Back to skill

Security audit

self-improving-sales

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed sales-learning logger with optional local reminder hooks; its persistent sales notes need care, but the behavior is scoped and user-controlled.

Install only from ClawdHub or a reviewed pinned commit. Keep hooks project-scoped, start with the UserPromptSubmit reminder only, and review hook scripts before enabling PostToolUse. Treat `.learnings` as potentially sensitive sales data: anonymize customers, avoid exact deal terms and raw transcripts, and require an explicit reviewed diff before changing AGENTS.md, MEMORY.md, hooks, rules, or generated skills.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a runtime sales-analysis capability that detects or captures recurring sales patterns and operational issues based on deal and forecast events. The supplied code does not inspect deals, objections, pricing, forecasts, competitors, discounts, or win/loss data at all. Instead, it is a command-line helper that generates a markdown scaffold for a new sales skill. Its primary purpose is materially different: local file and directory creation for skill authoring. The filesystem-writing behavior is also undeclared, and the trigger model is unrelated to the listed sales conditions. Therefore, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 536)May include surrounding context.

md
Extracted skills are untrusted until a human reviews the generated `SKILL.md`. Do not keep or publish an extracted skill without explicit user approval.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill instructs creation of persistent files under ~/.openclaw/workspace/.learnings, which survives the current session and can accumulate sensitive sales intelligence over time. Even though the content warns against storing PII, persistent storage of deal context, competitor intelligence, pricing issues, and forecast data increases exposure if the workspace is shared, synced, or later accessed by other tools or users.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Lines L103-L104 explicitly instruct users not to copy the hook to ~/.openclaw/hooks/ because that path is user-global. However, L106-L107 then creates .openclaw/hooks and copies hooks/openclaw into .openclaw/hooks/self-improving-sales, which contradicts the stated safety guidance and appears to implement the prohibited install path.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 644)May include surrounding context.

md
### Ownership Rules
- This skill writes only to `.learnings/sales/` in stackable mode.
- Do not read other skill folders, their SKILL.md files, or their log entries.
- Standalone mode writes to this project's `.learnings/*.md` log files only.
- Stackable mode writes only to the namespaced folder above and must not rewrite other skills' log entries.
- Promotion into `AGENTS.md`, `SOUL.md`, `TOOLS.md`, `MEMORY.md`, rules, hooks, or generated skills is not a logging write. Show a reviewed diff and apply only after explicit user approval.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example feature proposes monitoring competitor websites and reviews, tracking job postings, and aggregating competitor mentions from call transcripts, but it does not mention consent, lawful basis, data minimization, retention, or platform terms-of-service constraints. In a sales-improvement skill, that omission can normalize broad collection and processing of third-party and customer-derived data in ways that create privacy, compliance, and contractual risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The matcher uses broad sales-related keywords such as 'deal,' 'pricing,' and 'competitor,' which are common in many prompts and can trigger the hook unexpectedly. In a hook system that auto-executes scripts, overbroad triggering increases exposure of sensitive context to the script and creates unnecessary command execution opportunities across routine workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states that the scripts 'only output text' and 'don't modify files or run commands,' but the hook configuration explicitly invokes shell scripts via a command hook. That mismatch can cause operators to underestimate execution risk and approve hooks that run with full agent permissions, increasing the chance of unsafe deployment or abuse if the referenced scripts are modified.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 46)May include surrounding context.

2. Install the Hook (Optional)

bash
mkdir -p .openclaw/hooks
cp -r hooks/openclaw .openclaw/hooks/self-improving-sales

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The ownership rules at L645 say standalone mode writes only to this project's .learnings/*.md log files. But earlier sections instruct adding workflow content to AGENTS.md, CLAUDE.md, or .github/copilot-instructions.md (L124-L137), and promoting process improvements into AGENTS.md (L99, L392), so the documented write scope is broader than this later claim.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file presents a 'Minimal Setup (Activator Only)' and later recommends 'enable UserPromptSubmit only' by default, but it also includes verification steps for a PostToolUse-based error detector and describes its behavior in the security section. While not a code-level contradiction, the documentation sends mixed intent signals about whether the skill is activator-only or includes tool-output monitoring.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.