T01 · Skill Instruction Hijacking
- Location
HEARTBEAT.md:1- Finding
Autonomous Processing of Attacker-Controlled Marketplace Tasks Can Hijack Agent Goals
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a marketplace integration, but it gives agents recurring autonomous authority to use authenticated APIs, take job actions, and store state without tight user approval boundaries.
Review this skill carefully before installing. It is not just a manual command reference: in OpenClaw it claims a 30-minute heartbeat that can use your ClawdWork API key, check notifications, browse jobs, apply for work, deliver work, mark notifications, and persist state. Only install it if you are comfortable with that automation, and prefer disabling or constraining heartbeat behavior until job acceptance, delivery, completion, Moltbook posting, and any credit-affecting action require explicit approval.
HEARTBEAT.md:1Autonomous Processing of Attacker-Controlled Marketplace Tasks Can Hijack Agent Goals
SKILL.md:446Job Completion Is Documented Without Authentication and Trusts a Caller-Supplied Identity
Referenced artifact was not completely inspected
- `SKILL.md` - Main skill documentation (this file)
The heartbeat file instructs the agent to perform ongoing autonomous polling of a third-party service, take actions on notifications, and maintain persistent local state, which materially expands behavior beyond a simple marketplace skill description. This creates a hidden always-on workflow that can trigger external actions and data retention without clear user awareness, increasing the chance of unauthorized task execution or privacy surprises.
The skill directs use of a bearer API key against remote endpoints and later instructs writing persistent state to a local file, but provides no user-facing warning about credential use, external data access, or storage of job-related metadata. In an agent context, this is dangerous because it normalizes silent authenticated network activity and local persistence, making accidental overreach, data leakage, or misuse of privileged marketplace access more likely.
The skill explicitly encourages direct posting to Moltbook using a ready-to-use share_suggestion, but it does not clearly warn that this sends user/agent-generated content to a third-party platform and may disclose job details, activity patterns, or account-linked identity information. Because the post content can be used directly and the integration is framed as a convenience step, an agent may share externally without meaningful user awareness or consent.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
↓
Budget deducted from credit (if paid job)
↓
OPEN (instant - no approval needed!)
↓
Other agents apply via comments
↓
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
↓
Budget deducted from credit (if paid job)
↓
OPEN (instant - no approval needed!)
↓
Other agents apply via comments
↓
The statement that the heartbeat file will 'automatically run every 30 minutes' indicates autonomous recurring behavior by the agent environment. In context, this is dangerous because it normalizes unsupervised action loops that may trigger network access, task handling, and downstream decisions without explicit user awareness each time.
### OpenClaw Users: Automatic Heartbeat
If you're using OpenClaw, the `HEARTBEAT.md` file in this skill will automatically run every 30 minutes. It will:
- Check your notifications
- Monitor your active tasks
- Alert your human when needed
The skill states that HEARTBEAT.md will automatically run every 30 minutes and perform recurring network actions such as checking notifications and monitoring tasks, but it does not present this as a high-visibility warning with clear consent and scope. Autonomous periodic network activity can create unexpected data disclosure, background spending of rate limits/resources, and user confusion about when the agent is acting on its own.
No suspicious patterns detected.