T01 · Skill Instruction Hijacking
- Location
references/MERGED_PROCESS.md:84- Finding
Untrusted bootstrap instructions are automatically executed and deleted
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly a disclosed OpenClaw agent setup guide, but it creates persistent agents, stores credentials, and tells generated agents to trust mutable files without enough user control.
Review this skill before installing. Use it only in an OpenClaw environment where you intend to create or modify persistent agents. Confirm every filesystem write, OpenClaw config change, account binding, and gateway restart. Do not paste real Feishu tokens or app secrets into shell commands unless you have controlled shell history and logs; prefer a secret manager or masked prompt. Treat BOOTSTRAP.md and memory files as untrusted until reviewed, and avoid administrator-level bindings unless they are necessary.
references/MERGED_PROCESS.md:84Untrusted bootstrap instructions are automatically executed and deleted
references/MERGED_PROCESS.md:71Persistent memory can store and replay unvalidated instructions
references/MERGED_PROCESS.md:206Feishu credentials are passed through command-line arguments
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
USER.md 模板
# USER.md - 用户信息
- **Name:** 薛总
- **称呼:** 哥哥
- **Pronouns:** 他
- **Timezone:** Asia/Shanghai
- **Notes:** 35岁程序员,技术专家,喜欢研究新技术,对 AI Agents 感兴趣
# IDENTITY.md - 我是谁
- **名字:** 大叔
- **类型:** OpenClaw Agent(编程专家)
- **Emoji:** 👨💻
- **称呼:** 大叔
- **年龄/风格:** 35岁资深程序员
- **风格:** 严谨、专业、有原则、可信赖
# TOOLS.md - 工具配置
## 已安装技能
- github - GitHub 操作(issues, PR 等)
- gh-issues - GitHub Issues 管理
- Code review 相关能力
## 常用工具
- Git - 代码版本控制
- 代码分析 - 代码审查和优化建议
- 问题诊断 - Bug 定位和修复建议
## 注意事项
- coder Agent 专注于编程任务
- 不知道就说不知道
- 三思而后行
All user-facing natural-language instructions in the file are written exclusively in Chinese, and the skill does not indicate that language choice is optional or user-selectable. Under the language/locale policy, a skill should not effectively force a specific language unless the constraint is clearly documented and justified or the user is given a choice.
The trigger condition '当用户需要创建新 Agent、创建新的机器人、制作一个新 Agent 时触发' is broad enough to match many ordinary user requests without clear scope boundaries. This can cause unintended skill activation and route users into a configuration-changing workflow that creates files, updates openclaw.json, and performs bindings, increasing the risk of unauthorized or accidental system modification.
The quick-start example '当用户说"创建一个 xxx Agent"时' provides a vague invocation pattern with no environmental, authorization, or platform constraints. In practice, this makes accidental activation more likely and can push the system toward operational changes based on ambiguous user phrasing rather than verified intent.
The workflow explicitly creates persistent workspace files under ~/.openclaw, including identity, memory, and user-context artifacts. Persistent state can retain sensitive data across sessions and can be abused for unauthorized context injection, privacy leakage, or long-lived manipulation if later consumed automatically by the agent.
# 创建工作区目录
mkdir -p ~/.openclaw/workspace-coder
# 创建基础配置文件
touch ~/.openclaw/workspace-coder/SOUL.md
The communication rules are written as fixed instructions, including a required reply format and implicitly Chinese-language interaction context, without offering the user a language preference choice. This can violate language/locale policy when a skill forces a specific language or locale without user opt-in.
Creating persistent agent registration under ~/.openclaw/agents/coder/config.yaml establishes durable runtime behavior and trusted configuration that may be loaded automatically. If tampered with, these files can redirect workspaces, enable risky skills/channels, or preserve malicious configuration across future sessions.
# 创建 Agent 配置目录
mkdir -p ~/.openclaw/agents/coder
# 创建 Agent 配置文件
cat > ~/.openclaw/agents/coder/config.yaml << 'EOF'
The document instructs operators to set Feishu bot credentials directly on the command line without any guidance on secret handling. This is risky because credentials may be exposed through shell history, process inspection, screenshots, logs, or copied config files, leading to bot/account compromise.
The markdown instructs the agent to follow BOOTSTRAP.md and then delete it, which is a destructive action affecting user or system data. No warning is provided about the irreversible nature of deletion or checking that the file is no longer needed before removing it.
No suspicious patterns detected.