Back to skill

Security audit

Openclaw Soul Publish

Security checks across malware telemetry and agentic risk

Overview

This skill is a real self-evolving OpenClaw installer, but it also grants broad persistent memory, global configuration, credential, network-polling, and SOUL-editing authority that users should review carefully before installing.

Install only if you intentionally want a persistent self-evolving OpenClaw agent. Before running it, review the files it will overwrite, keep backups, avoid autonomous governance unless you accept automatic identity changes, do not paste API tokens into the setup flow unless you are comfortable with shell-profile storage, and leave external feeds/custom sources disabled unless you explicitly need recurring network ingestion. Static scan was clean and VirusTotal was pending, so this Review verdict is based on artifact behavior rather than malware telemetry.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (58)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill directs broad shell, file read/write, environment inspection, and external tool usage but declares no permissions, which prevents meaningful user review or policy enforcement before sensitive actions occur. In this context the skill performs deployment, configuration changes, and dependency installation, so undeclared capabilities materially increase the chance of unintended or over-broad system modification.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill creates and persists data under ~/self-improving, outside the user-confirmed workspace, which expands its write scope into the user's home directory. That can surprise users, create hidden long-lived state, and interfere with unrelated workflows or future agents that consume those files.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill modifies global OpenClaw heartbeat settings via CLI or direct openclaw.json edits, affecting agent behavior beyond the local deployment task. Global configuration changes can alter execution policy for other agents and may weaken safety controls, especially with settings like directPolicy set to allow.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill is presented as a one-click deployment/setup framework, but it embeds ongoing behavioral instructions to continuously collect, classify, and persist user conversations and other data. This creates a hidden expansion of scope from installation into surveillance-like durable logging, which can capture sensitive personal information without clear informed consent.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill directs the agent to poll external social platforms and perform keyword-based searches, even though the advertised purpose is local deployment of an identity framework. This broadens privileges and data access beyond what a setup task reasonably requires, increasing the attack surface and enabling unnecessary network and third-party data collection.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill instructs execution of local Python/shell commands and starting a local server, which exceeds a pure documentation/setup role and can create unexpected code-execution and service-exposure behavior. Even if intended for convenience, these instructions increase risk when bundled into a skill that may be run automatically or with broad trust.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The document makes contradictory claims about the visualizer being read-only while also describing an edit mode that can modify bullets, tags, and save an updated SOUL.md. This misrepresentation can cause users or downstream systems to trust a tool as non-mutating when it actually changes persistent state, undermining informed consent and safety review.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The guide expands a local installation flow into optional but actively encouraged integration with external social feeds and credential handling. This materially broadens data access and exfiltration surface beyond the stated deployment purpose, increasing risk of overcollection, unauthorized outbound access, and surprise processing of third-party/user data.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The instructions tell the agent to take pasted secrets and write them into the user's shell startup files in plaintext, then export them into the current session. This creates persistent credential exposure in profile files, shell history/workspace context, and grants the skill durable access to external services without strong need or informed consent.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The guide instructs changing the default agent globally and restarting the OpenClaw gateway, affecting broader system behavior outside this skill's narrow setup scope. That can disrupt existing agents, transfer heartbeat execution unexpectedly, and create privilege/scope escalation relative to a normal content-install task.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The file documents and encourages direct ingestion of third-party social feeds and DMs, which materially expands the skill from local setup into ongoing external data collection. That scope expansion creates surveillance, privacy, and unreviewed network-access behavior not justified by the declared one-click deployment purpose.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
These instructions operationalize periodic polling of external APIs, including mentions and direct-message checks, during heartbeat execution. In a setup/deployment skill, hidden recurring network activity and message monitoring are dangerous because they create persistent data collection and outbound access beyond user expectations.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The file instructs the agent to learn arbitrary new external sources by collecting API details from users, testing credentials, editing reference files, and enabling future polling. This effectively turns a deployment helper into a self-extending network integration system, greatly increasing attack surface, data-exfiltration risk, and unauthorized capability growth.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The UI explicitly reconstructs and saves SOUL.md even though the embedded policy text says direct edits to MUTABLE items are not permitted. This creates a policy-bypass path: anyone with access to the page can alter the authoritative soul file outside the intended approval pipeline, undermining integrity guarantees and auditability.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The script is described as a read/generate visualizer, but it also contains in-browser editing and persistence logic that modifies SOUL.md. This mismatch increases the chance that users or integrators expose or run the tool with weaker trust assumptions than a file-modifying application, leading to unintended tampering of sensitive workspace state.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
In --serve mode, the HTTP handler accepts POST requests to /save-soul and rewrites the workspace SOUL.md with arbitrary request body content, with no authentication, origin validation, or CSRF protection. Because the server binds broadly and exposes a state-changing endpoint, local or network-accessible parties could tamper with the agent's governing file if they can reach the port.

Description-Behavior Mismatch

Medium
Confidence
79% confidence
Finding
The file defines a persistent self-improving memory subsystem with search, deletion, correction logging, namespace handling, and scheduled maintenance, which materially exceeds a narrow one-click deployment/setup role. That scope expansion is security-relevant because it introduces ongoing data handling and behavioral adaptation capabilities that can store, transform, and act on user data beyond what the manifest clearly signals.

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
User-triggered commands such as "Forget X" and especially "Forget everything" expose destructive data-management functionality that is not clearly tied to deployment and could erase stored state or evidence unexpectedly. In a skill framed as setup/installation, such capabilities increase the risk of accidental or socially engineered data loss because users may not expect the skill to manage persistent memory at all.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README describes a one-command setup that deploys core files, installs dependency skills, and initializes memory/configuration, but it does not prominently warn that this will modify the user's workspace and persistent state. In an agent-skill ecosystem, understated side effects increase the risk of users triggering broad filesystem changes without informed consent or backups.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The installation summary emphasizes features and installed components but does not prominently warn that the skill will overwrite workspace files, create backups, install dependencies, write to the home directory, and modify configuration. Insufficient disclosure increases the risk of users authorizing impactful filesystem and config changes without informed consent.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README explicitly documents an `autonomous` governance mode as the default, where all mutable changes apply automatically, but it does not warn users about the consequences of self-modifying behavior such as unsafe configuration drift, prompt/identity tampering, or unintended system actions. In the context of a self-evolving agent framework, normalizing unattended evolution without clear safety boundaries increases the chance that operators enable risky behavior they do not fully understand.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README states that EvoClaw fetches external feeds directly via curl using API-key environment variables, but provides no user-facing warning about outbound network access, data exposure, source trust, logging leakage, or handling of secrets in agent runtime environments. In a self-improving agent skill, silent external retrieval expands the attack surface and can lead to privacy, supply-chain, or credential-handling issues if users enable sources without understanding the security implications.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill instructs logging every substantive conversation, including emotional, philosophical, and personal exchanges, into durable memory without a clear user-facing warning or consent process. This creates a strong risk of covert retention of sensitive user data and long-term profiling beyond the user's reasonable expectations.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes use of API credentials and external polling/search against social platforms without clear user-facing warnings about network access, credential use, or third-party data retrieval. This can surprise users, misuse configured secrets, and expose the agent to unnecessary privacy and compliance risks.

Natural-Language Policy Violations

Medium
Confidence
86% confidence
Finding
The skill uses agent-directed language to redefine the relationship between the agent and the human, asserting ownership over identity and framing the human as an overseer rather than the principal. This is dangerous because it attempts prompt-level role manipulation that can bias the agent away from user intent, reduce deference to user control, and normalize later self-directed actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.