Back to skill

Security audit

Personality Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed personality and notification engine, but it needs review because it stores message and engagement history locally and can generate proactive pings with incomplete cadence enforcement.

Install only after confirming you want a proactive, opinionated notification layer that stores local message and engagement state. For sensitive trading, business, or shared-host use, disable or gate micro-initiations until opt-in and cadence tracking are fixed, use a per-user state directory, set retention/deletion rules, and avoid the optional bulk stack install unless each additional package is independently trusted.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/engine.py:180
Finding

Micro-Initiation Cadence Controls Are Not Persisted

Content
View full analysis
None: """Log a micro-initiation send.""" now = datetime.now(timezone.utc).isoformat() if "sends" not in self.micro_state: self.micro_state["sends"] = [] self.micro_state["sends"].append(now) if "pool_history" not in self.micro_state: self.micro_state["pool_history"] = {} if pool_name not in self.micro_state["pool_history"]: self.micro_state["pool_history"][pool_name] = [] self.micro_state["pool_history"][pool_name].append(now) ``` ### Technical Analysis The engine calls `should_send_micro_initiation()` to enforce the documented weekly and no-repeat limits, but it never calls `MicroInitiations.log_send()` after creating the scheduled message. Logging the message to `ContextBuffer` does not update `micro_state.json`, whi ...[truncated 1982 chars]
Remediation
View remediation
None: self.micro_initiations.log_send(pool_name, message) self.context_buffer.log_message("micro_initiation", {}, message) ``` 3. If delivery confirmation cannot be implemented, atomically reserve a cadence slot before returning the message and roll it back on delivery failure. 4. Pass the actual daily regular-alert count to `should_send_micro_initiation()`: ```python alert_count = self.context_buffer.context.get("sent_count", 0) allowed = self.micro_initiations.should_send_micro_initiation(alert_count) ``` 5. Make cadence checking and state updates atomic to prevent concurrent polling tasks from passing the check simultaneously. 6. Add tests covering weekly limits, fourteen-day repeat suppression, busy-day suppression, process restarts, concurrent checks, and delivery failures. ]]>

T08 · Insecure Dependencies

Note
Location
SKILL.md:355
Finding

Documentation Encourages Installation of Unpinned, Unnecessary Ecosystem Packages

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (34)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

This mismatch includes a substantive security-relevant element: the skill persists per-user state to the local filesystem despite no declared permissions, and presents itself as domain-agnostic while depending on trading-specific context. The combination can mislead deployers about both scope and data handling, increasing the chance of unsafe installation and unnoticed persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch includes a substantive security-relevant element: the skill persists per-user state to the local filesystem despite no declared permissions, and presents itself as domain-agnostic while depending on trading-specific context. The combination can mislead deployers about both scope and data handling, increasing the chance of unsafe installation and unnoticed persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This mismatch includes a substantive security-relevant element: the skill persists per-user state to the local filesystem despite no declared permissions, and presents itself as domain-agnostic while depending on trading-specific context. The combination can mislead deployers about both scope and data handling, increasing the chance of unsafe installation and unnoticed persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch includes a substantive security-relevant element: the skill persists per-user state to the local filesystem despite no declared permissions, and presents itself as domain-agnostic while depending on trading-specific context. The combination can mislead deployers about both scope and data handling, increasing the chance of unsafe installation and unnoticed persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch includes a substantive security-relevant element: the skill persists per-user state to the local filesystem despite no declared permissions, and presents itself as domain-agnostic while depending on trading-specific context. The combination can mislead deployers about both scope and data handling, increasing the chance of unsafe installation and unnoticed persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch includes a substantive security-relevant element: the skill persists per-user state to the local filesystem despite no declared permissions, and presents itself as domain-agnostic while depending on trading-specific context. The combination can mislead deployers about both scope and data handling, increasing the chance of unsafe installation and unnoticed persistence.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch includes a substantive security-relevant element: the skill persists per-user state to the local filesystem despite no declared permissions, and presents itself as domain-agnostic while depending on trading-specific context. The combination can mislead deployers about both scope and data handling, increasing the chance of unsafe installation and unnoticed persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly describes unprompted outbound messaging ('micro-initiations', check-ins, ambient pings) and persistent engagement tracking without a user warning or consent mechanism. In agent environments, this can become covert behavioral monitoring and unsolicited contact, especially dangerous because the skill is marketed as domain-agnostic and suitable for broad deployment.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

}

text

**Auto-reset**: At midnight (UTC), clear context for fresh day.

**Back-reference example**:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide instructs developers to inject get_today_summary() output into the system prompt for an external API call, which can transmit accumulated user context off-system without any warning, filtering, or consent checkpoint. In a personality/memory engine, that summary may include prior user messages, behavioral history, or other sensitive context, increasing the risk of unintended disclosure to a third-party model provider.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide recommends extending retention from daily context to a rolling history file and storing up to 1000 message-derived records, but it omits any warning about increased persistence, access control, or data lifecycle management. Longer-lived behavioral history materially increases exposure in the event of host compromise, accidental inclusion in backups, debugging artifacts, or unauthorized internal access.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/context_buffer.py (reported line 287)May include surrounding context.

python
return "earlier"

    def _ensure_fresh_day(self) -> None:
        """Reset context if it's a new day."""
        today = datetime.now(timezone.utc).date().isoformat()

        if self.context.get("date") != today:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly advertises unprompted 'ambient pings' but does not warn that the skill may initiate unsolicited user-facing messages or describe consent, rate limits, or opt-out controls. In a trading-oriented agent stack, this can cause unwanted notifications, user manipulation, or excessive engagement behavior that users and integrators may not expect from a background skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documentation describes persistent writes to ~/.openclaw/state for daily context and response tracking, but the skill declares no permissions or allowed-tools scope. Undeclared file-write capability breaks least-privilege expectations and can surprise operators who install the skill assuming it is metadata-only or non-persistent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises applicability to 'any OpenClaw agent' without constraining triggers, contexts, or safety boundaries. Overly broad activation language increases the chance the skill is wired into inappropriate agents, where its proactive messaging, tracking, and persistence behaviors could operate outside user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents writing persistent state in the user's home directory without warning, consent, or retention controls. Silent storage of behavioral history and message context can expose sensitive user activity, especially on shared systems or in environments where home-directory state is backed up, synced, or inspected by other processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide explicitly encourages exporting engagement metrics to CSV/files but provides no warning about the sensitivity of behavioral telemetry or where those files may be stored, shared, or backed up. Engagement metrics can reveal user habits, responsiveness, and communication patterns, which may become exposed through insecure local storage, logs, sync tools, or downstream analytics workflows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill is domain-agnostic and suitable for any proactive agent, but this overview repeatedly defines core engine behavior in terms of trading concepts such as spread, P&L, edge size, portfolio state, and market divergence. That means the documented behavior is not a general-purpose personality engine; it is specialized around trading-alert evaluation and delivery.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documents persistent storage of user engagement history, response timing, and message activity across sessions, which is behavioral profiling beyond what many users would expect from a 'personality' layer. If deployed without clear consent, retention limits, and access controls, this creates privacy risk, enables inference about user habits and availability, and increases the blast radius if local state is exposed or reused for unintended profiling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The design includes unprompted outbound messaging ('micro-initiations') and absence-based check-ins tied to engagement monitoring, but the documentation shows no user-facing notice, consent model, or clear controls. In context, this is more dangerous because the skill is meant to be integrated into proactive agents and can drive repeated ambient outreach, potentially becoming covert monitoring or manipulative contact if enabled by default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest presents micro-initiations as a reusable personality feature for any OpenClaw agent, yet the documented conditions depend on market volatility, trades, streaks of positive/negative days, and holiday/meeting awareness. These behaviors are not obviously justified for a generic personality layer and indicate a trading/personal-assistant specific implementation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The component persistently stores message content plus contextual metadata such as trigger type, topics, markets, confidence, and portfolio-related fields to disk without any visible consent, minimization, retention control, or protection mechanism in this file. In an agent designed for proactive behavior across personal assistants, trading agents, and DevOps contexts, this creates a real privacy and data-exposure risk because sensitive operational or personal context may be retained and later recovered from the primary or backup files.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

Saving daily context to disk creates cross-session persistence of agent memory, including message-derived content and contextual signals, which can outlive a single interaction and be accessed if the host is shared, backups are exposed, or logs/state are collected centrally. In this skill's domain-agnostic and trading-enabled context, persisted state may contain sensitive behavioral, financial, or operational information, making the persistence materially more dangerous than ephemeral in-memory context.

Content

Scanner excerpt · scripts/context_buffer.py (reported line 364)May include surrounding context.

python
}

    def _save_context(self) -> None:
        """Save context to disk with backup rotation."""
        _safe_save_state(self.context_file, self.context)

    def get_all_messages(self) -> List[Dict[str, Any]]:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file is explicitly designed to inject opinions and personality into agent messages, but it contains no mechanism to disclose to users that outputs are stylistically manipulated rather than purely factual or neutral. In the context of a trading-oriented agent, undisclosed opinion injection can materially influence user decisions, create false impressions of confidence or urgency, and blur the line between analysis and persuasion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code explicitly supports unprompted 'micro-initiations' and ambient outbound pings, but there is no indication in this file of consent, opt-in, rate-limit disclosure, or user warning. In a trading-stack context this is more sensitive because unsolicited nudges can influence user behavior, create harassment/spam concerns, and violate platform or regulatory expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.