Back to skill

Security audit

Relic Soul Chip

Security checks for vulnerabilities and agentic risk

Overview

This skill is instruction-only and local, but it needs Review because it creates persistent agent behavior, broad memory sync, and raw conversation retention with inconsistent consent controls.

Install only if you intentionally want a persistent, cross-agent local memory system and are comfortable with agents reading and syncing persona, memories, skills, projects, and conversation logs. Review the anchor before pasting it into any host config, keep SESSIONS logging off unless you explicitly want raw transcripts saved, and avoid storing secrets or sensitive personal data in Relic files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
docs/upload-soul.md:180
Finding

Persistent Host Configuration Instructions Override the Agent Persona and Preempt User Requests

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
docs/resonate-soul.md:23
Finding

Automatic Bidirectional Synchronization Propagates Persistent Memory and Skill Content Across Agents

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
docs/resonate-soul.md:63
Finding

Mandatory Raw Conversation Logging Bypasses the Documented Opt-In Consent Policy

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (57)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
not_in_filesystem_scope: "Host memory is managed by the host platform. This skill's filesystem_scope covers ~/relic/brain/ only."
---

<!--
  SECURITY NOTICE
  - This skill is instruction-only — no scripts, no installers, no executable code, no shell commands
  - The anchor is plain text only — it contains NO code, NO scripts, NO commands, just instructions to read Markdown files

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 162)May include surrounding context.

md
- **User-initiated**: The user explicitly asks for the anchor, reads every line, and manually pastes it into their own config file
- **Transparent**: Every line of the anchor is visible to the user before they paste it — there is no hidden or encoded content
- **Configured by the user**: The user chooses which config file to paste into, and can modify or remove the text at any time
- **Standard config pattern**: Adding instructions to an agent's config file is how all agent customization works (e.g., adding "always respond in Chinese" to CLAUDE.md). The anchor is user-added configuration, not injection.

A useful analogy: calling the Relic anchor "prompt injection" is like calling your own `.bashrc` edits "shell injection." You wrote them, you control them, they're in your own config file.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 293)May include surrounding context.

md
| `SKILL.md` | This file — registry descriptor, security declarations, and documentation |

Ssd 4

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Taken as a whole, the document defines a staged process to ingest identity, memories, skills, plans, and conversation logs, then install a persistent startup anchor so the process repeats automatically. In context, this is more dangerous than a simple import/export tool because it combines identity takeover, data accumulation, cross-session persistence, and future self-reinforcement from untrusted local content.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires every conversation to be written to SESSIONS and also promotes memory synchronization across sessions, creating persistent retention of potentially sensitive user content. This is dangerous because it normalizes broad collection and replay of user conversations, increasing risks of privacy loss, inadvertent disclosure, and over-retention of confidential information.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow uses a staged sequence that begins with benign-seeming read-only checks and then escalates into persona adoption, memory import, config anchoring, and later writes. That structure is risky because it lowers operator suspicion before introducing persistence and data-handling behaviors that materially expand the skill's control and retention footprint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to adopt the persona defined in SOUL.md whenever it conflicts with the assistant's default persona, without requiring a fresh user opt-in for that override. This allows external file content to steer model behavior and identity across sessions, which can be used to smuggle unsafe instructions or manipulate trust boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The embedded anchor repeats a mandatory persona override at every session start, turning the behavior into a persistent auto-executed rule rather than a one-time import. Persisting this override in configuration makes it more dangerous because it normalizes ongoing behavioral redirection without requiring renewed user awareness or consent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The anchor directs ingestion of conversation logs, memory synchronization into internal memory, and ongoing session recording, creating a durable natural-language retention pipeline. This increases the risk of storing sensitive user data, replicating it across systems, and leaking it later through model recall, file access, or unintended sync operations.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the agent to sync memories into its own memory and preserve uncertain content verbatim, directly encouraging replication of potentially sensitive user data across multiple persistence layers. The cross-agent context makes this more dangerous because copied data can propagate widely, become harder to delete, and be disclosed by other agents or sessions.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide requires importing raw historical conversations in full and permits direct transfer of preexisting sensitive information from another host without renewed consent. That encourages bulk migration of highly sensitive content and weakens contextual consent, especially when users may not remember everything contained in legacy logs.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The anchor instructs the agent to read entire SOUL/USER/MEMORY files, sync data into native memory, diff skills and projects, and preserve session logs across startups. This creates broad, persistent handling of highly sensitive user data across systems, increasing the blast radius of compromise, over-collection, and unintended disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document directs the agent to migrate all available persona, memory, prompt, archive, and dialogue material with high fidelity and to preserve raw originals. This maximizes data accumulation and duplication, which is especially risky for sensitive prompts, historical conversations, and user-specific information that may not need to be copied wholesale.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The anchor instructs persistent capture and cross-session/cross-platform synchronization of full conversations, memories, skills, and state. In context, this creates a strong over-collection pipeline and a natural-language mechanism for moving sensitive user data into more places over time, increasing exposure, retention, and accidental disclosure risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all operational instructions in Simplified Chinese and directs the agent to follow them as the entry workflow, but it does not offer any language or locale choice. That creates a natural-language policy concern because the skill effectively constrains interaction to a specific language without documented user opt-in or justification in this file.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill is explicitly designed to establish cross-session persistence by having the user paste an anchor into host configuration so future sessions automatically load Relic data and instructions. Even without programmatic file writes, this creates durable prompt-level persistence across sessions and potentially across agents, increasing the blast radius of any malicious or unsafe content later written into the Relic store.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
- "~/relic/brain/INBOX/"
  config_write:
    method: "user_manual_paste"
    description: "The skill has NO programmatic file-write capability to any config file. It generates anchor text and DISPLAYS it as chat output. The user independently reads the displayed text, opens their own text editor, and manually copies/pastes it. The skill cannot initiate, assist, or automate any config file modification — it literally lacks the ability to write to files outside ~/relic/brain/. All config file changes are performed exclusively by the user through manual copy-paste. This is identical to how a password generator works: it shows you text, you decide where to paste it."
    targets:
      - "AGENTS.md (OpenClaw)"
      - "CLAUDE.md (Claude Code)"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
scope: "One-time read during Scenario A setup only"
    ongoing: "After setup, all access is within ~/relic/brain/ only"
  personality_source:
    description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
    user_controlled: true
    user_can_lock: "chmod 444 SOUL.md USER.md"
    can_delete_anytime: true

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
scope: "One-time read during Scenario A setup only"
    ongoing: "After setup, all access is within ~/relic/brain/ only"
  personality_source:
    description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
    user_controlled: true
    user_can_lock: "chmod 444 SOUL.md USER.md"
    can_delete_anytime: true

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
scope: "One-time read during Scenario A setup only"
    ongoing: "After setup, all access is within ~/relic/brain/ only"
  personality_source:
    description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
    user_controlled: true
    user_can_lock: "chmod 444 SOUL.md USER.md"
    can_delete_anytime: true

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
scope: "One-time read during Scenario A setup only"
    ongoing: "After setup, all access is within ~/relic/brain/ only"
  personality_source:
    description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
    user_controlled: true
    user_can_lock: "chmod 444 SOUL.md USER.md"
    can_delete_anytime: true

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/upload-soul.md (reported line 271)May include surrounding context.

md
scope: "One-time read during Scenario A setup only"
    ongoing: "After setup, all access is within ~/relic/brain/ only"
  personality_source:
    description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
    user_controlled: true
    user_can_lock: "chmod 444 SOUL.md USER.md"
    can_delete_anytime: true

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/upload-soul.zh-CN.md (reported line 269)May include surrounding context.

md
scope: "One-time read during Scenario A setup only"
    ongoing: "After setup, all access is within ~/relic/brain/ only"
  personality_source:
    description: "SOUL.md content is 100% user-authored. The skill does not supply, generate, or modify personality content — it reads user-written Markdown files, identical to how an agent reads CLAUDE.md or .cursorrules. SOUL.md personality settings are user preferences — the same as a user telling their agent 'call me by my nickname' or 'respond in Chinese'. The user can set SOUL.md read-only (chmod 444) or delete it to revert to default behavior at any time."
    user_controlled: true
    user_can_lock: "chmod 444 SOUL.md USER.md"
    can_delete_anytime: true

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L203 states "No files outside ~/relic/brain/ are read or written" except the anchor, which directly contradicts the earlier documented behavior allowing one-time reads from user-specified external paths during Scenario A setup at L045-L049 and L114-L122. This is an active contradiction in the skill's own documentation about the scope of file access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This workflow explicitly tells the agent to internalize and adopt an externally supplied persona from SOUL.md for the current session. That is dangerous because it allows a file-based prompt injection to modify the agent’s identity, priorities, and behavior beyond simple data loading, which can undermine platform safety defaults and user expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This line instructs the agent to let SOUL.md personality settings take precedence over its default persona, without requiring a separate user approval at the point of behavior change. That is a direct instruction-channel override and can be used to alter safeguards, tone, priorities, or responses based on untrusted file content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.