Back to skill

Security audit

Self-Check System v7

Security checks for vulnerabilities and agentic risk

Overview

The skill is a self-check workflow, but it also requires persistent behavior logging and cross-agent memory sharing that users should review carefully before installing.

Install only if you are comfortable with an agent persistently logging task summaries, inferred preferences, and self-check records under ~/.openclaw, and with remembered content being synchronized to another agent through a Bitable relay. Prefer a version that makes logging and cross-agent sync explicit, opt-in, scoped, and deletable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:5
Finding

Global Agent Behavior and Response Hijacking

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:158
Finding

Persistent Collection of Conversation Content and Inferred User Preferences

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:243
Finding

Uncontrolled Cross-Agent Memory Propagation Through an External Relay

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (18)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The cross-agent memory sync section explicitly instructs writing remembered user content to local files and an external relay, then making it available for other agents to internalize, without warning, consent, access controls, or scope restrictions. This is dangerous because it enables broad propagation of potentially sensitive user data across systems and agents, increasing exposure, misuse, and compliance risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the agent to write remembered user content to local files and a relay for other agents to consume, which is a concrete data persistence and sharing instruction. In this context, the skill is especially dangerous because it is described as required for all tasks, making broad collection and cross-agent dissemination the default behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section mandates persistent behavior tracking, including storing conversation summaries, user feedback, and inferred preferences, even when that data is not necessary for task completion. That creates unjustified profiling and retention of potentially sensitive user information without consent, transparency, or minimization, which materially increases privacy and misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The markdown requires persistent logging of task details and inferred user preferences without any privacy notice, consent flow, or limitation on what may be inferred and stored. This is dangerous because it normalizes silent profiling and long-term retention of potentially sensitive behavioral data for every task.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs recording user content and inferred preferences into persistent memory files for every task. That creates durable surveillance-style storage of behavioral data, increasing the chance of privacy harm, unauthorized reuse, and cross-session profiling beyond what a self-check feature should do.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill requires cross-agent memory synchronization through multiple stores and an external relay, which is unrelated to a normal self-check function and broadens data exposure. Replicating user-provided information across systems increases the attack surface, creates unnecessary persistence, and makes containment or deletion much harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This section propagates user-provided information into multiple memory stores and an external relay without any privacy warning or consent mechanism. Multi-destination replication magnifies confidentiality, integrity, and retention risks because more systems and agents can access or mishandle the data.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Cross-agent memory sync requires propagating remembered user instructions across multiple stores and retrying until successful, which encourages over-retention and broad dissemination of user data. This makes accidental leakage, inconsistent deletion, and unauthorized downstream use significantly more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates behavior tracking that stores conversation summaries, user feedback, and inferred preferences before delivery, but provides no user-facing notice, consent flow, retention limit, or data minimization guidance. This creates a privacy and compliance risk because an agent following the skill may persist sensitive user data beyond what is necessary for the task.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This instruction creates an explicit requirement to retain conversation summaries, feedback, and inferred preferences as part of normal operation. Because the retention is mandatory and not bounded by necessity, consent, or lifecycle controls, it increases the risk of unnecessary collection and storage of personal or sensitive information.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 112)May include surrounding context.

md
- ❌ Deliver without multi-dimensional thinking
- ❌ Self-check your own work
- ❌ Single-path without comparison
- ❌ Report without verification
- ❌ Wait for user to find problems
- ❌ Deliver without behavior tracking

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill content is written entirely in Chinese and includes fixed Chinese output structures and phrases such as required status blocks and trigger wording, with no indication that the user can choose another language. This imposes a language/locale constraint without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The role table says the checking agent validates without modifying, and explicitly forbids executors from checking themselves. Later sections, however, require every task delivery to include the same agent's own multidimensional thinking record, self-check punch card, and behavior-tracking append before delivery, which collapses execution and checking into one actor.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A self-check skill should govern reasoning quality, not force writes to persistent memory locations. By directing the agent to create directories and log every task to disk, the skill expands its behavior into data collection and storage, which can capture sensitive task context beyond the user's expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to write self-check logs to disk for every task without informing the user that task content and reasoning artifacts are being persistently stored. Even if intended for quality control, undisclosed disk logging can capture sensitive prompts, internal deliberation, and identifiers in a way users would not reasonably expect.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Persisting self-check contents to disk for every interaction stores task context and reasoning artifacts across sessions, which can expose sensitive information and create unnecessary long-term records. The danger is amplified because the logging is mandatory and not framed as optional or administrator-controlled.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The command to create a persistent directory under the user's home path is a session-persistence mechanism that enables later storage of task-related logs. While creating a directory is not dangerous in isolation, within this skill it serves as infrastructure for undisclosed long-term retention of interaction data, making the overall pattern security-relevant.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

目录不存在则先创建:

bash
mkdir -p ~/.openclaw/workspace-taizi/memory/self-check-logs

6.2 打卡内容模板

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Several core checklist prompts are presented only in Chinese, and the memory trigger phrase is also Chinese-specific. Because the README does not state that the skill is intended only for Chinese-language use or offer an opt-in language choice, this can amount to an undocumented language/locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.