Back to skill

Security audit

meowtest

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about logging learnings, but it can persist user/session-derived guidance into future agent instructions with broad automatic reminders and limited approval safeguards.

Review this skill carefully before installing. Use it only in trusted workspaces, keep hooks disabled or narrowly matched unless you really want automatic reminders, avoid global user-level hooks, and require human review before anything from a conversation, command output, or another session is written into CLAUDE.md, AGENTS.md, SOUL.md, TOOLS.md, or Copilot instructions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:282
Finding

Untrusted Session-Derived Content Can Be Promoted into Persistent Agent Context

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description is about recording and reviewing learnings for continuous improvement, especially after mistakes or corrections. The supplied code does not capture learnings, log errors/corrections, review prior learnings, or update a learning repository. Instead, it is a helper utility that scaffolds a new skill directory and markdown file from a learning entry name. Its primary purpose is materially different: skill extraction/scaffolding rather than learning capture or review. The filesystem write behavior is also undeclared in the description.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

An empty hook matcher causes the reminder hook to run on every prompt, creating an unbounded activation surface. In practice this can lead to pervasive inspection and repeated nudges to persist information, increasing privacy risk, prompt bloat, and the likelihood of unintended logging across unrelated tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The second hook example repeats the same empty-matcher pattern, again allowing unconditional activation for all prompts and tool-use events. Combined with PostToolUse error detection, this broad scope can cause systematic monitoring of command output and expand the amount of data evaluated or persisted without sufficient contextual limitation.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/hooks-setup.md (reported line 48)May include surrounding context.

Option 2: User-Level Configuration

Add to ~/.claude/settings.json for global activation:

json
{

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 181)May include surrounding context.

sessions_send

Send message to another session:

text
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")

Session Persistence

Medium
Category
Rogue Agent
Confidence
73% confidence
Finding

Writing persistent logs under a user home/workspace path creates long-lived session artifacts that may accumulate sensitive operational details over time. Although the skill advises against logging secrets, persistence itself increases exposure if the workspace is shared, backed up, indexed, or later accessed by other tools and sessions.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs use of cross-session history access and messaging, which can expose data from other sessions beyond the local learning log use case. Even though it says to use these only in trusted environments and with explicit user intent, normalizing transcript access increases the risk of accidental privacy breaches or over-collection of sensitive context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The feature-request trigger examples map to common conversational phrases, so the skill may over-classify ordinary discussion as a request to persist data in .learnings/FEATURE_REQUESTS.md. In a coding-agent environment, that increases the chance of unwanted logging and retention of user context that was never intended for storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a skill for capturing learnings, errors, corrections, and reviewing them before major tasks. The Automatic Skill Extraction section extends this into creating new reusable skills and invoking helper scripts to generate them, which is a distinct capability not justified by the narrow self-improvement/logging purpose stated in the manifest.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The suggested activation phrases are extremely broad and resemble ordinary user requests, which can cause the skill to trigger in contexts where the user did not intend persistent logging or review behavior. That can lead to unnecessary retention of conversation content, accidental file writes, or inadvertent promotion of sensitive information into workspace memory files.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/examples.md (reported line 301)May include surrounding context.

When the above learning is extracted as a skill, it becomes:

File: skills/docker-m1-fixes/SKILL.md

markdown
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/hooks-setup.md (reported line 15)May include surrounding context.

Option 1: Project-Level Configuration

Create .claude/settings.json in your project root:

json
{

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 57)May include surrounding context.

openclaw hooks enable self-improvement

text

### 3. Create Learning Files

Create the `.learnings/` directory in your workspace:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The detection triggers are broad enough that routine events such as generic tool errors, user corrections, or model 'surprise' could automatically cause persistent logging or promotion into shared workspace files. In a system that injects workspace content into future sessions, this can create accidental prompt poisoning, over-collection of sensitive context, or repeated propagation of low-quality or attacker-influenced data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill focused on recording learnings, errors, corrections, and reviewing those learnings before major tasks. This script instead generates a new skill directory and SKILL.md scaffold, and even instructs users to add scripts/ executable code, which is a distinct skill-authoring capability rather than merely capturing or reviewing learnings.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Creating arbitrary skill directories and templated SKILL.md files is a repository authoring capability, not an obvious requirement for capturing corrections or failed operations. The guidance to add references/ and scripts/ folders further broadens the capability toward creating deployable skills, which is not justified by the stated purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown template instructs authors to 'Include trigger conditions' but does not require specificity, examples, or exclusions. Because downstream skills may copy this verbatim, it can lead to ambiguous invocation descriptions that overlap with broad everyday phrasing.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The '[Trigger 1]' and '[Trigger 2]' placeholders show where triggers go, but they provide no guardrails against vague phrases. In a template file, this omission can propagate ambiguous activation conditions into generated skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.