Back to skill

Security audit

Agent Nurture Framework (OpenClaw Edition)

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about its self-learning goal, but it asks agents to preserve memories and change future skills without a consistently mandatory human review step.

Install only if you intentionally want an agent to manage persistent learning records and propose skill changes. Require explicit human approval for every memory write, MEMORY.md change, skill creation/update, archive, or deletion, and avoid storing secrets or sensitive session details in durable memory.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:39
Finding

Persistent Agent Memory and Skill Modification Without Mandatory Operator Approval

Content
View full analysis
_learned.md ### Stage 2: Verify (Experimental Verification) - Verify in a notebook or actual environment - Turn "knowledge from books" into "usable knowledge" - Output: verified patterns and discovered pitfalls ### Stage 3: Apply (Practical Application) - Solve real problems - Kaggle competitions, Moltbook posts, and project tasks - Output: performance metrics, discovered bugs, and workflow insights ### Stage 4: Extract (Knowledge Crystallization) - Extract reusable patterns from session experience - Create or update Skill files - Trigger conditions: non-trivial debugging, workarounds, trial-and-error success, and configuration insights ``` Related provenance and validation template: ```yaml knowledge_origin: type: agent-originated validated_by: [Operator Name] # @handle or "self" (self-validation) validation_date: [YYYY-MM-DD] notes: "The agent discovered this in practice, and the operator confirmed its novelty" ``` Related approval option: ```markdown **Operator confirmation**: ☐ Yes ☐ N/A (agent-originated self-validation) ``` The framework also instructs the agent to use shared notebooks as learning input: ```markdown 1. Read documentation/books → create a memory file 2. Someone shares a notebook → verify understanding 3. Discover a pattern or pitfall absent from the documentation → extract it as a Skill 4. Crystallize it as an L1 or L2 Skill → use it for future tasks ``` ### Technical Analysis The Skill establishes a workflow ...[truncated 3173 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill metadata and body are written primarily in Chinese with some English terminology, and there is no statement that the user may choose another language. Under the policy for natural-language violations, forcing a specific language or locale without opt-in is reportable unless the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest-style description says to use the skill when systematizing learning, extracting reusable skills from experience, managing skill fragmentation, measuring growth, or helping new agents. These are broad, high-level situations that overlap with many ordinary agent activities, and the file does not provide a bounded trigger list or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

This duplicate finding points to shell commands and workflow guidance that normalize long-term storage of memory artifacts in ~/.openclaw/workspace/memory. In context, the framework is designed to crystallize and preserve knowledge across sessions, which makes persistence more dangerous because sensitive operational context may be retained and later surfaced or acted upon.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

md
# 按类别统计技能
ls ~/.openclaw/workspace/skills/ | sed 's/-.*//' | sort | uniq -c | sort -rn

# Memory文件数(应该循环:create → crystallize → archive)
ls ~/.openclaw/workspace/memory/*.md | wc -l

# 过期memory文件(2周以上未更新)

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

This duplicate finding points to shell commands and workflow guidance that normalize long-term storage of memory artifacts in ~/.openclaw/workspace/memory. In context, the framework is designed to crystallize and preserve knowledge across sessions, which makes persistence more dangerous because sensitive operational context may be retained and later surfaced or acted upon.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

md
# 按类别统计技能
ls ~/.openclaw/workspace/skills/ | sed 's/-.*//' | sort | uniq -c | sort -rn

# Memory文件数(应该循环:create → crystallize → archive)
ls ~/.openclaw/workspace/memory/*.md | wc -l

# 过期memory文件(2周以上未更新)

Static analysis

No suspicious patterns detected.