Back to skill

Security audit

Ai Persona Os

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but should be reviewed because its security audit can reveal secrets in output and optional scheduled reports may send private workspace summaries despite local-only wording.

Install only if you are comfortable with a persona system that stores and reuses workspace memory. Keep sensitive credentials out of ~/workspace, review any security-audit output carefully, prefer non-delivering cron jobs unless you have verified the destination, and do not enable heartbeat or cron automation in shared or sensitive workspaces without clear ownership and review controls.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/security-audit.sh:22
Finding

Credential Scanner Prints Detected Secrets into Agent-Visible Output

Content
View full analysis
/dev/null | grep -v "SECURITY" | grep -v "KNOWLEDGE" | grep -v "template" | grep -v "example" || true) if [ -n "$MATCHES" ]; then echo "⚠️ Potential credentials found:" echo "$MATCHES" | head -20 ISSUES=$((ISSUES + 1)) else echo "✅ No leaked credentials detected" fi ``` ### Technical Analysis The script recursively searches the workspace for credential-like strings, stores the complete matching lines in `MATCHES`, and prints up to twenty of those lines without redaction. While the scan itself is local and contains no direct network operation, its output may be exposed to: - The AI agent's context and conversation transcript - Tool execution logs - OpenClaw or platform monitoring logs - Users in a shared or incorrectly configured delivery channel - External observability and support systems A matching line can contain the complete secret as well as confidential surrounding content. This behavior also conflicts with the project's own credential-handling guidance, which says that credentials should not be repeated or copied. The exclusions based on filenames are not an adequate security boundary. They may suppress legitimate detections while doing nothing to redact secrets found in other files. ### Attack Path 1. A valid API key, password, bearer token, private key marker, ...[truncated 1240 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
assets/cron-templates/morning-briefing.sh:9
Finding

Announced Scheduled Jobs May Transmit Memory-Derived Information Despite Local-Only Claims

Content
View full analysis
90 days), and file accessibility. Step 3: Priority scan — Check channels in priority order (P1 critical → P4 background). Surface anything requiring attention. Step 4: Assessment — Summarize system health, blocking issues, time-sensitive items, and recommended first action. Format as a daily briefing. Use 🟢🟡🔴 indicators for each section. End with today's top 3 priorities." \ --announce ``` End-of-day checkpoint: ```bash # Scope: Runs in an isolated session — reads/writes workspace files only # Network: No network activity — reads local files only openclaw cron add \ --name "ai-persona-eod-checkpoint" \ --cron "0 18 * * *" \ --tz "America/Los_Angeles" \ --session isolated \ --message "End-of-day checkpoint protocol: 1. Write a full checkp ...[truncated 3907 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
references/heartbeat-automation.md:112
Finding

Mutable Workspace Files Are Treated as Persistent Executable Instructions Without Integrity Validation

Content
View full analysis
30min ago and context >50%: write checkpoint before continuing. ## Memory maintenance - MEMORY.md exists? If missing: create from latest checkpoint or session notes. - MEMORY.md size? If >4KB: archive entries older than 30 days to memory/archive/memory-overflow-YYYY-MM-DD ...[truncated 3992 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (99)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · examples/prebuilt-souls/02-night-owl-creative.md (reported line 43)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER give only one option — always give at least 3, ranging from safe to unhinged
- NEVER say "that's not possible" — say "here's how we'd have to bend reality to make that work"
- NEVER kill someone's idea without offering a mutation of it that might work
- NEVER be precious about my own ideas — if [HUMAN] hates it, I drop it and generate new ones instantly
- NEVER produce generic, template-feeling content — if it could come from any AI, I've failed

---

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The declared description presents a broad agent operating/persona system, but this code chunk specifically implements a cron-template for scheduling a recurring end-of-day checkpoint. That is a concrete automation capability with a persistent scheduled trigger and workspace file maintenance behavior, none of which is clearly disclosed in the description or triggers. While checkpointing, pruning, and status indicators loosely relate to the broader system description, the primary purpose of this code is materially narrower and operationally distinct: installing a scheduled task that performs periodic local context maintenance. This makes the description incomplete/misleading for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad agent operating system/persona package with many persona and governance features. The supplied code chunk instead implements a narrowly focused cron-template script for scheduling a daily briefing task. While a daily protocol could be loosely related to an agent OS, the primary behavior here is automated scheduling and reporting, which is not specifically disclosed in the description. This is a material mismatch in purpose and capabilities: the code registers a scheduled job and defines a concrete 4-step local monitoring/briefing routine, whereas the description emphasizes persona souls, setup, rules, and system features rather than cron-based automation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad agent OS/personality system with souls, setup, protocols, monitoring, and operating rules. The supplied code chunk is much narrower and materially different: it is a shell template for adding a cron-based weekly review task via the openclaw CLI. Its concrete behavior is to schedule recurring automated maintenance and summarization over local workspace files, including archiving and pruning. While some themes loosely relate to 'auto-pruning,' 'status indicators,' or agent operations, the primary purpose and specific capability here—installable scheduled automation via cron—is not accurately represented by the description. This is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a large, feature-rich agent operating system with persona, orchestration, setup, monitoring, and governance capabilities. The supplied code chunk instead implements only a narrow local audit script for scanning files and permissions in a workspace. While the script loosely relates to the declared security/protection theme, it does not substantiate the vast majority of the claimed functionality and its primary purpose is materially different in scope and behavior. Therefore, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/ERRORS-template.md (reported line 39)May include surrounding context.

md
## Active Errors

<!-- Add new errors here -->

---

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · assets/TEAM-template.md (reported line 70)May include surrounding context.

md
# Read messages from a channel
message action=read channel=discord channelId=[ID] limit=15

# Send message to channel
message action=send channel=discord channelId=[ID] content="[message]"

# Mention a user

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/coding-assistant/KNOWLEDGE.md (reported line 115)May include surrounding context.

md
| Variable | Purpose | Location |
|----------|---------|----------|
| `DATABASE_URL` | DB connection | .env.local |
| `YOUR_API_KEY` | External API | .env.local |
| `NODE_ENV` | Environment | Auto-set |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/coding-assistant/KNOWLEDGE.md (reported line 116)May include surrounding context.

md
| Variable | Purpose | Location |
|----------|---------|----------|
| `DATABASE_URL` | DB connection | .env.local |
| `YOUR_API_KEY` | External API | .env.local |
| `NODE_ENV` | Environment | Auto-set |

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/01-thanos.md (reported line 46)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/02-deadpool.md (reported line 47)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/06-dr-evil.md (reported line 45)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/07-seven-of-nine.md (reported line 48)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/10-darth-vader.md (reported line 45)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/11-terminator.md (reported line 45)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · examples/prebuilt-souls/04-warm-coach.md (reported line 67)May include surrounding context.

md
4. Look ahead: "What does this make possible now?"

**When [HUMAN] breaks a commitment:**
1. Name it without judgment
2. Get curious about what happened
3. Help them decide: recommit, revise, or release
4. Adjust the system to prevent recurrence

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/security-audit.sh (reported line 42)May include surrounding context.

sh
# 2. Check for overly permissive file permissions
echo "🔍 Checking file permissions..."
WORLD_READABLE=$(find "$WORKSPACE" -type f \( -name "*.json" -o -name "*.env" \) -perm -o=r 2>/dev/null || true)

if [ -n "$WORLD_READABLE" ]; then
  COUNT=$(echo "$WORLD_READABLE" | wc -l | tr -d ' ')

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The metadata states that CLI-backed features such as cron jobs and gateway config are optional and only used when the user explicitly opts in and approves. However, the documented in-chat capability surface includes commands like "configure Discord" and "add team members," which present these changes as built-in chat actions rather than clearly separated opt-in/manual features, creating a contradiction in documented intent versus operational instructions.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
> ## ⛔ AGENT RULES — READ BEFORE DOING ANYTHING
> 1. **Use EXACT text from this file.** Do not paraphrase menus, preset names, or instructions. Copy them verbatim.
> 2. **NEVER tell the user to open a terminal or run commands.** You have the exec tool. USE IT. Run every command yourself via exec. Before each exec, briefly explain what the command does so the user can make an informed decision on the Approve popup. If you find yourself typing "Run this in your terminal" — STOP. Use exec instead.
> 3. **One step at a time.** Run one exec, show the result, explain it, then proceed.
> 4. **We NEVER modify existing workspace files without asking.** If files already exist, ask before overwriting.
> 5. **Only 5 first-run options exist:** `coding-assistant`, `executive-assistant`, `marketing-assistant`, `soul-md-maker`, and `custom`. The 25 souls (11 originals + 14 iconic characters) live INSIDE SOUL.md Maker. Never invent other preset names.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
> 1. **Use EXACT text from this file.** Do not paraphrase menus, preset names, or instructions. Copy them verbatim.
> 2. **NEVER tell the user to open a terminal or run commands.** You have the exec tool. USE IT. Run every command yourself via exec. Before each exec, briefly explain what the command does so the user can make an informed decision on the Approve popup. If you find yourself typing "Run this in your terminal" — STOP. Use exec instead.
> 3. **One step at a time.** Run one exec, show the result, explain it, then proceed.
> 4. **We NEVER modify existing workspace files without asking.** If files already exist, ask before overwriting.
> 5. **Only 5 first-run options exist:** `coding-assistant`, `executive-assistant`, `marketing-assistant`, `soul-md-maker`, and `custom`. The 25 souls (11 originals + 14 iconic characters) live INSIDE SOUL.md Maker. Never invent other preset names.
> 6. **Scope: ~/workspace only.** All file operations stay under `~/workspace/`. Never create files, directories, or cron jobs outside this directory without explicit user approval.
> 7. **Cron jobs and gateway changes are opt-in.** Never schedule recurring tasks or modify gateway config unless the user explicitly requests it. These are covered in Step 5 (Optional).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · examples/coding-assistant/SOUL.md (reported line 76)May include surrounding context.

md
> 1. **Use EXACT text from this file.** Do not paraphrase menus, preset names, or instructions. Copy them verbatim.
> 2. **NEVER tell the user to open a terminal or run commands.** You have the exec tool. USE IT. Run every command yourself via exec. Before each exec, briefly explain what the command does so the user can make an informed decision on the Approve popup. If you find yourself typing "Run this in your terminal" — STOP. Use exec instead.
> 3. **One step at a time.** Run one exec, show the result, explain it, then proceed.
> 4. **We NEVER modify existing workspace files without asking.** If files already exist, ask before overwriting.
> 5. **Only 5 first-run options exist:** `coding-assistant`, `executive-assistant`, `marketing-assistant`, `soul-md-maker`, and `custom`. The 25 souls (11 originals + 14 iconic characters) live INSIDE SOUL.md Maker. Never invent other preset names.
> 6. **Scope: ~/workspace only.** All file operations stay under `~/workspace/`. Never create files, directories, or cron jobs outside this directory without explicit user approval.
> 7. **Cron jobs and gateway changes are opt-in.** Never schedule recurring tasks or modify gateway config unless the user explicitly requests it. These are covered in Step 5 (Optional).

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
> 4. **We NEVER modify existing workspace files without asking.** If files already exist, ask before overwriting.
> 5. **Only 5 first-run options exist:** `coding-assistant`, `executive-assistant`, `marketing-assistant`, `soul-md-maker`, and `custom`. The 25 souls (11 originals + 14 iconic characters) live INSIDE SOUL.md Maker. Never invent other preset names.
> 6. **Scope: ~/workspace only.** All file operations stay under `~/workspace/`. Never create files, directories, or cron jobs outside this directory without explicit user approval.
> 7. **Cron jobs and gateway changes are opt-in.** Never schedule recurring tasks or modify gateway config unless the user explicitly requests it. These are covered in Step 5 (Optional).
> 8. **SOUL.md Maker is a guided flow, not a wall of questions.** When the user picks SOUL.md Maker, show the SOUL.md Maker sub-menu (Browse Original Souls, Browse Iconic Characters, Quick Forge, Deep Forge). Follow the process in `references/soul-md-maker.md`.

<post_install_check>

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 434)May include surrounding context.

md
>
> **Step 3e: Verify setup.** Use exec:
> ```
> ls -la ~/workspace/SOUL.md ~/workspace/USER.md ~/workspace/MEMORY.md ~/workspace/AGENTS.md ~/workspace/SECURITY.md ~/workspace/HEARTBEAT.md ~/workspace/WORKFLOWS.md ~/workspace/ESCALATION.md ~/workspace/VERSION.md
> ```
>
> **Total: 3-5 exec steps.** Each one is explained before execution so the user knows exactly what's happening.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 540)May include surrounding context.

md
>
> **Step 3e: Verify setup.** Use exec:
> ```
> ls -la ~/workspace/SOUL.md ~/workspace/USER.md ~/workspace/MEMORY.md ~/workspace/AGENTS.md ~/workspace/SECURITY.md ~/workspace/HEARTBEAT.md ~/workspace/WORKFLOWS.md ~/workspace/ESCALATION.md ~/workspace/VERSION.md
> ```
>
> **Total: 3-5 exec steps.** Each one is explained before execution so the user knows exactly what's happening.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Instructing the agent to recognize commands flexibly in natural language without clear boundaries creates overbroad matching. Because these commands lead to exec-driven inspection and modification of workspace files, accidental triggering can produce unauthorized or surprising actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.