Back to skill

Security audit

Contradiction Detector

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent audit skill that reads OpenClaw instruction files to find contradictions and requires user confirmation before making changes.

Install this only if you are comfortable letting an agent read local OpenClaw instruction files, cron prompt text, installed skill files, and hook listings. Review proposed diffs before approving any edits, and do not enable periodic cron or HEARTBEAT scheduling unless you specifically want recurring audits.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.