Back to skill

Security audit

self-improving-hr

Security checks for vulnerabilities and agentic risk

Overview

This skill is an HR learning logger with disclosed local files and optional reminder hooks; it has privacy-sensitive use cases but no hidden exfiltration, destructive behavior, or deceptive execution.

Install only where HR operations notes are appropriate. Keep .learnings local or gitignored, never store PII or raw HR records, avoid enabling PostToolUse unless you need it, and review any proposed changes to AGENTS.md, policies, hooks, or generated skills before applying them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as an HR learning/compliance aid, but substantial portions of the workflow expand into workspace modification, hook installation, and reusable skill generation. That mismatch can mislead users into granting trust or enabling automation they would not expect from the declared purpose, increasing the chance of unintended persistent changes.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 538)May include surrounding context.

md
Extracted skills are untrusted until a human reviews the generated `SKILL.md`. Do not keep or publish an extracted skill without explicit user approval.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill instructs creation of persistent files under ~/.openclaw/workspace/.learnings, which stores data across sessions. Even though the content is intended to be anonymized, persistence of HR-related operational notes in a user-scoped workspace increases the risk of long-term retention, accidental disclosure, or policy drift if sensitive details are later logged.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states hooks should not be installed at user/global scope, yet the instructions copy files into ~/.openclaw/hooks/..., which is user-home persistence. This contradiction can lead to broader-than-intended activation and long-lived behavioral changes outside the current project boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The hook matcher uses broad everyday HR-related terms that are likely to trigger in many normal conversations. Overbroad auto-activation increases prompt-surface area, causes unnecessary script execution, and may collect or process sensitive context more often than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The second hook example repeats the same broad matcher while also enabling PostToolUse processing, which compounds the chance of unnecessary activation. In practice this can increase exposure to command output and create noisy or privacy-invasive automation around sensitive HR workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented workflow goes beyond passive HR note capture into modifying broader workspace artifacts and generating new skills. Expanding write influence into agent instruction files and derivative skills increases the blast radius of mistakes or abuse, especially because those artifacts can shape future agent behavior across sessions.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

The ownership rules explicitly allow reading other skill folders for cross-linking, which introduces a skill-enumeration capability beyond the narrow HR logging function. While not directly destructive, cross-skill discovery can expose surrounding workspace structure and increase the available context for later misuse or data overcollection.

Content

Scanner excerpt · SKILL.md (reported line 643)May include surrounding context.

md
### Ownership Rules
- This skill writes only to `.learnings/hr/` in stackable mode.
- It may read other skill folders for cross-linking, but should not rewrite their entries.
- Standalone mode writes to this project's `.learnings/*.md` log files only.
- Stackable mode writes only to the namespaced folder above and must not rewrite other skills' log entries.
- Promotion into `AGENTS.md`, `SOUL.md`, `TOOLS.md`, `MEMORY.md`, rules, hooks, or generated skills is not a logging write. Show a reviewed diff and apply only after explicit user approval.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The matcher terms are broad enough to activate on many routine prompts containing words like 'policy', 'hire', or 'compliance', causing the hook to run outside narrowly intended HR-improvement scenarios. Because hook scripts execute automatically with agent permissions, overbroad triggering increases exposure to unnecessary context interception and unintended prompt injection into unrelated workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Although the text discourages global installation, the example still provides a ready-to-copy user-level hook using the same vague matcher, which could persist across all repositories and sessions. That combination of global scope plus broad activation materially increases the chance of unintended execution and cross-project exposure of sensitive prompt context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'minimal setup' reduces overhead but does not reduce trigger breadth, so the activator can still run on ordinary prompts containing ambiguous HR-adjacent terms. This creates unnecessary automatic execution and may inject reminders or process data in contexts not intended for HR logging, which is especially risky in workflows handling sensitive personnel information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Codex example propagates the same overbroad matcher into another agent ecosystem, expanding the number of environments where unintended automatic execution can occur. Reusing generic trigger terms across tools amplifies the likelihood of accidental activation and unnecessary processing of sensitive HR-related context.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 50)May include surrounding context.

openclaw hooks enable self-improving-hr

text

### 3. Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Static analysis

No suspicious patterns detected.