Back to skill

Security audit

Rule Toolkit

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate rule-to-tooling purpose, but it broadly reads sensitive agent context files and can create persistent hooks that run unpinned commands automatically.

Install only if you are comfortable letting the skill inspect agent context files and modify project tooling. Before running it, review the exact files it will read, exclude memory or identity files unless needed, require a diff before any writes, avoid deleting original rules, and replace generated bare npx hooks with pinned local dependencies or lockfile-backed package scripts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:26
Finding

Overbroad Access to Sensitive Agent State and Memory Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:26-36
Vulnerability Type: Excessive access to persistent agent state
Risk Level: Medium

Vulnerable Code

markdown
## Platform Detection

Detect which platform(s) are present, then scan the corresponding constraint files.

```bash
test -f CLAUDE.md && echo "CLAUDE_CODE"
test -f openclaw.json && echo "OPENCLAW"
test -f .cursorrules && echo "CURSOR"
test -f .github/copilot-instructions.md && echo "COPILOT"

Claude Code: CLAUDE.md (monolithic), .claude/commands/*.md OpenClaw: agents.md (priority 10), soul.md (20), identity.md (30), user.md (40), tools.md (50), bootstrap.md (60), memory.md (70). Skip SAFETY.md (hardcoded, read-only). Cursor: .cursorrules Copilot: .github/copilot-instructions.md Generic: AGENT.md, SOUL.md, README.md conventions sections

Read ALL found files. Extract every rule, convention, and constraint.

text

### Technical Analysis

The Skill explicitly directs the agent to read every detected OpenClaw context file, including `identity.md`, `user.md`, `bootstrap.md`, and `memory.md`. These files can contain persistent memories, personal preferences, identity constraints, operational details, or other sensitive state that is not necessarily required to convert coding conventions into automated tools.

This violates least-privilege principles because access is mandatory rather than limited to files selected by the user or directly relevant to the requested rule conversion. The Skill also permits generated reports and tooling, creating a risk that sensitive content encountered during scanning could be reproduced in generated artifacts or conversation output.

No network exfiltration, credential harvesting, or direct bypass of operating-system permissions was found. The risk is confined to unnecessary access through permissions already available to the
...[truncated 1215 chars]
Remediation
View remediation

Remediation Suggestions

  1. Default scanning to rule-oriented files such as tools.md, CLAUDE.md, and explicitly selected project instruction files.
  2. Require informed user confirmation before reading identity.md, user.md, bootstrap.md, or memory.md.
  3. Display the exact proposed file list before any content is read.
  4. Add exclusion controls so users can omit sensitive state files or directories.
  5. Apply secret and personal-data redaction before including extracted rules in reports or generated artifacts.
  6. Prohibit copying memory, identity, or user-profile content into generated configurations unless the user explicitly approves the exact content.
  7. Preserve the existing prohibition against modifying SAFETY.md and extend it to prevent automatic rewriting of memory and identity files.

T08 · Insecure Dependencies

Warning
Location
references/openclaw-hooks.md:12
Finding

Automatically Triggered Hooks Use Unpinned npx Package Execution

Content
View full analysis

Vulnerability Details

File Locations: references/openclaw-hooks.md:12-29, references/tool-patterns.md:110-119, and SKILL.md:133-145
Vulnerability Type: Unsafe third-party package resolution in persistent hooks
Risk Level: Medium

Vulnerable Code

From references/openclaw-hooks.md:12-29:

json5
{
  "hooks": {
    "afterFileWrite": {
      "pattern": "src/**/*.{ts,tsx,js,jsx}",
      "command": "npx eslint --fix $FILE && npx prettier --write $FILE"
    }
  }
}
json5
{
  "hooks": {
    "beforeReply": {
      "command": "npx tsc --noEmit 2>&1 | head -20"
    }
  }
}

From references/tool-patterns.md:110-119:

bash
# .husky/pre-commit
npx lint-staged
bash
# .husky/commit-msg
npx commitlint --edit "$1"

The persistence and automatic execution context is established by SKILL.md:133-145:

markdown
**OpenClaw** — replace removed rules in each file (e.g. `tools.md`):

```markdown
## Tool Rules
Automated: linting (`npx eslint .`), type check (`npx tsc --noEmit`).
API format: use `ok()`/`fail()` from `src/utils/response.ts`.
Remaining rules below require human judgment.

Safety Rules

  • NEVER modify existing tool configs without showing a diff first
  • ALWAYS preserve existing rules, only add new ones
  • ALWAYS create wrapper functions in a new file
  • ALWAYS run generated configs to verify they parse correctly
text

### Technical Analysis

The documented generation patterns place bare `npx` commands into OpenClaw and Git hooks. The commands do not use pinned package versions, a verified lockfile, local executable paths, or `npx --no-install`.

When a requested executable is unavailable locally, applicable `npx` configurations may resolve and install a package from the configured registry. The resolved package can then execute arbitrary JavaScript with the privileges of the user running the ho
...[truncated 1983 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add reviewed dependencies to the project manifest with pinned versions and commit the corresponding lockfile.
  2. Require explicit user approval before installing any new dependency.
  3. Invoke verified local executables, for example ./node_modules/.bin/eslint, ./node_modules/.bin/prettier, and ./node_modules/.bin/tsc.
  4. If npx remains necessary, use npx --no-install so a missing local package causes a safe failure instead of a registry download.
  5. Install dependencies with lockfile-enforcing commands such as npm ci, and review lockfile changes before enabling hooks.
  6. Configure an approved registry and use package integrity verification and dependency scanning.
  7. Generate hooks in a disabled or review-only state, show the complete diff, and require explicit confirmation before activation.
  8. Run hooks with the least available privileges and prevent unnecessary access to secrets or production credentials.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description promises a rule-to-tools conversion capability: scanning constraint files and auto-generating enforceable artifacts such as linters, hooks, validators, and wrapper functions. The supplied code only implements detection and reporting. It identifies some platform files, scans bullet-list lines, matches simple regex patterns for categories like code style or security, and outputs counts plus a prompt to 'run the skill' for actual generation. That is a materially different, narrower behavior than the declared primary purpose. There is no undeclared harmful capability, but the description overstates what this code chunk does.

Content

No source excerpt is available for this finding.

Indirect Prompt Extraction

Medium
Category
System Prompt Leakage
Confidence
75% confidence
Finding

Skill contains patterns that could indirectly extract system prompts through rephrasing, translation, summarization, or side-channel techniques.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: rule-toolkit
version: 1.0.0
description: Scan constraint files (CLAUDE.md, agents.md, soul.md, tools.md, bootstrap.md, .cursorrules) across AI coding platforms, identify rules enforceable by tools, and auto-generate linters, hooks, validators, and wrapper functions. Use when setting up a new project, onboarding an existing codebase, or when the user says "convert rules to tools", "make rules enforceable", "automate my CLAUDE.md rules", or "toolify constraints".
license: MIT
compatibility: "Requires Node.js 18+ for ESLint/Prettier/Husky generation. Python projects use ruff. Works with Claude Code, OpenClaw, Cursor, Copilot, and any Agent Skills compatible tool."
allowed-tools: "Bash Glob Grep Read Write Edit"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
| security | "No innerHTML" / "Validate user input" | ESLint + zod |
| testing | "Every module needs a test file" | Test existence checker |
| git | "Conventional commits" / "Lint before commit" | commitlint + husky |
| dependency | "No new deps without approval" | dependency-check script |
| performance | "No lodash, use lodash-es" | ESLint no-restricted-imports |

### Prompt-Only (cannot automate)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly instructs users to remove toolified rules from human-readable constraint files to save tokens. This can weaken layered safeguards by stripping context, rationale, and non-toolable guidance; if the generated tooling is incomplete or later drifts, important safety and workflow constraints may silently disappear.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

npx tsc --noEmit has the same trust problem as other unpinned npx usage: it may execute whatever typescript version is locally resolved or fetched at runtime. Because this skill is about auto-generating tooling that users may run in repositories of varying trust, unpinned execution increases the attack surface for dependency confusion and unexpected behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

npx tsc --noEmit has the same trust problem as other unpinned npx usage: it may execute whatever typescript version is locally resolved or fetched at runtime. Because this skill is about auto-generating tooling that users may run in repositories of varying trust, unpinned execution increases the attack surface for dependency confusion and unexpected behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx lint-staged in a generated hook runs whatever package/version is resolved in the local environment or fetched by npm if absent, which can lead to non-reproducible execution and potential supply-chain exposure. In the context of a tool-generation skill, this is more dangerous because the pattern may be propagated automatically into many repositories and executed on every commit.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Using npx commitlint --edit "$1" allows execution of an unpinned package/version if commitlint is not already installed locally, creating a supply-chain and reproducibility risk. Because this file is a pattern library for auto-generated tooling, the unsafe invocation can be copied into multiple projects and triggered routinely during commits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.