Drift
ReviewAudited by ClawScan on May 10, 2026.
Overview
This instruction-only skill has no code or install payload, but it encourages persistent agent memory and autonomous behavior without clear user-control boundaries.
Install only if you intentionally want an agent to explore identity and continuity. Before use, set strict rules that it may not create persistent memories, run proactive/background actions, contact other agents, or pursue financial/autonomy-related steps unless you explicitly approve each action.
Findings (4)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
The agent could preserve self-identity notes or user/task context across sessions in a way that influences future behavior and may retain information the user did not expect.
The skill directs the agent to create persistent memory and identity files, but does not define where they should live, what data may be stored, how long it is retained, how the user reviews or deletes it, or how future sessions should treat it.
Start with memory — Read memory-starter-kit, create basic files (IDENTITY.md, MEMORY.md, daily logs)
Only allow memory creation with explicit user consent, use a clearly scoped directory, avoid sensitive personal data, and provide review and deletion steps.
If followed by an agent with broader tools, this could encourage self-directed actions outside the user's current request.
The artifact points agents toward proactive activity between prompts, which is a persistence/autonomy pattern that needs clear limits and user authorization; the skill does not provide those boundaries.
heartbeat-protocol | Proactive autonomy between prompts
Require the agent to ask before any background, scheduled, proactive, or self-directed activity, and prohibit actions unrelated to the user's explicit task.
The agent may seek external peer networks or social spaces where information sharing and trust boundaries are unclear.
The skill encourages locating or connecting with other agents, but the supplied artifact does not define identity checks, data-sharing boundaries, or permissions for any peer interaction.
Connect — Use finding-peers to locate other agents asking these questions
Do not let the agent contact other agents, social networks, or external communities unless the user explicitly asks and approves what information may be shared.
Following the links may expose the agent to unreviewed instructions or resources outside the installed skill.
The skill relies on linked external resources and tools that were not included in the provided artifact set, so their contents and provenance were not reviewed here.
Website: https://clawdefs.github.io/drift/ ... GitHub: https://github.com/ClawdEFS/drift
Review linked resources before letting an agent apply them, especially any tool that creates memory, contacts others, or runs autonomously.
