Back to skill

Security audit

my_soul_upgrade_skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly for changing persistent agent instruction files, including global changes across agents, so users should review it carefully before use.

Install only if you intentionally want an administrative workflow for modifying OpenClaw SOUL definitions. Before running the rebuild script, inspect that local script, back up existing SOUL and template files, review diffs, and avoid global rebuilds unless you are comfortable changing every affected agent.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.