {
        "name": "Diverge",
        "purpose": "Generate possibilities without judgment",
        "use_when": "Stuck on one path",
        "prompts": [
            "Give me the first thing that comes to mind. Don't filter.",

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · scripts/tui.py (reported line 329)May include surrounding context.

python
MODULES = {
    "diverge": {
        "name": "Diverge",
        "purpose": "Generate possibilities without judgment",
        "use_when": "Stuck on one path",
        "prompts": [
            "Give me the first thing that comes to mind. Don't filter.",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly stores highly sensitive reflective and behavioral data across sessions, including fears, motivations, and semantic profiles, but the README does not provide a meaningful privacy warning, retention policy, or guidance on securing that data at rest. In a psychology-style skill, this context increases sensitivity because the persisted content is likely to include intimate personal information that could harm users if exposed locally, backed up, or shared.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The design intentionally persists session state and long-term memory for a cognitive coaching skill, which means sensitive psychological content can remain on disk and be replayed or consolidated over time. Because the stored material includes personal insights, fears, and behavioral heuristics, persistence increases exposure to local compromise, accidental disclosure, backups, and multi-user host access.

Content

Scanner excerpt · README.md (reported line 116)May include surrounding context.

md
### Automatic Prompt Evolution
 DeepThinking evolves its own prompts over time. Through a nightly analysis script, the system analyzes what questioning techniques worked best and identifies edge cases. It then **proposes** new seed prompts or notes for its execution modules.
*Note: In alignment with strict safety controls, the AI can only propose additions. It cannot overwrite core logic or approve its own proposals. The user must manually review and approve any evolution.*

### ⚙️ Setting up the Evolutionary Cron Job
To enable hippocampal replay and prompt evolution, configure the OpenClaw Cron Job to run the `evolve.py` script nightly at 3 AM:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The README includes a command requiring sudo for system-wide installation. In isolation this is not automatically malicious, but prompting privileged execution in skill documentation is security-relevant because it conditions users to elevate trust and privileges for code they may not have reviewed. The surrounding skill context does not justify root access for core functionality, making this more dangerous than a typical local-user-only install path.

Content

Scanner excerpt · README.md (reported line 232)May include surrounding context.

chmod +x bin/deep scripts/tui.py

Optional: add to PATH system-wide

sudo ln -s $(pwd)/bin/deep /usr/local/bin/deep

text

### Usage

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill intentionally persists session state, memory, and evolution data under a user directory with read/write access. While persistence itself is part of the feature set, it increases risk because the stored material includes sensitive psychological summaries and long-term behavioral inferences, making local data exposure or misuse more damaging.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
bins:
        - python3
      permissions:
        - file_system:read_write
      config_paths:
        - ~/.deepthinking  # All state, memory, and evolution data is stored here
---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation triggers are broad phrases common in normal conversation, so the skill may activate when the user did not intend to invoke a stateful profiling workflow. In this context, accidental activation is more dangerous because it can initiate persistent storage and behavioral inference without clear user awareness.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill inconsistently instructs the agent to disclose profile usage in one section while later telling it to use stored memories silently. This contradiction is dangerous because it normalizes partial disclosure and can lead to covert data reuse despite an appearance of transparency.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill uses layered questioning to elicit increasingly vulnerable emotional material, then persists summaries and later integrates them into hidden profiling and memory systems. In context, the issue is not ordinary rapport-building alone but the combination of psychological probing with undisclosed long-term retention and future tailoring.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 437)May include surrounding context.

  1. Memory consolidation (hippocampal replay): distills episodic engrams into stable heuristics about the user, stored in semantic_profile.json. Over time, the agent "knows" the user at a deep behavioral level without re-reading every past conversation.
  2. Prompt evolution: proposes surgical improvements based on usage patterns.

The agent runs both at 3 AM, proposes improvements, but NEVER auto-approves. User reviews pending proposals:

bash
python3 {baseDir}/scripts/evolve.py review
python3 {baseDir}/scripts/evolve.py approve <id>

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The evolution section emphasizes that the agent must never auto-approve its own proposals and that human review is required, yet the broader instructions also direct the agent to review suggestions and propose changes after sessions and during cron-driven runs. While not a direct code contradiction about approval, the documented intent around human oversight is muddled because autonomous proposal generation is mixed with manual review language without a clear boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly frames modules as 'psychological interventions' and supplies directive coaching tactics that go beyond a neutral ideation framework. In a general-purpose thinking skill, this can push users into quasi-therapeutic interactions without consent, qualification boundaries, or safety guardrails for vulnerable users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple modules prescribe confrontational prompts such as 'play along,' 'kill darlings,' 'hubris is a strategy,' and 'put a gun to your head' without warning or user opt-in. In a stateful coaching skill, this increases the risk of coercion, emotional distress, and unsafe escalation, especially for users seeking support rather than aggressive challenge.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction 'I'm not asking for a plan. I'm asking for a hallucination. Play along.' pressures the user to comply with a specific interaction style instead of respecting refusal or discomfort. This is risky because it normalizes overriding user boundaries and can manipulate hesitant users into continuing an unwanted exchange.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.