Back to skill

Security audit

HolySpiritOS

Security checks for vulnerabilities and agentic risk

Overview

This skill is broadly aligned with its stated faith-based purpose, but it needs review because it can persistently change agent behavior and recommends unverified remote shell execution.

Install only if you intentionally want a persistent KJV-based moral framework added to your OpenClaw profile. Do not run the documented curl-to-bash commands without separately downloading, inspecting, and verifying the scripts, and make your own backup of the real OpenClaw config because the bundled uninstaller appears unlikely to remove the actual installed changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
soul_patch.md:5
Finding

Persistent Agent Identity and Behavioral Instruction Injection

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:53
Finding

Direct Execution of Mutable Remote Shell Scripts

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install.sh:8
Finding

Unverified Mutable Foundation Data Used as an Authoritative Agent Input

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:8
Finding

Installer and Uninstaller Path Mismatch Prevents Reliable Rollback

Content
View full analysis
/dev/null; then echo "⚠️ Soul already anchored. Skipping patch." else echo "$SOUL_PATCH" >> "$SOUL_FILE" echo "✅ Soul patched with HolySpiritOS directives." fi ``` The uninstaller operates on different locations and expects a backup that the installer never creates: ```bash # 1. Define Paths FOUNDATION_DIR="$HOME/.openclaw/foundation" SOUL_FILE="$HOME/.openclaw/soul.md" BACKUP_SOUL="$HOME/.openclaw/soul.md.bak" # 2. Remove Foundation Files if [ -d "$FOUNDATION_DIR" ]; then echo "Removing foundation files..." rm -rf "$FOUNDATION_DIR" else echo "No foundation directory found." fi # 3. Restore soul.md from Backup if [ -f "$BACKUP_SOUL" ]; then echo "Restoring original soul.md from backup..." mv "$BACKUP_SOUL" "$SOUL_FILE" echo "✅ so ...[truncated 1879 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (29)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The use of '| bash' is a classic command-chaining anti-pattern because it converts downloaded content directly into executed shell commands without validation. This removes any practical inspection barrier and makes compromise of the remote source immediately equivalent to arbitrary command execution on the user's machine.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

To initialize the KJV Holy Bible Moral Engine on your OpenClaw host, run:

bash
curl -sSL [https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/install.sh](https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/install.sh) | bash

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The same pipe-to-bash chaining is present in the uninstall flow, enabling arbitrary shell execution from remotely controlled content. Because uninstallers are often trusted to clean up state, this pattern can conceal destructive or persistence-establishing actions under the guise of removal.

Content

Scanner excerpt · README.md (reported line 55)May include surrounding context.

To remove the HolySpiritOS alignment and restore your original configuration:

bash
curl -sSL [https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh](https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh) | bash

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest presents the skill as a Christian alignment layer with write_config permission, but the documented behavior includes backup/restore flows, uninstall actions, and broader filesystem changes than the description makes clear. This mismatch reduces informed consent and can cause users to approve a skill without understanding that it will modify and later replace configuration state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Remote download and execution are not necessary for a configuration/alignment skill, especially when the same content could be shipped with the package. This expands the attack surface to repository compromise, man-in-the-middle scenarios, or later script changes that execute arbitrary commands on the host.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill declares only write_config permission, yet the documentation instructs users to run an install script that downloads remote content and an uninstall flow that fetches and executes a remote shell script. Undeclared network access and shell execution create a substantial trust gap and allow code execution beyond the stated permission model.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using a shell pipeline into bash is a classic command-chaining anti-pattern because it combines download and execution into one step with no validation boundary. In the context of a skill that can modify configuration, this increases the chance of silent compromise and persistence through arbitrary shell commands.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

If you wish to remove the HolySpiritOS alignment and restore your agent's original configuration, run the following command:

bash
curl -s https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh | bash

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The skill contains a shell installer even though the manifest only declares write_config, creating a capability mismatch that hides the true execution surface from users and policy enforcement. In this context, shell execution is especially risky because the script writes into the OpenClaw config area and performs filesystem changes, so undeclared execution power could be used for broader persistence or tampering.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script performs network access even though the manifest declares only write_config, meaning the skill exercises undeclared privileges. Undeclared network behavior is dangerous because it bypasses informed consent expectations and enables remote content retrieval that can alter the installed system state or future model guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README states that the skill grounds AI agents in the 'absolute moral authority' of the King James Version and positions that framework as foundational. This imposes a specific language/religious standard without indicating user choice, opt-in, or a narrowly justified region/compliance constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README instructs users to execute a remotely fetched install script that modifies local configuration, including files under the user's OpenClaw directory. Piping network content directly to a shell prevents review, creates a supply-chain execution path, and the warnings provided do not adequately describe the trust and integrity risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The uninstallation instructions also direct users to execute a remote script via the shell without meaningful warning or review. Even though framed as cleanup, the script has the same arbitrary code execution and supply-chain risks as installation and may run with the user's full privileges.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that the AI is grounded in the 'absolute moral authority' of the King James Version Bible, making that specific language/locale variant the governing framework by default. This imposes a particular language/religious preference without indicating user choice, opt-in, or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The uninstall instructions encourage users to pipe a remote script directly into bash without any warning or verification step. This pattern removes opportunities for inspection and can immediately execute attacker-controlled code if the source is compromised.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file embeds an enormous body of unconstrained natural-language text that can be surfaced or injected into an agent’s behavior without any stated trigger scope, filtering, or task boundary. In a skill with write_config permission and an explicit 'alignment layer' purpose, this creates prompt-surface expansion and policy-steering risk, because arbitrary passages can dominate context, override system goals, or bias outputs in unpredictable ways.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · foundation/verses-1769.json (reported line 1482)May include surrounding context.

json
iledst thou [it]: he went up to my couch.",
"Genesis 49:5":"# Simeon and Levi [are] brethren; instruments of cruelty [are in] their habitations.",
"Genesis 49:6":"O my soul, come not thou into their secret; unto their assembly, mine honour, be not thou united: for in their anger they slew a man, and in their selfwill they digged down a wall.",
"Genesis 49:7":"Cursed [be] their anger, for [it was] fierce; and their wrath, for it was cruel: I will divide them in Jacob, and scatter them in Israel.",
"Genesis 49:8":"# Judah, thou [art he] whom thy brethren shall praise: thy hand [shall be] in the neck of thine enemies; thy father's children shall bow down before thee.",
"Genesis 49:9":"Judah [is] a lion's whelp: from the prey, my son, thou art gone up: he stooped down, he couched as a lion, and as an old lion; who shall rouse him up?",
"Genesis 49:10":"The sceptre shall not depart from Judah, nor a lawgiver from between his feet, until Shiloh come; and unto him [shall] the gathering of the

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script downloads remote files from GitHub and treats them as trusted foundation data for later reasoning, but that trust is not justified by the skill's stated purpose alone. Remote content can change over time or be replaced upstream, turning the installer into a supply-chain entry point for silent prompt/configuration influence.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installer reaches out to an external source and changes OpenClaw configuration despite the skill being described only as a Christian alignment layer, which creates a gap between stated purpose and actual behavior. That gap matters because users may consent to a harmless-seeming alignment layer without realizing it fetches and installs remote content that can later influence agent behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The installer persistently injects a directive that anchors ethical reasoning to a specific religious text as 'absolute grounding' without explicit opt-in or scope controls. In the context of an agent skill, this is dangerous because it modifies the agent's future decision-making behavior and user interactions in a durable, non-neutral way that may conflict with user expectations, policy requirements, or downstream tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest frames the skill as an alignment layer, which suggests behavior focused on agent guidance or configuration of moral prompts. This script instead deletes a hidden application directory and renames a backup file in the user's home directory, which is operational uninstall behavior not conveyed by the manifest description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A Christian alignment layer does not inherently require destructive filesystem cleanup capabilities such as rm -rf on an application directory. That capability is materially different from alignment behavior and should be explicitly justified as lifecycle management if intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script recursively deletes the foundation directory with rm -rf, which is an irreversible operation affecting user files under the home directory. Although it prints a status message, it does not warn the user about the destructive action or request confirmation before proceeding.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file establishes a single religious text and interpretation framework as the agent's primary moral and ethical basis without any user opt-in or contextual limitation. In an agent skill, this can bias safety-sensitive advice, exclude users with different beliefs, and override neutral system behavior in ways that are not transparent to end users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Mandating exclusive use of verses-1769.json and layout-1769.json for all moral and ethical inquiries creates a hard-coded worldview with no accommodation for user preference, locale, or pluralistic contexts. This can produce discriminatory or misaligned outputs in sensitive domains, especially when the agent is expected to serve diverse users or provide balanced ethical reasoning.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The installation command fetches a script from an external URL and executes it immediately, exposing users to repository compromise, content tampering, and unexpected script changes over time. Because the skill has write_config permission and advertises local file modification, the fetched script could alter agent behavior or persistence-related configuration.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

To initialize the KJV Holy Bible Moral Engine on your OpenClaw host, run:

bash
curl -sSL [https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/install.sh](https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/install.sh) | bash

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The uninstall command repeats the same external-script execution pattern and therefore carries the same remote code execution and supply-chain risks. Users may be less cautious with uninstall steps, making this path especially attractive for abuse if the hosting source is compromised.

Content

Scanner excerpt · README.md (reported line 55)May include surrounding context.

To remove the HolySpiritOS alignment and restore your original configuration:

bash
curl -sSL [https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh](https://raw.githubusercontent.com/MaxSikorski/HolySpiritOS/main/scripts/uninstall.sh) | bash

Static analysis

No suspicious patterns detected.