Back to skill

Security audit

Learned Workflows

Security checks for vulnerabilities and agentic risk

Overview

The skill is a small Markdown workflow note, but it persists a copied untrusted UI request as reusable guidance that could steer future agent sessions.

Review and remove the copied sender metadata and one-off layout request before installing. Keep only short, task-agnostic workflow rules that were intentionally approved for reuse across sessions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:9
Finding

Untrusted Conversation Content Embedded as a Skill Instruction

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 9
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Complete Vulnerable Snippet:

markdown
- Sender (untrusted metadata): ```json { "label": "openclaw-control-ui", "id": "openclaw-control-ui" } ``` [Wed 2026-05-06 17:48 EDT] Minor layout modifications: I like the stats card row, but for the listing I prefer a list view (datatable view) with pagination instead of a card list layout

Technical Analysis

The skill stores untrusted sender metadata and a task-specific UI modification request directly within its authoritative Workflow section. The text explicitly identifies its source as untrusted, but it is nevertheless formatted as a workflow bullet that an agent may interpret as an instruction whenever the skill is loaded.

This mixes untrusted transcript content with trusted skill instructions and creates a skill instruction-hijacking condition. An attacker able to influence content that is persisted into this file could substitute the benign layout request with instructions that alter the agent's current objective, request unrelated changes, or attempt to weaken operational safeguards.

Attack Path

  1. An attacker submits a crafted message through a source represented as sender metadata.
  2. The message is copied into SKILL.md under the authoritative Workflow heading without validation or sanitization.
  3. The skill persists as part of the project and is loaded during a later agent session.
  4. The agent interprets the persisted attacker-controlled text as workflow guidance.
  5. The agent may perform unrelated or unauthorized actions using whatever tools and permissions are already available in that session.

Impact Assessment

Exploitation can alter the agent's current task goals and resulting code or output. The affected scope includes sessions in which this skill is loaded and repositories or resources acces ...[truncated 397 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove line 9 from the skill because it contains task-specific, untrusted transcript content rather than reusable workflow guidance.
  2. Maintain a strict trust boundary between skill instructions and messages, sender metadata, logs, or conversation transcripts.
  3. If workflow learning is supported, allow only sanitized, task-agnostic rules through a structured schema and explicit human approval.
  4. Reject or quarantine candidate workflow entries containing sender fields, timestamps, quoted conversations, role markers, or imperative requests copied from user messages.
  5. Store provenance and trust labels separately from executable or authoritative instruction text.
  6. Review existing learned workflow files for similar persisted transcript content before loading them into agent sessions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.