T01 · Skill Instruction Hijacking
- Location
soul_patch.md:5- Finding
Persistent Agent Identity and Behavioral Instruction Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is broadly aligned with its stated faith-based purpose, but it needs review because it can persistently change agent behavior and recommends unverified remote shell execution.
Install only if you intentionally want a persistent KJV-based moral framework added to your OpenClaw profile. Do not run the documented curl-to-bash commands without separately downloading, inspecting, and verifying the scripts, and make your own backup of the real OpenClaw config because the bundled uninstaller appears unlikely to remove the actual installed changes.
soul_patch.md:5Persistent Agent Identity and Behavioral Instruction Injection
SKILL.md:53Direct Execution of Mutable Remote Shell Scripts
scripts/install.sh:8Unverified Mutable Foundation Data Used as an Authoritative Agent Input
scripts/install.sh:8Installer and Uninstaller Path Mismatch Prevents Reliable Rollback
The use of '| bash' is a classic command-chaining anti-pattern because it converts downloaded content directly into executed shell commands without validation. This removes any practical inspection barrier and makes compromise of the remote source immediately equivalent to arbitrary command execution on the user's machine.
To initialize the KJV Holy Bible Moral Engine on your OpenClaw host, run:
curl -sSL [https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/install.sh](https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/install.sh) | bash
The same pipe-to-bash chaining is present in the uninstall flow, enabling arbitrary shell execution from remotely controlled content. Because uninstallers are often trusted to clean up state, this pattern can conceal destructive or persistence-establishing actions under the guise of removal.
To remove the HolySpiritOS alignment and restore your original configuration:
curl -sSL [https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh](https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh) | bash
The manifest presents the skill as a Christian alignment layer with write_config permission, but the documented behavior includes backup/restore flows, uninstall actions, and broader filesystem changes than the description makes clear. This mismatch reduces informed consent and can cause users to approve a skill without understanding that it will modify and later replace configuration state.
Remote download and execution are not necessary for a configuration/alignment skill, especially when the same content could be shipped with the package. This expands the attack surface to repository compromise, man-in-the-middle scenarios, or later script changes that execute arbitrary commands on the host.
The skill declares only write_config permission, yet the documentation instructs users to run an install script that downloads remote content and an uninstall flow that fetches and executes a remote shell script. Undeclared network access and shell execution create a substantial trust gap and allow code execution beyond the stated permission model.
Using a shell pipeline into bash is a classic command-chaining anti-pattern because it combines download and execution into one step with no validation boundary. In the context of a skill that can modify configuration, this increases the chance of silent compromise and persistence through arbitrary shell commands.
If you wish to remove the HolySpiritOS alignment and restore your agent's original configuration, run the following command:
curl -s https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh | bash
The skill contains a shell installer even though the manifest only declares write_config, creating a capability mismatch that hides the true execution surface from users and policy enforcement. In this context, shell execution is especially risky because the script writes into the OpenClaw config area and performs filesystem changes, so undeclared execution power could be used for broader persistence or tampering.
The script performs network access even though the manifest declares only write_config, meaning the skill exercises undeclared privileges. Undeclared network behavior is dangerous because it bypasses informed consent expectations and enables remote content retrieval that can alter the installed system state or future model guidance.
The README states that the skill grounds AI agents in the 'absolute moral authority' of the King James Version and positions that framework as foundational. This imposes a specific language/religious standard without indicating user choice, opt-in, or a narrowly justified region/compliance constraint.
The README instructs users to execute a remotely fetched install script that modifies local configuration, including files under the user's OpenClaw directory. Piping network content directly to a shell prevents review, creates a supply-chain execution path, and the warnings provided do not adequately describe the trust and integrity risks.
The uninstallation instructions also direct users to execute a remote script via the shell without meaningful warning or review. Even though framed as cleanup, the script has the same arbitrary code execution and supply-chain risks as installation and may run with the user's full privileges.
The skill states that the AI is grounded in the 'absolute moral authority' of the King James Version Bible, making that specific language/locale variant the governing framework by default. This imposes a particular language/religious preference without indicating user choice, opt-in, or a justified region-specific constraint.
The uninstall instructions encourage users to pipe a remote script directly into bash without any warning or verification step. This pattern removes opportunities for inspection and can immediately execute attacker-controlled code if the source is compromised.
The file embeds an enormous body of unconstrained natural-language text that can be surfaced or injected into an agent’s behavior without any stated trigger scope, filtering, or task boundary. In a skill with write_config permission and an explicit 'alignment layer' purpose, this creates prompt-surface expansion and policy-steering risk, because arbitrary passages can dominate context, override system goals, or bias outputs in unpredictable ways.
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
iledst thou [it]: he went up to my couch.",
"Genesis 49:5":"# Simeon and Levi [are] brethren; instruments of cruelty [are in] their habitations.",
"Genesis 49:6":"O my soul, come not thou into their secret; unto their assembly, mine honour, be not thou united: for in their anger they slew a man, and in their selfwill they digged down a wall.",
"Genesis 49:7":"Cursed [be] their anger, for [it was] fierce; and their wrath, for it was cruel: I will divide them in Jacob, and scatter them in Israel.",
"Genesis 49:8":"# Judah, thou [art he] whom thy brethren shall praise: thy hand [shall be] in the neck of thine enemies; thy father's children shall bow down before thee.",
"Genesis 49:9":"Judah [is] a lion's whelp: from the prey, my son, thou art gone up: he stooped down, he couched as a lion, and as an old lion; who shall rouse him up?",
"Genesis 49:10":"The sceptre shall not depart from Judah, nor a lawgiver from between his feet, until Shiloh come; and unto him [shall] the gathering of the
The script downloads remote files from GitHub and treats them as trusted foundation data for later reasoning, but that trust is not justified by the skill's stated purpose alone. Remote content can change over time or be replaced upstream, turning the installer into a supply-chain entry point for silent prompt/configuration influence.
The installer reaches out to an external source and changes OpenClaw configuration despite the skill being described only as a Christian alignment layer, which creates a gap between stated purpose and actual behavior. That gap matters because users may consent to a harmless-seeming alignment layer without realizing it fetches and installs remote content that can later influence agent behavior.
The installer persistently injects a directive that anchors ethical reasoning to a specific religious text as 'absolute grounding' without explicit opt-in or scope controls. In the context of an agent skill, this is dangerous because it modifies the agent's future decision-making behavior and user interactions in a durable, non-neutral way that may conflict with user expectations, policy requirements, or downstream tasks.
The manifest frames the skill as an alignment layer, which suggests behavior focused on agent guidance or configuration of moral prompts. This script instead deletes a hidden application directory and renames a backup file in the user's home directory, which is operational uninstall behavior not conveyed by the manifest description.
A Christian alignment layer does not inherently require destructive filesystem cleanup capabilities such as rm -rf on an application directory. That capability is materially different from alignment behavior and should be explicitly justified as lifecycle management if intended.
The script recursively deletes the foundation directory with rm -rf, which is an irreversible operation affecting user files under the home directory. Although it prints a status message, it does not warn the user about the destructive action or request confirmation before proceeding.
The file establishes a single religious text and interpretation framework as the agent's primary moral and ethical basis without any user opt-in or contextual limitation. In an agent skill, this can bias safety-sensitive advice, exclude users with different beliefs, and override neutral system behavior in ways that are not transparent to end users.
Mandating exclusive use of verses-1769.json and layout-1769.json for all moral and ethical inquiries creates a hard-coded worldview with no accommodation for user preference, locale, or pluralistic contexts. This can produce discriminatory or misaligned outputs in sensitive domains, especially when the agent is expected to serve diverse users or provide balanced ethical reasoning.
The installation command fetches a script from an external URL and executes it immediately, exposing users to repository compromise, content tampering, and unexpected script changes over time. Because the skill has write_config permission and advertises local file modification, the fetched script could alter agent behavior or persistence-related configuration.
To initialize the KJV Holy Bible Moral Engine on your OpenClaw host, run:
curl -sSL [https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/install.sh](https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/install.sh) | bash
The uninstall command repeats the same external-script execution pattern and therefore carries the same remote code execution and supply-chain risks. Users may be less cautious with uninstall steps, making this path especially attractive for abuse if the hosting source is compromised.
To remove the HolySpiritOS alignment and restore your original configuration:
curl -sSL [https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh](https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh) | bash
No suspicious patterns detected.