Back to skill

Security audit

Self Improving Compound

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent self-improvement memory system, but it asks for persistent jobs that can read conversations and modify durable agent instruction files.

Install only if you intentionally want a persistent self-improvement system that can read conversation history, store local memories, and update agent control-plane files. Before enabling cron, review every job, disable jobs you do not need, remove broad tools such as exec/write/edit where possible, set an explicit session key, avoid raw transcript capture, and require human review before anything is promoted into AGENTS.md, SOUL.md, USER.md, TOOLS.md, or skills.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T06 · System Persistence

Error
Location
scripts/setup-cron.json:4
Finding

Persistent Scheduled Agents Receive Broad Workspace and Session Capabilities

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/memory-pipeline.py:87
Finding

Conversation Transcripts Are Automatically Copied to Plaintext Workspace Files Without Redaction

Content
View full analysis
list[dict[str, Any]]: messages: list[dict[str, Any]] = [] with session_file.open("r", encoding="utf-8", errors="replace") as f: for line_no, line in enumerate(f, 1): ...[truncated 2935 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
scripts/learnings.py:1197
Finding

Untrusted Lesson Content Can Be Promoted into Durable Agent Instruction Files

Content
View full analysis
None: path.parent.mkdir(parents=True, exist_ok=True) if path.exists(): text = path.read_text(encoding="utf-8") text = text.rstrip() if text: text += "\n\n" text += block_text.rstrip() + "\n" else: text = block_text.rstrip() + "\n" path.write_text(text, encoding="utf-8") ``` ```python def _suggest_promotion_target(chunk: Chunk, override: str = "") -> str: if override: return override tags = set(chunk.metadata.tags) if "FTR" in tags: return "TOOLS.md" return "AGENTS.md" ``` ```python def _resolve_promotion_target(workspace_root: Path, target_file: str) -> Path: target_path = (workspace_root / target_file).resolve() try: target_path.relative_to(workspace_root) except ValueError as e: raise ValueError( f"target must stay under workspace root: {target_file}" ) from e return target_path ``` ```python def _promote_chunk( store: MemoryStore, workspace_root: Path, chunk: Chunk, target_file: str, ) -> Dict[str, Any]: entry_id = _extract_entry_id(chunk) target_path = _resolve_promotion_target(workspace_root, target_file) chunk.content = _replace_or_append_field( chunk.content, "Status", "promoted" ) chunk.content = _replace_or_append_field( chunk.content, "Promoted-To", target_file ) chunk.metadata.tags = [ t for t in chunk.metadata.tags if not t.startswith("status:") ] chunk.metadata.tags.append("status:promoted") promoted_text = _render_chunk_as_markdown(chunk).rstrip() appended = append_block_to_file_once( target_path, promote ...[truncated 2532 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/daily-memory.sh:56
Finding

User-Configurable Collector Command Is Evaluated by a Login Shell

Content
View full analysis
&2; usage >&2; exit 1 ;; esac done ``` ```bash if [[ -n "$COLLECTOR" ]]; then echo "[daily-memory] Running collector: $COLLECTOR" DAILY_MEMORY_DATE="$DATE" OPENCLAW_WORKSPACE="$ROOT" bash -lc "$COLLECTOR" else echo "[daily-memory] No collector configured. Gather context with runtime tools before writing the note." fi ``` ### Technical Analysis The helper accepts the collector as a single command string from either `SELF_IMPROVING_DAILY_COLLECTOR` or the `--collector` argument and passes it to `bash -lc`. A login shell interprets shell metacharacters, substitutions, pipelines, redirections, command separators, and initialization files. This is an intentional extensibility mechanism, but it creates a command-injection boundary: any party able to influence the environment variable, process arguments, cron configuration, or surrounding agent prompt can cause arbitrary shell commands to run with the privileges of the invoking process. The script also prints the complete collector command, which can disclose embedded credentials if an operator includes them in the command string. ### Attack Path 1. An attacker gains influence over `SELF_IMPROVING_DAILY_COLLECTOR`, the `--collector` argument, or a configuration process that constructs either value. 2. The attacker supplies a command containing shell syntax, for example a legitimate-looking colle ...[truncated 903 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (54)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill advertises a bounded memory/self-improvement workflow, but its documented behavior extends into broad ingestion of conversation content, durable modification of control-plane files, and automated background processing that is more powerful than the headline description suggests. This mismatch is dangerous because operators may approve or install it under a narrower trust assumption while it actually performs persistence and synthesis across multiple files and sessions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

md
- `hooks/activator.sh` as a pre-prompt / prompt-start reminder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 661)May include surrounding context.

md
- `hooks/activator.sh` as a pre-prompt / prompt-start reminder.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 298)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 403)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 461)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 482)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 483)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 484)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 487)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 497)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 512)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 522)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 532)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 542)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 552)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 559)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 560)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 621)May include surrounding context.

md
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 595)May include surrounding context.

md
bash scripts/extract-skill.sh my-skill-name /absolute/path/to/workspace

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly describes automated or semi-automated writes to workspace state, including memory files and root control-plane Markdown files, but the warning about modification scope and operational risk is limited and easy to miss. In an agent skill that influences files like AGENTS.md, TOOLS.md, MEMORY.md, and related control-plane state, insufficiently prominent warnings can lead users to enable automation that alters agent behavior, persistence, or safety-relevant instructions without fully understanding the blast radius.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly instructs use of shell commands, file reads/writes, environment variables, cron setup, and modification of durable workspace files, but it declares no tool scope or permissions boundary. That creates an over-privileged, ambiguous execution model where a host agent may grant broader capabilities than users expect, increasing the risk of unintended file mutation, persistence, or command execution.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs collection and persistence of recent conversation content into local files and summaries, creating a durable transcript-derived memory store. Even though it says to skip secrets and hidden thinking, this kind of automated capture materially increases privacy and data-retention risk because user-provided sensitive content can be copied into searchable local storage, exports, and cron-generated artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The smoke-test command explicitly uses TZ=Asia/Shanghai, which imposes a specific locale/timezone behavior in the instructions. This is a natural-language policy concern because the skill elsewhere presents itself as generally portable, but this example can steer users or agents into a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The routing guidance explicitly instructs storing user facts and preferences in persistent memory files such as MEMORY.md and daily notes. That is contextually aligned with the skill's purpose, but it still creates a real privacy vulnerability because personal preferences, profile data, and system state may accumulate indefinitely in plaintext workspace files without clear retention, access control, or consent enforcement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.