Back to skill

Security audit

ksdsl-skilll

Security checks for vulnerabilities and agentic risk

Overview

This skill is not overtly malicious, but it saves conversation and error details into persistent agent memory and can promote them into future instructions with broad optional hooks.

Install only if you are comfortable with the agent keeping durable notes about errors, corrections, and feature requests. Before enabling hooks or promotion, require manual review, redact secrets and private context, prefer project-scoped .learnings files, avoid automatic promotion into agent instruction files, and verify any referenced hook scripts from the installed package.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:16
Finding

Untrusted Conversation Content Can Poison Persistent Agent Instructions

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Third-Party Installation Can Introduce Executable Hook Scripts

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Creating persistent learning files under a user workspace establishes session-to-session storage for conversation-derived data. In the context of this skill, that persistence is the core mechanism, but it also means sensitive data or injected instructions can survive beyond the current task and influence future sessions.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions explicitly encourage promoting learnings into long-lived memory and agent instruction files, which can propagate user-provided or task-derived content across future sessions. Without sanitization, this creates a durable data-retention channel for sensitive information and can also amplify prompt-injection content into trusted memory locations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The error logging format directs the agent to store raw error messages, inputs, parameters, and environment details. Error output frequently contains secrets, tokens, file paths, proprietary code fragments, or personal data, so preserving it verbatim in markdown creates a clear confidentiality risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The hook example uses an empty matcher, which will fire on every user prompt and can cause pervasive prompt injection of the skill's behavior. In this skill, that increases the chance of indiscriminate logging and repeated propagation of sensitive or user-provided content into persistent files, even when the task does not warrant it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The second hook configuration repeats the same broad activation pattern, invoking the skill for all user prompts. Combined with PostToolUse automation, this can create a high-frequency pipeline that captures conversation and tool context broadly, expanding privacy and persistence risk.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The feature-request template asks to retain user context and requested capability, which can preserve unnecessary details about user goals, internal projects, or other sensitive context. While less acute than raw error logging, it still increases retention of potentially private information without clear minimization safeguards.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.