Back to skill

Security audit

Self Reflection

Security checks for vulnerabilities and agentic risk

Overview

This self-reflection skill is understandable in purpose, but it asks users to run a recurring command from an unpinned external GitHub checkout and persist agent memory without enough safeguards.

Review this skill carefully before installing. Only use it if you are comfortable with a recurring agent workflow that reads and writes local memory, and install the executable from a pinned, reviewed commit or release instead of a mutable GitHub branch. Configure the memory path deliberately, inspect it regularly, and do not let agents log secrets, credentials, private prompts, customer data, or sensitive incident details.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:78
Finding

Unpinned Remote Payload Retrieval and Execution Through PATH

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 78-84
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
# Clone the skill
git clone https://github.com/hopyky/self-reflection.git ~/.openclaw/skills/self-reflection

# Add to PATH
ln -sf ~/.openclaw/skills/self-reflection/bin/self-reflection ~/bin/self-reflection

Technical Analysis

The installation instructions retrieve executable content from the mutable default branch of an external GitHub repository. They do not pin a reviewed commit or release and do not verify a cryptographic checksum or signature. The downloaded bin/self-reflection script is then exposed through the user's PATH.

The executable is absent from the audited artifact, so its implementation and behavior could not be verified. The documentation subsequently instructs the agent to invoke self-reflection check on every heartbeat and to execute additional subcommands when an alert occurs. Consequently, the effective executable payload can differ from the content reviewed in this audit.

This is best classified as remote payload retrieval and execution because mutable external code is fetched and subsequently invoked. Repository compromise, ownership changes, or malicious upstream revisions could alter the executed payload without modifying the audited package.

Attack Path

  1. An attacker compromises the upstream repository, its maintainer account, or otherwise causes its default branch to serve a malicious bin/self-reflection script.
  2. A user follows the documented git clone command without pinning a trusted commit.
  3. The user creates the documented symlink under ~/bin, making the remotely obtained script available through PATH.
  4. The OpenClaw heartbeat instructions invoke self-reflection check; alert handling may also invoke read and log.
  5. The malicious script executes with the permissions and environment of the agen ...[truncated 755 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the complete bin/self-reflection implementation in the reviewed skill package so that installed code matches audited code.
  2. If remote installation remains necessary, pin the clone or checkout to a specific reviewed commit hash rather than a mutable branch.
  3. Publish signed releases and verify a trusted cryptographic signature before installation.
  4. Publish an expected SHA-256 or stronger digest through a separately trusted channel and verify it before exposing the executable through PATH.
  5. Avoid symlinking unverified downloads into a PATH directory. Install only after explicit source review and integrity verification.
  6. Restrict execution to the minimum required user account and ensure the process does not receive unnecessary credentials or filesystem permissions.
  7. Add a reproducible release process and document the exact version, commit, signature verification procedure, and expected checksum.
  8. Audit the missing executable before enabling recurring heartbeat execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly promotes persistent storage of reflections, mistakes, and lessons learned in local files, but does not warn that those entries may contain sensitive operational details, prompts, credentials, incident notes, or private user data. In an agent environment, this kind of institutional memory can accumulate sensitive context over time and later be exposed through local compromise, backup leakage, overbroad file access, or accidental sharing.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 85)May include surrounding context.

Add to PATH

ln -sf ~/.openclaw/skills/self-reflection/bin/self-reflection ~/bin/self-reflection

Create config

cp ~/.openclaw/skills/self-reflection/self-reflection.example.json ~/.openclaw/self-reflection.json

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The configuration explicitly defines persistent memory_file and state_file paths, confirming that the skill stores session-derived content and timer state on disk across runs. In context, the memory file is intended to hold reflections about agent mistakes and fixes, which can include sensitive workflow, security, or user-context details and create a durable disclosure surface.

Content

Scanner excerpt · README.md (reported line 200)May include surrounding context.

Configuration

Create ~/.openclaw/self-reflection.json:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says the skill supports "continuous self-improvement" through "regular heartbeat-triggered reflections," but it does not clearly define the exact activation conditions or boundaries for when the skill should run. This is reinforced by later heartbeat instructions, making the trigger scope feel broad rather than tightly constrained.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The heartbeat instructions require the agent to run self-reflection check at each heartbeat and, on ALERT, to read past lessons and log insights without defining exclusions, approval requirements, or context limits. This can cause automatic invocation and autonomous stateful behavior in unrelated tasks, increasing the chance of prompt-scope creep, unwanted file reads/writes, and persistence of sensitive task details.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The configuration introduces persistent storage via memory_file and state_file, allowing reflections and state to survive across sessions. Session persistence is risky because an agent may unintentionally retain sensitive prompts, credentials, proprietary context, or behavioral instructions and reuse them later outside their original scope.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

Configuration

Create ~/.openclaw/self-reflection.json:

json
{

Static analysis

No suspicious patterns detected.