Back to skill

Security audit

Autonomous Loop

Security checks for vulnerabilities and agentic risk

Overview

This skill openly creates an autonomous agent loop, but it has broad, persistent authority and limited built-in controls, so users should review it before installing.

Install only in workspaces where you intentionally want unattended agent activity. Configure narrow per-agent messages, create stop files before working on sensitive sessions, monitor the logs, and avoid using it with agents that can deploy, delete data, access secrets, or make irreversible changes without human review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
*
 * Stop/resume:
 *   Stop:   touch ~/.openclaw/autonomous-loop.{agentId}.stop
 *   Resume: rm    ~/.openclaw/autonomous-loop.{agentId}.stop
 */

import { definePluginEntry } from "openclaw/plugin-sdk/plugin-entry";

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · plugin/index.ts (reported line 17)May include surrounding context.

ts
*
 * Stop/resume:
 *   Stop:   touch ~/.openclaw/autonomous-loop.{agentId}.stop
 *   Resume: rm    ~/.openclaw/autonomous-loop.{agentId}.stop
 */

import { definePluginEntry } from "openclaw/plugin-sdk/plugin-entry";

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · plugin/index.ts (reported line 254)May include surrounding context.

ts
};

// ---------------------------------------------------------------------------
// Helpers — send message to session via Gateway WebSocket
// ---------------------------------------------------------------------------

const sendMessage = async (details: {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill enables continuous autonomous behavior, log writing, stop-file control, and gateway interaction, yet it declares no explicit tool scope or permissions boundary. In a system that relies on manifest-declared capabilities, this creates a mismatch between what the skill appears allowed to do and what it instructs users to configure, increasing the risk of over-privileged execution and unsafe deployment.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

This skill is explicitly designed to make autonomous decisions by automatically re-triggering the agent with a task-selection prompt, allowing continued operation without fresh user approval each round. In context, that autonomy is the core feature, but it materially increases risk because the loop can continue executing tasks, editing files, and invoking project workflows based on broad instructions like picking the highest-priority task.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
# Autonomous Loop

Keeps an OpenClaw agent working continuously without human intervention. After each reply, the plugin waits N seconds and automatically sends the next task instruction — until you place a stop file.

## Installation

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises unattended operation that repeatedly performs work, updates files, and can start services, but it does not present a prominent safety warning about persistent changes to the workspace and local system state. Users may enable it without understanding that the agent will continue acting after each reply, which raises the chance of unintended file modification, runaway changes, or resource consumption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The plugin automatically re-engages the agent after each reply and sends a new message through the gateway without any direct user-facing consent prompt or persistent warning at the time the loop is active. In an autonomous agent context, this can cause continued actions and additional session traffic beyond what a user may reasonably expect, increasing the risk of unintended operations or silent persistence.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

This plugin is designed to autonomously send new messages after each reply, enabling ongoing agent action without fresh human initiation. That materially increases risk because the agent can continue making decisions, issuing actions, or propagating harmful instructions in a loop, especially if paired with powerful tools or broad task prompts.

Content

Scanner excerpt · plugin/openclaw.plugin.json (reported line 6)May include surrounding context.

json
"name": "Autonomous Loop",
  "version": "1.0.0",
  "kind": "automation",
  "description": "Automatically sends a follow-up message after each agent reply to keep the agent working autonomously.",
  "configSchema": {
    "type": "object",
    "additionalProperties": false,

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest explicitly advertises an automatic follow-up after every agent reply with no stated trigger boundaries, stop conditions, scope limits, or user-approval gate. In an agent environment, this creates a self-sustaining execution loop that can amplify mistakes, consume resources indefinitely, and continue acting on stale or unsafe context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The connection parameters hard-code the locale as "en-US", which imposes a specific language/locale choice regardless of user preference. The file does not offer a locale choice or explain a region-specific reason for this constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.