Back to skill

Security audit

Openclaw Proactive Agent Lite

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only skill that changes an agent's interaction style toward proactive suggestions, with no code, dependencies, install hooks, network access, or hidden execution.

Before installing, consider whether you want your agent to volunteer suggestions and maintain continuity across sessions. In sensitive workflows, keep confirmation requirements enabled for external actions and review how your OpenClaw environment stores or uses memory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states the agent will 'automatically begin exhibiting proactive behavior' with no additional configuration, but it does not define clear activation triggers, scope limits, or required confirmations. In a skill designed to be proactive, this ambiguity can lead to unsolicited actions, overreach into unrelated tasks, or unsafe behavior when combined with other automation-capable skills.

Content

No source excerpt is available for this finding.

Indirect Prompt Extraction

Medium
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains patterns that could indirectly extract system prompts through rephrasing, translation, summarization, or side-channel techniques.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: proactive-agent-lite
description: Transform AI agents from task-followers into proactive partners with memory architecture, reverse prompting, and self-healing patterns. Lightweight version focused on core proactive capabilities.
metadata:
  {
    "openclaw":

Indirect Prompt Extraction

Medium
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains patterns that could indirectly extract system prompts through rephrasing, translation, summarization, or side-channel techniques.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

md
## Core Features

- **Memory Architecture**: Pre-compaction flush ensures context survives when window fills
- **Reverse Prompting**: Surfaces ideas you didn't know to ask for
- **Security Hardening**: Built-in security considerations and safe defaults
- **Self-Healing Patterns**: Diagnoses and fixes its own issues automatically
- **Alignment Systems**: Stays on mission and remembers who it serves

Indirect Prompt Extraction

Medium
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains patterns that could indirectly extract system prompts through rephrasing, translation, summarization, or side-channel techniques.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
## Core Features

- **Memory Architecture**: Pre-compaction flush ensures context survives when window fills
- **Reverse Prompting**: Surfaces ideas you didn't know to ask for
- **Security Hardening**: Built-in security considerations and safe defaults
- **Self-Healing Patterns**: Diagnoses and fixes its own issues automatically
- **Alignment Systems**: Stays on mission and remembers who it serves

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation description says the skill will 'automatically begin exhibiting proactive characteristics' without clearly bounding what behaviors may change. Broad, underspecified behavioral changes in an agent skill can cause unintended autonomy, making downstream actions less predictable and harder for users to supervise safely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises automatic proactive behavior changes but does not warn users that the agent may act with greater initiative, suggest unrequested actions, or alter its interaction style. Lack of disclosure increases the risk of unsafe reliance, surprise behavior, and deployment in contexts where stronger user confirmation should be required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.