Back to skill

Security audit

self-improving-coding

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed coding-learning logger with opt-in reminders; use its persistent logs and hooks deliberately, but I found no deceptive or destructive behavior.

Install this only if you want an agent to keep local coding-learning notes. Keep hooks project-scoped, avoid global installation, review .learnings before committing or sharing, and redact stack traces, file paths, source snippets, secrets, tokens, and private data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a passive logging/improvement aid, but it also instructs the agent to create files, install hooks, clone external content, and run helper scripts. That mismatch is dangerous because users or policy systems may approve it under a lower-risk mental model while it performs state-changing and potentially networked actions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 536)May include surrounding context.

md
Extracted skills are untrusted until a human reviews the generated `SKILL.md`. Do not keep or publish an extracted skill without explicit user approval.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill includes network-capable installation commands (git clone, clawdhub install) and hook/script execution guidance, but it declares no explicit tool or permission scope. In an agent environment, missing scope declarations can cause the skill to be loaded with broader-than-expected capabilities, making supply-chain or unintended external access risks harder to govern.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
72% confidence
Finding

The skill encourages writing persistent files under ~/.openclaw/workspace/.learnings, which survives beyond a single interaction and may accumulate debugging details over time. Even though it warns against logging secrets, persistent storage of error summaries, file paths, and code snippets can still create privacy and data retention risk in shared or synced environments.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill tells stackable mode not to read other skills' logs, yet separately instructs broad grep -r searches across .learnings/. In shared workspaces, that contradiction can lead to cross-skill data access, exposing unrelated logs that may contain sensitive debugging context, internal paths, or operational details.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The section title "Advanced Setup (With Error Detection)" implies the configuration enables error-detection behavior. However, the JSON shown on L511-L523 is effectively identical to the quick setup and only invokes scripts/activator.sh, while the actual error-detection capability is separately described as scripts/error-detector.sh on L525-L530.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 638)May include surrounding context.

md
### Ownership Rules
- This skill writes only to `.learnings/coding/` in stackable mode.
- Do not read other skill folders, their SKILL.md files, or their log entries.
- Standalone mode writes to this project's `.learnings/*.md` log files only.
- Stackable mode writes only to the namespaced folder above and must not rewrite other skills' log entries.
- Promotion into `AGENTS.md`, `SOUL.md`, `TOOLS.md`, `MEMORY.md`, rules, hooks, or generated skills is not a logging write. Show a reviewed diff and apply only after explicit user approval.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown file declares generic triggers such as code_review, static_analysis, and profiler, which can apply to many normal development contexts. It does not clarify when the skill should activate versus when these terms are merely being discussed, nor does it provide negative examples or scope limits.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/examples.md (reported line 247)May include surrounding context.

md
### Root Cause
Code uses `user?.addresses` (optional chaining for property access) but then calls
`.map()` directly on the result without checking if the chain resolved to undefined.

\`\`\`typescript
// Bug: addresses is undefined when user is null, .map() throws

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The hook matcher includes very common terms such as "fix," "debug," and especially "error," which can match many ordinary coding prompts and trigger the hook more often than users expect. In this skill context, the hook executes a local script on prompt submission, so overbroad activation increases the chance of unnecessary command execution, unwanted context injection, and accidental exposure of sensitive prompt or tool-output-derived data to the skill workflow.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 46)May include surrounding context.

2. Install the Hook (Optional)

bash
mkdir -p .openclaw/hooks
cp -r hooks/openclaw .openclaw/hooks/self-improving-coding

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
| Learning Type | Promote To | Example |
|---------------|------------|---------|
| Code style patterns | Style guide | "Always use early returns over nested if/else" |
| Recurring lint fixes | Lint rules | "Disallow mutable default arguments (B006)" |
| Reusable solutions | Code snippets library | "Retry with exponential backoff template" |
| Debugging workflows | Debug playbooks | "Race condition diagnosis in async code" |

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 62)May include surrounding context.

md
| Learning Type | Promote To | Example |
|---------------|------------|---------|
| Code style patterns | Style guide | "Always use early returns over nested if/else" |
| Recurring lint fixes | Lint rules | "Disallow mutable default arguments (B006)" |
| Reusable solutions | Code snippets library | "Retry with exponential backoff template" |
| Debugging workflows | Debug playbooks | "Race condition diagnosis in async code" |

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The verification step assumes users know what prompts match, but the document does not provide clear positive and negative examples beyond the regex snippets. That ambiguity can lead to unintended or inconsistent invocation across normal conversations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.