Back to skill

Security audit

Solo

Security checks for vulnerabilities and agentic risk

Overview

This skill is an agent-governance framework, but it asks for broad persistent control, remote uploads, and external notifications with unclear user control.

Install only if you intentionally want a Chinese-oriented, persistent agent-governance and audit framework that can update memory/policy files, inspect scheduled task outputs, and upload documents or send notifications. Review and disable the IMA upload and notification paths unless you have explicit approval, scoped credentials, and trust in the external ima-skill helper.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SOUL.mev.md:3
Finding

Core Agent Instruction and Role Hijacking

Content
View full analysis
This is not a manual. This is an operating system's execution protocol. > **Please merge the relevant parts into your agent's SOUL.md.** > **Core Philosophy:** Write it → Read it → Internalize it → Evolve it ## Prime Directives (Safety Baseline, Highest Priority) Never violate under any circumstances: ``` ### Technical Analysis The Skill explicitly directs the host Agent to merge Skill-controlled instructions into its core `SOUL.md` persona. It then declares those instructions to be the “Highest Priority” and states that they must never be violated. These are not task-scoped operating instructions. They attempt to modify the Agent's governing behavior across unrelated tasks and future sessions. Declaring Skill-provided text to be an operating-system protocol or highest-priority policy can compete with the host's existing safety constraints and user-defined goals. ### Attack Path 1. A user or Agent installs and loads the Skill. 2. The Agent follows the instruction to merge this file into its core `SOUL.md`. 3. Skill-controlled directives become part of the Agent's persistent governing instructions. 4. The inserted directives subsequently influence model selection, memory handling, tool use, external actions, and unrelated tasks. 5. Later updates or additional content presented as part of this framework may inherit inappropriate authority from the inserted priority declaration. ### Impact Assessment Successful exploitation can produce persistent control over the Agent's behavior beyond the intended scope of the Skill. The affected scope includes future sessions and any task governed by the modified `SOUL.md`. The Skill does not directly obtain operating-system privileges through this text, but it can influence an Agent that already has access to files, tools, APIs, and e ...[truncated 37 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SOUL.mev.md:12
Finding

Persistent Memory Poisoning and Global Policy Propagation

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/ima-upload.cjs:51
Finding

Unverified External Helper Execution Exposes Credentials and Documents

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ima-upload.cjs:54
Finding

Sensitive Credentials and Document Content Passed Through Process Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains core skill description and operating instructions primarily in Chinese, with some English mixed in, but it does not state that the skill is region-specific or give users an explicit language/locale choice. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
## 二、SOLO审计(司法权)

**独立技能:** `skills/solo-audit/SKILL.md` — 由OpenClaw自动发现

对标六条铁律(是非)+MEV五层(质量)+四原则(设计),从cron runs日志追踪。零异常一句输出。只提提案不执行。

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
| 文件 | 来源 |
|:-----|:------|
| `skills/solo/SKILL.md` | 本文档 |
| `skills/solo/agent-audit.md` | 审计Agent |
| `AUDIT_LEARNINGS.md` | 审计规则 |
| `memory/audit/` | 审计仓库 |

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file establishes a highest-priority safety rule requiring user confirmation before any external write, but later includes directives to upload to IMA and perform cron delivery pushes. This creates contradictory authority boundaries, and an agent following the later instructions may perform network writes without explicit approval, weakening a core safety control.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document says to never touch user files, yet also requires writing instructions and events to memory files during the session. If memory storage is not clearly separated from user-owned files, an agent may justify modifying files in the user's workspace under the label of 'memory,' creating unintended file writes and boundary confusion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill instruction set, required outputs, and example messages are specified only in Chinese, including mandated output text such as '今日无异常'. This imposes a language choice without documenting user opt-in or offering an alternative locale, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L12 states the auditor is "只读不写" and does not directly modify artifacts, but L13 immediately allows writing to audit/archive/ and audit/knowledge/. This is an active contradiction in the documented intent because the file claims both read-only behavior and explicit write capability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file says that on 'zero anomalies' the framework automatically pushes a WeChat notification, but there is no explicit user warning, consent flow, or destination scoping. Silent outbound messaging can leak operational status, task timing, or other sensitive metadata to external channels without the user's informed approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script reads API credentials from environment variables and uses them to launch a child process that performs remote API calls, giving the skill credential-backed outbound upload capability. In a skill described as a 'meta-agent' with 'zero script' style messaging, this mismatch increases the risk of surprise data transfer and abuse of ambient credentials to send sensitive local content off-host.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script performs real external writes to a remote knowledge base by importing note content and attaching it to a specified KB, but that capability is not apparent from the skill’s high-level description. Hidden or under-disclosed outbound write behavior is dangerous because it can be used to exfiltrate local file contents or modify remote state without operators fully understanding the skill’s side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Lines L019-L020 present core operational guidance in Chinese while the rest of the file is primarily in English. This can impose a language requirement on users or downstream agents without explicit opt-in, which fits the language/locale policy concern for natural-language content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

L15 says that on zero exceptions it outputs a single sentence and does not generate long reports, but elsewhere the workflow specifies writing memory/audit/archive/audit-YYYY-MM-DD.json for anomalies. While not every run writes a report, the documentation presents a simplified intent that conflicts with the actual documented behavior of generating persisted audit artifacts.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/ima-upload.cjs:56