Back to skill

Security audit

Genome Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed genome-management tool, but its implementation can escape its intended storage folder and its credential-safety claims are not enforced.

Review this skill before installing. It does not appear to exfiltrate data or run hidden background code, but only use trusted genome names, avoid putting secrets in prompts, and treat generated genome JSON files as persistent, shareable plaintext until path validation and secret checks are added.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/genome_manager.py:57
Finding

Path Traversal Allows Reading and Overwriting JSON Files Outside Genome Storage

Content
View full analysis
Remediation
View remediation
str: if not GENOME_NAME_PATTERN.fullmatch(name): raise ValueError("Invalid genome name") return name ``` 2. Resolve every target path and verify that it remains under the resolved genome directory: ```python def genome_path(name: str) -> Path: validate_genome_name(name) base = GENOMES_DIR.resolve() target = (base / f"{name}.json").resolve() if target.parent != base: raise ValueError("Genome path escapes the storage directory") return target ``` 3. Use this centralized path function for `create`, `get`, `mutate`, and `validate`. 4. Validate the `name` loaded from a parent genome before using it to construct a mutated output filename. 5. Reject absolute paths, `..`, forward slashes, backslashes, null bytes, and platform-specific path syntax even if a less restrictive naming policy is required. 6. Avoid silent overwrites. Use exclusive creation mode (`"x"`) for new genomes or require an explicit overwrite option. 7. Where overwriting is supported, use an atomic temporary-file write followed by a controlled rename within the validated storage directory. 8. Add tests covering absolute paths, nested paths, repeated traversal sequences, Windows-style separators, symlink-related edge cases, and malicious `name` fields loaded from JSON. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/genome_manager.py:36
Finding

Credential-Safety Guarantees Are Not Enforced When Storing Genome Prompts

Content
View full analysis
= 0.8", outcome.get("success_rate", 0) >= 0.8), ("Sample size >= 3", outcome.get("sample_size", 0) >= 3), ("Has task type", bool(genome.get("task_type"))), ("Has approach steps", len(genome.get("approach", {}).get("steps", [])) > 0), ] ``` The implementation conflicts with the documented security requirements: ```markdown ## Validation Rules Before saving a genome: - [ ] Success rate >= 0.8 (proven pattern) - [ ] Sample size >= 3 (not luck) - [ ] No credentials in prompts - [ ] Steps are reproducible - [ ] Tools are available ## Security - Genomes never contain API keys or credentials ``` ### Technical Analysis The `--prompts` value is split and persisted verbatim in a JSON file under `~/.openclaw/genomes`. No secret detection, redaction, confirmation, or encryption is applied. The validation routine checks quality metadata but does not implement the documented “No credentials in prompts” requirement. This creates a security-control gap: users may reasonably rely on the stated guarantee that genomes never contain credentials, while the actual implementation permits arbitrary secrets to be written in plaintext and subsequently printed by `get`. Although the audited pr ...[truncated 1741 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
# Genome Manager

Manages the Genome Evolution Protocol (GEP) genomes - structured success patterns that enable AI agents to self-evolve.

## What are Genomes?

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

This skill provides a command-line tool for genome management:

bash
# Create a new genome
python3 scripts/genome_manager.py create \
  --name research-comprehensive-v1 \
  --task-type research \

Static analysis

No suspicious patterns detected.