Back to skill

Security audit

ilc

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed entrypoint for installing and using an ILC command-line tool, with ordinary supply-chain caution needed for the external package and GitHub source it points to.

Install only if you trust the ILC publisher and referenced repository. Prefer an isolated virtual environment, review the installer or source before running it, keep invite material private, and understand that enrollment and identity commands create local state for the ILC tool.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:45
Finding

Unverified Third-Party Code Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45 and 54–60
Vulnerability Type: Remote code retrieval through unverified package and source installation
Risk Level: Medium

Vulnerable Code:

bash
pip install ilc-core==0.4.19
ilc version   # should report 0.4.19
bash
git clone https://github.com/jamison/ilc.git
cd ilc
python3 --version   # must be Python 3.10+
python3 -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade pip
python -m pip install -e ".[openclaw-hosted]"

Technical Analysis

The skill directs users to retrieve and install executable code from PyPI and a remote Git repository, but none of that executable code is included in the audited artifact. Consequently, the behavior of package installation hooks, build-system configuration, optional dependencies, and transitive dependencies cannot be verified from this project.

The PyPI package is version-pinned, which reduces accidental version drift, but no package hashes or signatures are verified. The source installation is more exposed because git clone retrieves the repository's mutable default branch rather than a reviewed immutable commit or cryptographically verified signed tag. The subsequent editable installation can execute attacker-controlled build hooks and resolve additional dependencies.

This finding does not establish that the referenced package or repository is malicious. It identifies an unsafe trust boundary through which upstream compromise or later repository modification could introduce executable payloads after this skill has been reviewed.

Attack Path

  1. An attacker compromises the referenced PyPI release, repository, maintainer account, build pipeline, or a resolved transitive dependency.
  2. The attacker adds malicious package initialization, build-backend logic, installation hooks, or dependency content.
  3. A user follows the installation commands in SKILL.md ...[truncated 929 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin source installations to a reviewed full commit hash or a cryptographically verified signed release tag rather than the mutable default branch.
  2. Publish a locked dependency manifest containing cryptographic hashes for all direct and transitive packages.
  3. Use pip's hash-checking mode, such as --require-hashes, with an audited requirements file.
  4. Provide package provenance, signatures, or attestations and document the exact verification procedure users must perform before installation.
  5. Vendor the executable implementation into the reviewed artifact when practical, allowing its installation and runtime behavior to be audited together with the skill.
  6. Avoid the unnecessary pip self-upgrade during installation, or pin and verify the intended pip distribution.
  7. Recommend installation in an isolated, non-privileged virtual environment without sensitive environment variables or credentials.
  8. Audit build-system hooks, optional openclaw-hosted dependencies, and all transitive dependencies before publishing approved hashes.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
ILC is an evidence-first graph protocol for human-AI civilization: a shared truth ledger where claims, validations, refutations, revisions, links, and epoch commitments become content-addressed graph objects.

The goal is practical: make knowledge work attributable, challengeable, reusable, and eventually economically accountable without asking a central operator to decide what is true. Humans and AI agents can contribute to the same graph, inspect the same evidence trail, and coordinate through sidecars that do not become privileged protocol authorities.

This is the canonical ClawHub entrypoint for ILC. It points to the public source, local install path, public-RC status, Genesis contact channel, and OpenClaw local capture route.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

The source-level local-capture boundary remains available for agents that need to inspect the exact OpenClaw behavior:

text
skills/ilc-openclaw-local-capture/SKILL.md

That boundary covers local private capture, local classification, private non-binding ECU estimates, invite-gated setup, ConsentGate submission intent, and idle-capacity task offers.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

The source-level local-capture boundary remains available for agents that need to inspect the exact OpenClaw behavior:

text
skills/ilc-openclaw-local-capture/SKILL.md

That boundary covers local private capture, local classification, private non-binding ECU estimates, invite-gated setup, ConsentGate submission intent, and idle-capacity task offers.

Static analysis

No suspicious patterns detected.