Back to skill

Security audit

Knowledge Distillation

Security checks for vulnerabilities and agentic risk

Overview

This skill creates a local Markdown draft to help distill OpenClaw memory and session materials, with no evidence of hidden network access, credential use, persistence, or destructive behavior.

Install only if you are comfortable having the agent read local memory, session logs, notes, and reports and write a new distilled Markdown file. Review the generated file before reusing or sharing it because it may contain sensitive conclusions drawn from internal materials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents an end-user skill whose primary function is to analyze workspace-native materials and generate distilled knowledge output. The actual code chunk does not do that work. It is a developer-oriented test harness for the skill package. While one test verifies that distill.sh can create a dated Markdown file, this script itself mainly validates packaging, metadata, directory structure, and script syntax. That is a materially different primary purpose from the declared behavior, so this code chunk does not accurately represent the described skill behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
bash scripts/distill.sh ./memory ./dist

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
bash scripts/distill.sh ./memory ./dist

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
bash scripts/distill.sh ./memory ./dist

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest sets "language": "en", which can indicate a fixed language/locale constraint. The file also includes Chinese trigger keywords, but there is no natural-language indication that users may choose their preferred language or that English-only behavior is justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file explicitly states that output must be a dated Markdown file and specifies the filename format, which implies a filesystem write. Under the markdown-file criteria for SQP-2, behaviors that affect user data or system state should include a warning or disclosure, but no user-facing warning about file creation is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template mixes English headings with required Chinese output fields such as '新的知识点' and '本轮蒸馏结论', which implicitly constrains generated output to Chinese. The file does not state that Chinese is optional, user-selected, or required for a region-specific purpose, so it appears to impose a language choice without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The report-heavy and follow-up templates continue to require Chinese section names and bullet labels, effectively enforcing a locale across multiple output formats. Because no language-selection instruction or justification is provided, this conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.