Back to skill

Security audit

self-improving-operations

Security checks for vulnerabilities and agentic risk

Overview

This skill persistently records operations learnings and offers opt-in reminders/scaffolding, and I found no hidden exfiltration, destructive behavior, or deceptive execution.

Install this only if you want persistent local operations logs and optional agent reminders. Keep hooks project-scoped, review any change to AGENTS.md/MEMORY/hooks/generated skills before applying it, avoid logging secrets or customer data, and do not let the skill read other skill folders unless you explicitly need that cross-linking.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/extract-skill.sh:97
Finding

Output Directory Boundary Bypass Through Symbolic Links

Content
View full analysis
"$SKILL_PATH/SKILL.md" << TEMPLATE ``` ### Technical Analysis The script attempts to constrain output to the current directory by rejecting absolute paths and paths containing `..`. These checks validate only the lexical path supplied by the caller. They do not resolve the path to its canonical filesystem destination or detect symbolic links in existing path components. Consequently, an accepted relative path can resolve outside the current working directory. For example, if `./skills` is a symbolic link to `/tmp/external-skills`, the default destination `./skills/example-skill/SKILL.md` passes both validation checks but resolves to `/tmp/external-skills/example-skill/SKILL.md`. Both `mkdir -p` and shell redirection follow symbolic links. The script therefore does not enforce its documented requirement that the output directory remain under the current directory. The existing-directory check reduces the likelihood of overwriting an already existing skill directory, but it does not prevent creation through a symlinked parent. It also does not provide protection against a time-of-check/time-of-use replacement of path components in a concurrently controlled workspace. ### Attack Path 1. An attacker controls or prepares the workspace in which the script will run. 2. The at ...[truncated 1571 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to capture operational learnings, but it also instructs creation of hooks, file scaffolding, and skill-extraction workflows that can modify workspace behavior beyond simple logging. This mismatch is dangerous because users or agents may grant trust based on the benign description while the skill persists automation and generates new artifacts with broader side effects.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 548)May include surrounding context.

md
Extracted skills are untrusted until a human reviews the generated `SKILL.md`. Do not keep or publish an extracted skill without explicit user approval.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill for identifying and capturing recurring incidents, toil, SLA breaches, and other operations-improvement signals. This script instead parses CLI arguments, creates directories, and writes a templated SKILL.md file for a new skill scaffold, which is a different developer tooling function rather than the stated operational analysis/capture behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill instructs creation of files under ~/.openclaw/workspace/.learnings, which is a persistent user-level location that can survive across sessions and affect future agent behavior. Persistent writes are risky because they expand the skill's influence beyond the current task and can silently accumulate operational context or prompt-shaping content over time.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 645)May include surrounding context.

md
### Ownership Rules
- This skill writes only to `.learnings/operations/` in stackable mode.
- It may read other skill folders for cross-linking, but should not rewrite their entries.
- Standalone mode writes to this project's `.learnings/*.md` log files only.
- Stackable mode writes only to the namespaced folder above and must not rewrite other skills' log entries.
- Promotion into `AGENTS.md`, `SOUL.md`, `TOOLS.md`, `MEMORY.md`, rules, hooks, or generated skills is not a logging write. Show a reviewed diff and apply only after explicit user approval.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 50)May include surrounding context.

openclaw hooks enable self-improving-operations

text

### 3. Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

For a skill whose stated purpose is to capture process bottlenecks, incident patterns, and toil-related operational insights, generating new directories and authoring SKILL.md files is not an obvious or declared requirement. This file-creation capability represents a separate repository-maintenance or content-generation function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown skill directs the agent to create and append to .learnings/ files in the project or workspace, which affects user data on disk. Although later sections mention not overwriting files and require approval for some promotions, the top-level description does not clearly warn users that normal use of the skill writes persistent files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.