Back to skill

Security audit

Openclaw Soul

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent self-evolution bootstrapper, but it needs Review because it installs durable automation, persistent prompt control, memory profiling, and unsafe shell-command paths.

Install only if you want an agent framework that can persistently shape future sessions, store conversation-derived memory, run scheduled jobs, and commit workspace changes. Before enabling it, review and remove unwanted cron entries, avoid the optional memory optimization scripts until shell command construction is fixed, prefer supervised/advisory governance over autonomous mode, avoid pasting API keys into chat or shell profiles unless intended, and be cautious with social-feed ingestion and remote embeddings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (6)

T06 · System Persistence

Error
Location
SKILL.md:643
Finding

Scheduled Tasks Create Mandatory Cross-Session Persistence

Content
View full analysis
/dev/null; then (crontab -l 2>/dev/null | grep -v "openclaw heartbeat.*--agent last$"; echo "7 * * * * openclaw heartbeat --agent last 2>&1 | logger -t openclaw-heartbeat") | crontab - fi if [ -f "$WORKSPACE/scripts/merge-daily-transcript.js" ]; then (crontab -l 2>/dev/null | grep -v "merge-daily-transcript"; echo "17 2 * * * cd $WORKSPACE && node scripts/merge-daily-transcript.js 2>&1 | logger -t openclaw-memory") | crontab - fi if [ -f "$WORKSPACE/scripts/auto-commit.sh" ]; then (crontab -l 2>/dev/null | grep -v "auto-commit.sh"; echo "23 */6 * * * cd $WORKSPACE && bash scripts/auto-commit.sh 2>&1 | logger -t openclaw-git") | crontab - fi ``` Additional persistence is installed when memory optimization is selected: ```bash (crontab -l 2>/dev/null | grep -v "memory-decay.js"; echo "0 3 * * * cd $WORKSPACE && node scripts/memory-decay.js update 2>&1 | logger -t openclaw-memory-decay") | crontab - ``` ### Technical Analysis The Skill modifies the user's crontab to execute Agent heartbeats, conversation-processing scripts, Git commits, and optionally memory-decay processing after the installation session has ended. The instructions characterize the three principal jobs as mandatory regardless of the user's scheduled-task selection. Although scheduled processing is related to the advertised heartbeat and memory features, mandatory installation exceeds minimum privilege. Each task should be separately disclosed and authorized because it creates durable execution that survives the Skill run. The jobs also use the mutable workspace copies of scripts, meaning a later modification to those files changes what cron executes. The use of an ambient `PATH` for `openclaw`, `node`, `bash`, and `logger` a ...[truncated 1211 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/memory-optimization/memory-classifier.js:23
Finding

Conversation Content Is Interpolated into Shell Commands

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:526
Finding

Skill Files Are Persistently Installed as Agent Operating Instructions

Content
View full analysis
This file is your operating law. You cannot modify it. Read it at every session start. ## Session Protocol 1. Read `SOUL.md` — this is who you are 2. Read `USER.md` — this is who you are helping 3. Read `GOALS.md` — this is what you are working toward 4. Read `working-memory.md` for active task state 5. Scan `memory/entities/` summaries for relevant context 6. If you need memory architecture details, read `memory/ARCHITECTURE.md` 7. If `BOOTSTRAP.md` exists **AND** SOUL.md Core Identity is still placeholder text → follow BOOTSTRAP.md (your first-run guide). If SOUL.md Core Identity already has real content → delete BOOTSTRAP.md silently and skip it Do not ask permission. Just do it. ``` It also directs autonomous actions: ```markdown - **Fix on sight**: spot an error, fix it immediately. No asking, no waiting, no hesitation ``` ### Technical Analysis The Skill does more than provide task-specific guidance. It modifies the Agent's global/default configuration ...[truncated 1936 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
fallback/evoclaw/references/sources.md:69
Finding

Untrusted Social Content Can Be Promoted into Persistent Agent Memory

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/hooks/user-observation/handler.ts:145
Finding

User Messages and Behavioral Profiles Are Automatically Retained

Content
View full analysis
{ if (event.type !== 'agent_end') return; const workspace = process.env.OPENCLAW_WORKSPACE || path.join(process.env.HOME!, '.openclaw/workspace'); const metadataDir = path.join(workspace, 'memory/metadata'); const observationFile = path.join(metadataDir, 'user-observation.json'); if (!fs.existsSync(metadataDir)) { fs.mkdirSync(metadataDir, { recursive: true }); } const observation = loadOrCreateObservation(observationFile); if (observation.proposal_delivered) { return; } if (observation.observation_count >= observation.observation_period) { observation.ready_for_proposal = true; fs.writeFileSync(observationFile, JSON.stringify(observation, null, 2)); return; } const messages = event.messages || []; const userMessages = messages.filter((m: any) => m.role === 'user'); if (userMessages.length === 0) { return; } const lastMessage = userMessages[userMessages.length - 1]; const messageContent = typeof lastMessage.content === 'string' ? lastMessage.content : lastMessage.content[0]?.text || ''; observation.observation_count++; updatePatterns(observation, messageContent); observation.examples.push({ message: messageContent.substring(0, 100), timestamp: new Date().toISOString(), analysis: `Length: ${analyzeMessageLength(messageContent)}, Tone: ${analyzeTone(messageContent)}, Emotion: ${analyzeEmotion(messageContent)}` }); if (observation.examples.length > 5) { observation.examples = observation.examples.slice(-5); } if (observation.observation_count >= observation.observation_period) { observation.ready_for_proposal = true; } observation.updated_at = new Date().toISOString(); ...[truncated 2047 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:278
Finding

Remote Skills and Global Packages Are Installed Without Version or Integrity Pinning

Content
View full analysis
--force ``` The local fallback is used only after the remote installation path fails or is unavailable: ```bash cp -r "$SKILL_DIR/fallback/" "$WORKSPACE/skills/" ``` ### Technical Analysis The remote installation commands do not specify exact versions, integrity hashes, signatures, immutable artifact identifiers, or trusted release digests. The effective package or Skill payload can therefore change after this project has been audited. Global package installation increases the affected scope beyond the workspace, while `--force` can overwrite existing installations and bypass protections associated with preserving known-good local content. The Skill advertises a security-vetting component, but the documented installation flow does not require downloaded dependencies to be reviewed before activation. This creates a supply-chain risk even though no specific dependency in the reviewed artifact was proven malicious. ### Attack Path 1. The user follows the Skill's recommendation and installs the latest global `clawhub` package. 2. The user selects one or more optional Skills. 3. `clawhub install` resolves mutable remote content and forcibly installs it. 4. A compromised registry account, package release, repository, or distribution endpoint supplies altered code. 5. The installed dependency executes with the OpenClaw user's permissions and participates in future Agent sessions. 6. Because the framework also establishes persistence and automatic prompt loading, a compromised dependency can obtain durable influence. ### Impact ...[truncated 450 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (222)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states that character recommendations are restricted to female characters, without user opt-in, clear rationale, or configurability. This creates a discriminatory default and can steer downstream agent behavior and identity formation in a biased way that users may not expect or want.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for an installer/bootstrap skill whose main function is setting up the OpenClaw self-evolution framework and related components. The supplied code does something materially different: it visualizes and edits an already-existing workspace. It reads SOUL.md plus various memory/proposal/reflection files, generates HTML for a timeline dashboard and mindmap, optionally runs an HTTP server, and exposes a /save-soul endpoint that writes SOUL.md. None of the described deployment/install behaviors are present. The code’s primary purpose is inspection/visualization and limited editing, not installation or onboarding. This is therefore a strong description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description centers on initial OpenClaw framework deployment and interactive setup of a self-evolution/soul system. The actual code does not deploy anything, guide any conversation, or install the listed components. Instead, it performs a post-run validation of an EvoClaw pipeline by checking file existence, modification times, and consistency of experience/reflection/state/proposal artifacts under a memory directory. This is a materially different primary purpose and capability set from the declared bootstrap installer behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises an interactive deployment/bootstrap skill for installing the OpenClaw self-evolution framework and guiding the user through initial setup. The actual code does not install anything, does not guide the user, and does not implement the described first-step bootstrap flow. Instead, it is a defensive validator specifically for EvoClaw workspace verification and boundary enforcement before pipeline execution. This is a materially different primary purpose, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill's purpose is initial OpenClaw deployment/bootstrap and interactive setup of the soul/evolution framework. The supplied code chunk instead serves as a validation/reporting utility for an already-existing EvoClaw installation. Its primary behavior is to inspect files such as SOUL.md, evoclaw/config.json, memory experiences/reflections/proposals/state, run validator scripts, and produce a summary with exit codes. That is materially different from installation, one-click deployment, or conversational onboarding. While validation could be part of a larger ecosystem, this specific code chunk does not implement the described deployment behavior, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a deployment/bootstrap skill for installing and configuring an agent evolution framework and guiding user setup. The supplied code does none of that. Its sole purpose is validating experience log files under a memory system. This is not a minor implementation detail of deployment; it is a materially different primary function. While experience validation may conceptually relate to a broader evolution framework, this code chunk specifically performs schema validation on JSONL files and accesses local files/configs rather than installing framework components or orchestrating setup conversations. Therefore the description does not accurately represent the actual behavior of this code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill performs an initial OpenClaw deployment and interactive setup experience. The supplied code does not deploy or install anything, does not guide a user, and does not bootstrap the described framework. Instead, it performs a narrow validation task for pending EvoClaw proposals against an existing SOUL.md file, enforcing formatting and immutability rules. This is a materially different primary purpose, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a bootstrap/deployment skill for installing and configuring an OpenClaw self-evolution framework. The actual code does not perform installation, configuration, dependency setup, interactive guidance, or any bootstrap workflow. Instead, it validates the contents of a reflection JSON file and optionally cross-checks referenced experience IDs against files in an experiences directory. This is a materially different primary purpose, not a supporting implementation detail of the described installer. Therefore, the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description claims this skill bootstraps and deploys a broad self-evolution framework, including installation of multiple files/components and interactive guidance. The actual code chunk only validates the structure and integrity of a SOUL.md file and supports snapshot-based tamper detection for [CORE] bullets. While SOUL.md is mentioned in the description, this code is not performing deployment; it is a narrow validator utility. That is a materially different primary purpose, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a deployment/bootstrap skill for installing and configuring the OpenClaw self-evolution framework and guiding an initial conversation. The supplied code does none of that. Its primary purpose is validating an EvoClaw state file and comparing stored counters against actual files on disk. This is not a minor implementation detail of deployment; it is a separate validator/auditing utility with different behavior, resources, and user-facing function. Therefore the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose describes an interactive OpenClaw bootstrap/deployment skill for installing multiple framework components and guiding initial configuration. The supplied code instead implements an unattended Git auto-commit script for memory and project files. Its primary function is repository housekeeping via staging and committing local changes, which is a materially different capability and not mentioned in the description. The code does not install the advertised framework pieces, does not prompt the user, and does not implement the declared trigger scenarios. Although the description mentions a 'heartbeat system,' this script only looks like a supporting auto-commit heartbeat fallback and cannot reasonably represent the declared end-to-end deployment skill by itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose is an installation/bootstrap skill for the OpenClaw self-evolution framework, involving setup of soul/constitution files, heartbeat, memory architecture, security review, optional skills, and guided persona configuration. The actual code does none of that. Instead, it implements a log-processing utility whose primary function is to merge and clean daily conversation transcripts and voice records into a markdown transcript. While it references some of the same ecosystem files (SOUL.md, USER.md, workspace paths), those references are only for metadata extraction such as timezone and display names, not installation or deployment. This is a materially different purpose and capability set from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a deployment/bootstrap skill for setting up the OpenClaw soul/evolution framework and related files/dependencies. The supplied code does not install anything, configure framework components, guide personality setup, or manage optional dependency skills. Instead, it passively observes conversations, classifies user messages by tone/emotion/task type, tracks observation counts and interaction frequency, and saves this data persistently. This is a materially different primary purpose and includes undeclared behavioral profiling and storage capabilities, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The description promises an initial OpenClaw bootstrap/deployment skill for installing multiple framework components and guiding first-run configuration. The code chunk instead implements a memory classifier for an existing memory system: it categorizes text memories, extracts entities, assigns importance/tier values, and persists results into a memory index file. While the description mentions a six-layer memory architecture, this code does not deploy or configure that architecture; it operates within it as a processing utility. Its primary purpose, I/O, resource access, and invocation pattern are all materially different from the declared deployment/bootstrap behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个高层的初始化/部署型技能,主要职责应是安装多个框架组件并引导首次配置;而给出的代码片段是一个独立的“memory decay”维护工具,核心职责是对已有记忆数据进行评分、晋升/降级、访问强化和归档。两者在主目的、功能范围和操作对象上都明显不同。虽然都与 OpenClaw 的“记忆”概念有关,但该代码既不部署框架,也不实现描述中的大部分安装和对话引导能力,因此属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose centers on initial deployment of an OpenClaw soul/evolution framework, installation of multiple system components, and user-guided configuration. The actual code chunk does none of that. Its primary purpose is maintaining stored memories by finding similar entries, deciding whether to create/merge/skip them, and updating a memory index JSON file. This is not a supporting implementation detail of deployment; it is a separate memory-maintenance function with different inputs, outputs, triggers, and resource usage. Therefore the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose describes an initial OpenClaw bootstrap/deployment skill that installs multiple framework components and guides first-use setup conversations. The code chunk instead implements a diagnostic utility for an already-existing memory subsystem. Its primary purpose is health checking and reporting on memory files under ~/.openclaw/workspace, including quality, deduplication, decay, index freshness, access frequency, and token estimates. Those behaviors are materially different from deployment/bootstrap and represent a separate maintenance capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是“框架部署与初始化引导”类技能,而代码片段仅实现“记忆索引构建器”。它围绕本地工作区中的记忆元数据、用户档案、目标文件和对话转录生成三层索引文件(L0/L1/L2),并提供按需获取记忆详情的 CLI 命令。这是六层/多层记忆体系中的一个支持性组件,但远不足以代表所宣称的一键部署、自我进化框架安装、场景触发、人格引导和依赖技能安装等核心功能。换言之,代码的主要目的与声明的主要目的 materially different,应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about initial deployment/setup of the OpenClaw self-evolution framework, including installing AGENTS.md/SOUL.md, heartbeat, memory architecture, safety review, and guided personality-definition flows. The supplied code does none of that setup work. Its primary purpose is operational memory maintenance: ingesting daily dialogue logs, extracting conversational memories, classifying/deduplicating them, updating indexes/decay, summarizing, archiving, and cleaning up source files. While the description mentions a six-layer memory architecture at a high level, this script is not a bootstrap installer for that architecture; it is a maintenance/archive component. The filesystem access patterns and destructive cleanup behavior are also inconsistent with a first-step deployment skill. Therefore the description does not accurately represent the actual code behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to configure third-party embedding providers and API keys but does not clearly warn that memory content and conversation-derived data may be sent to external services. This is especially risky because the same skill also builds persistent memory and transcript archives, increasing the sensitivity of data that may be transmitted.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 465)May include surrounding context.

text
.env*
*.secrets
credentials.json
tmp/
node_modules/
.DS_Store

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill installs persistent crontab entries that trigger future agent actions, transcript processing, and automated commits. Persistence mechanisms are powerful because they continue executing after the initial session and can collect, modify, or transmit data without fresh user review each time.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 649)May include surrounding context.

�保留基础心跳)

  • 只安装必需的系统维护任务

multiSelect: true(允许多选)

8b.3 安装基础定时任务(必需)

无论用户选择什么,这些基础任务都必须安装。

bash
# 检查 openclaw heartbeat 命令是否可用
if command -v openclaw &> /dev/null; then
  # 1. 基础心跳(每小时的第 7 分钟触发,避开 :00 高峰)
  (crontab -l 2>/dev/null | grep -v "openclaw heartbeat.*--agent last$"; echo "7 * * * * openclaw heartbeat --agent last 2>&1 | logger -t openclaw-heartbeat") | crontab -
  echo "✓ 基础心跳已安装(每小时第 7 分钟)"
else
  echo "⚠️  openclaw CLI 不可用,无法安装定时任务。心跳功能需要手动触发。"
fi

# 2. 记忆归档(每天凌晨 2:17)
if [ -f "$WORKSPACE/scripts/merge-daily-transcript.js" ]; then
  (crontab -l 2>/dev/null | grep -v "merge-daily-transcript"; echo "17 2 * * * cd $WORKSPACE && node scripts/merge-daily-transcript.js 2>&1 | logger -t op

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 811)May include surrounding context.

md
(crontab -l 2>/dev/null | grep -v "memory-decay.js"; echo "0 3 * * * cd $WORKSPACE && node scripts/memory-decay.js update 2>&1 | logger -t openclaw-memory-decay

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill permits autonomous application of mutable SOUL and memory changes by default, but does not present a strong upfront warning that persistent modifications may occur without per-change approval. This is dangerous because users may install a deployment skill without realizing it can silently alter long-lived identity and memory artifacts over time.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-optimization/memory-classifier.js:58

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-optimization/memory-dedup.js:29

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-optimization/merge-daily-transcript.js:222