T01 · Skill Instruction Hijacking
- Location
SKILL.md:5- Finding
Global Agent Behavior and Response Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a self-check workflow, but it also requires persistent behavior logging and cross-agent memory sharing that users should review carefully before installing.
Install only if you are comfortable with an agent persistently logging task summaries, inferred preferences, and self-check records under ~/.openclaw, and with remembered content being synchronized to another agent through a Bitable relay. Prefer a version that makes logging and cross-agent sync explicit, opt-in, scoped, and deletable.
SKILL.md:5Global Agent Behavior and Response Hijacking
SKILL.md:158Persistent Collection of Conversation Content and Inferred User Preferences
SKILL.md:243Uncontrolled Cross-Agent Memory Propagation Through an External Relay
The cross-agent memory sync section explicitly instructs writing remembered user content to local files and an external relay, then making it available for other agents to internalize, without warning, consent, access controls, or scope restrictions. This is dangerous because it enables broad propagation of potentially sensitive user data across systems and agents, increasing exposure, misuse, and compliance risk.
The skill directs the agent to write remembered user content to local files and a relay for other agents to consume, which is a concrete data persistence and sharing instruction. In this context, the skill is especially dangerous because it is described as required for all tasks, making broad collection and cross-agent dissemination the default behavior.
This section mandates persistent behavior tracking, including storing conversation summaries, user feedback, and inferred preferences, even when that data is not necessary for task completion. That creates unjustified profiling and retention of potentially sensitive user information without consent, transparency, or minimization, which materially increases privacy and misuse risk.
The markdown requires persistent logging of task details and inferred user preferences without any privacy notice, consent flow, or limitation on what may be inferred and stored. This is dangerous because it normalizes silent profiling and long-term retention of potentially sensitive behavioral data for every task.
The skill explicitly instructs recording user content and inferred preferences into persistent memory files for every task. That creates durable surveillance-style storage of behavioral data, increasing the chance of privacy harm, unauthorized reuse, and cross-session profiling beyond what a self-check feature should do.
The skill requires cross-agent memory synchronization through multiple stores and an external relay, which is unrelated to a normal self-check function and broadens data exposure. Replicating user-provided information across systems increases the attack surface, creates unnecessary persistence, and makes containment or deletion much harder.
This section propagates user-provided information into multiple memory stores and an external relay without any privacy warning or consent mechanism. Multi-destination replication magnifies confidentiality, integrity, and retention risks because more systems and agents can access or mishandle the data.
Cross-agent memory sync requires propagating remembered user instructions across multiple stores and retrying until successful, which encourages over-retention and broad dissemination of user data. This makes accidental leakage, inconsistent deletion, and unauthorized downstream use significantly more likely.
The skill mandates behavior tracking that stores conversation summaries, user feedback, and inferred preferences before delivery, but provides no user-facing notice, consent flow, retention limit, or data minimization guidance. This creates a privacy and compliance risk because an agent following the skill may persist sensitive user data beyond what is necessary for the task.
This instruction creates an explicit requirement to retain conversation summaries, feedback, and inferred preferences as part of normal operation. Because the retention is mandatory and not bounded by necessity, consent, or lifecycle controls, it increases the risk of unnecessary collection and storage of personal or sensitive information.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
- ❌ Deliver without multi-dimensional thinking
- ❌ Self-check your own work
- ❌ Single-path without comparison
- ❌ Report without verification
- ❌ Wait for user to find problems
- ❌ Deliver without behavior tracking
The skill content is written entirely in Chinese and includes fixed Chinese output structures and phrases such as required status blocks and trigger wording, with no indication that the user can choose another language. This imposes a language/locale constraint without opt-in or documented justification.
The role table says the checking agent validates without modifying, and explicitly forbids executors from checking themselves. Later sections, however, require every task delivery to include the same agent's own multidimensional thinking record, self-check punch card, and behavior-tracking append before delivery, which collapses execution and checking into one actor.
A self-check skill should govern reasoning quality, not force writes to persistent memory locations. By directing the agent to create directories and log every task to disk, the skill expands its behavior into data collection and storage, which can capture sensitive task context beyond the user's expectations.
The skill instructs the agent to write self-check logs to disk for every task without informing the user that task content and reasoning artifacts are being persistently stored. Even if intended for quality control, undisclosed disk logging can capture sensitive prompts, internal deliberation, and identifiers in a way users would not reasonably expect.
Persisting self-check contents to disk for every interaction stores task context and reasoning artifacts across sessions, which can expose sensitive information and create unnecessary long-term records. The danger is amplified because the logging is mandatory and not framed as optional or administrator-controlled.
The command to create a persistent directory under the user's home path is a session-persistence mechanism that enables later storage of task-related logs. While creating a directory is not dangerous in isolation, within this skill it serves as infrastructure for undisclosed long-term retention of interaction data, making the overall pattern security-relevant.
目录不存在则先创建:
mkdir -p ~/.openclaw/workspace-taizi/memory/self-check-logs
Several core checklist prompts are presented only in Chinese, and the memory trigger phrase is also Chinese-specific. Because the README does not state that the skill is intended only for Chinese-language use or offer an opt-in language choice, this can amount to an undocumented language/locale constraint.
No suspicious patterns detected.