Back to skill

Security audit

self-improving-marketing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed marketing-learning logger with optional project-scoped reminder hooks and no evidence of hidden exfiltration, destructive behavior, or deceptive execution.

Install only if you want a marketing workflow that records local learning notes. Keep hooks project-scoped, leave PostToolUse disabled unless you intentionally want output scanning, review any generated skill before keeping it, and avoid logging customer PII, credentials, raw transcripts, or sensitive revenue data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to perform marketing analysis and remediation, but substantial behavior focuses on file creation, hook installation, and even skill extraction workflows that can modify agent configuration and generate new skills. That mismatch is dangerous because users may authorize it expecting passive analysis while it actually changes workspace state and agent behavior, increasing the chance of unintended persistence or supply-chain-style expansion.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 539)May include surrounding context.

md
Extracted skills are untrusted until a human reviews the generated `SKILL.md`. Do not keep or publish an extracted skill without explicit user approval.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The OpenClaw setup directs creation of files under ~/.openclaw/workspace, which is a persistent user-level location surviving individual sessions. Persistence is security-relevant because marketing logs, hooks, and derived instructions can accumulate sensitive business context and continue influencing future sessions beyond the original task scope.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

At L573 the table says Claude Code uses "Hooks (UserPromptSubmit, PostToolUse)" with detection "Automatic via error-detector.sh". But earlier hook guidance at L526 says "Leave PostToolUse disabled" and L533 describes error-detector.sh only as an available script, not something to enable by default. This is an active contradiction in the documentation about what detection is actually configured.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 640)May include surrounding context.

md
### Ownership Rules
- This skill writes only to `.learnings/marketing/` in stackable mode.
- Do not read other skill folders, their SKILL.md files, or their log entries.
- Standalone mode writes to this project's `.learnings/*.md` log files only.
- Stackable mode writes only to the namespaced folder above and must not rewrite other skills' log entries.
- Promotion into `AGENTS.md`, `SOUL.md`, `TOOLS.md`, `MEMORY.md`, rules, hooks, or generated skills is not a logging write. Show a reviewed diff and apply only after explicit user approval.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states that the hook scripts 'only output text' and 'don't modify files or run commands,' but the configured hooks are explicitly of type 'command' and invoke shell scripts. This misleading assurance can cause operators to underestimate the trust boundary and install executable hooks that run with agent privileges, increasing the risk of unsafe deployment or review bypass.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The integration instructs users to install a persistent hook under the agent's hooks directory, which causes skill behavior to survive across sessions and automatically run on lifecycle events. Even though persistence is expected for integrations, this increases attack surface because compromised or overly permissive hook logic could execute repeatedly without a fresh user decision each session.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 46)May include surrounding context.

2. Install the Hook (Optional)

bash
mkdir -p .openclaw/hooks
cp -r hooks/openclaw .openclaw/hooks/self-improving-marketing

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The 'Marketing-Specific Detection Triggers' table lists generic conditions such as 'CTR drop detected', 'Conversion rate decline', and 'Audience behavior shifted' without defining thresholds, context, or when the skill should not activate. In a markdown integration guide, this can create ambiguous invocation behavior because many routine analytics fluctuations could match these phrases.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest claims the skill captures messaging misses, channel underperformance, audience drift, attribution gaps, and similar marketing signals for continuous improvement. This script only parses CLI arguments, validates paths, and emits a template SKILL.md file; it performs no campaign analysis, attribution checking, sentiment evaluation, or related marketing diagnostics.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill focused on detecting and improving marketing issues such as CTR drops, attribution gaps, and brand inconsistency. This script instead creates new skill directories and writes SKILL.md scaffolds, a repository-maintenance/code-generation capability unrelated to performing marketing improvement analysis itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to create and append to workspace files early and repeatedly, but does not front-load a strong warning that it will modify local project data. Silent or lightly disclosed writes are risky because they can persist potentially sensitive operational details or alter repositories in contexts where the user expected advisory behavior only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.