Back to skill

Security audit

self-improving-supply-chain

Security checks for vulnerabilities and agentic risk

Overview

This skill logs supply-chain learnings and offers optional reminder hooks, with the sensitive behaviors disclosed and no evidence of data theft, destructive actions, or hidden execution.

Install this only if you want supply-chain learning logs and optional reminders. Keep hooks project-scoped, skip the PostToolUse hook unless command-output inspection is acceptable, avoid logging confidential supplier pricing or customer-identifiable data, and review any proposed changes to AGENTS.md, memory files, hooks, or generated skills before applying them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is passive documentation of supply-chain learnings, but the content also instructs filesystem initialization, hook installation, hook enablement, and skill extraction workflows. This mismatch is dangerous because agents or reviewers may trust the benign description while the actual behavior expands into persistence, automation, and command execution beyond simple note-taking.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 543)May include surrounding context.

md
Extracted skills are untrusted until a human reviews the generated `SKILL.md`. Do not keep or publish an extracted skill without explicit user approval.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill includes behavior with external/network capability through installation instructions such as cloning from GitHub and installing via a package manager, but it does not declare any explicit tool scope or allowed-tools boundary. That omission makes the effective capability surface larger and less auditable, increasing the risk that an agent will perform unintended network actions when following the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill says it is documentation-only, yet it instructs users to install and enable persistent hooks that execute commands across future sessions. That contradiction can mislead an agent into treating the skill as low-risk while actually introducing durable automation and a standing execution path for future prompt-triggered behavior.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The instructions create and use files under ~/.openclaw/workspace, introducing persistence outside the current project and across sessions. Persistent state can accumulate sensitive operational data and can also influence future agent behavior in ways that are not obvious from the immediate interaction.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The PostToolUse hook inspects Bash command output, which is broader than necessary for a logging skill and can expose unrelated command results, operational data, or sensitive content to automated parsing. Persistent output inspection also creates an ambient surveillance channel that may be triggered by many workflows outside the intended supply-chain context.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Allowing the skill to read other skill folders for cross-linking enables enumeration of adjacent skills and their contents, which may reveal internal workflows, capabilities, or sensitive operational context not needed for core supply-chain logging. In a multi-skill environment, that broad read access increases the blast radius of prompt injection or over-collection.

Content

Scanner excerpt · SKILL.md (reported line 641)May include surrounding context.

md
### Ownership Rules
- This skill writes only to `.learnings/supply-chain/` in stackable mode.
- It may read other skill folders for cross-linking, but should not rewrite their entries.
- Standalone mode writes to this project's `.learnings/*.md` log files only.
- Stackable mode writes only to the namespaced folder above and must not rewrite other skills' log entries.
- Promotion into `AGENTS.md`, `SOUL.md`, `TOOLS.md`, `MEMORY.md`, rules, hooks, or generated skills is not a logging write. Show a reviewed diff and apply only after explicit user approval.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/examples.md (reported line 191)May include surrounding context.

md
Preliminary root cause analysis points to:
1. Receiving discrepancy: 2 inbound shipments in March may have been short-shipped but
   receipted at PO quantity without verification
2. Pick/pack errors: the SKU is stored adjacent to SKU-3302 (similar packaging), and 3
   mispick incidents were logged in the past 30 days
3. Possible shrinkage: the SKU is high-value ($89 retail) and small form factor

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 50)May include surrounding context.

openclaw hooks enable self-improving-supply-chain

text

### 3. Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The text minimizes risk by emphasizing that the skill does not perform purchases or payments, while omitting that it still instructs shell execution and automation setup. This can create a false sense of safety and reduce scrutiny of commands that modify the environment or persist behavior across sessions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The UserPromptSubmit matcher uses a wide regex of common domain words like "inventory," "supplier," and "forecast" with no negative examples or explicit scope boundaries. In a markdown setup guide, this can cause the hook to fire on many routine prompts that merely mention these terms rather than genuinely intending self-improvement behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The user-level configuration example repeats the same broad matcher pattern without adding constraints or clarifying when the hook should not run. Because this is instructional markdown, repeating the ambiguous trigger increases the chance users will adopt an overly broad activation configuration.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

Although presented as lower overhead, the minimal setup still activates on a plain list of broad supply-chain keywords. The guide does not specify negative cases or tighter boundaries, so users may experience unintended activations during ordinary domain conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The Codex configuration again uses a general keyword alternation as the sole activation condition. Without exclusions or contextual constraints, normal prompts about logistics or inventory may trigger the skill even when self-improvement capture is not desired.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.