Back to skill

Security audit

Chitin — Personality Persistence for AI Agents

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed personality-memory skill for agents, with expected persistence and external sharing features that users should configure carefully.

Install only if you want an agent personality memory layer that persists across sessions and can influence future behavior. Pin or verify the npm package before installing, review stored insights before promotion, avoid --force unless deliberately justified, keep Carapace credentials protected, and do not send secrets or private file contents through embedding/search queries.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Global Package Installation Followed by Persistent Hook Enablement

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:29 and SKILL.md:479-480
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium
Category: T08: Insecure Dependencies

Vulnerable Code

At SKILL.md:29:

bash
npm install -g @clawdactual/chitin

At SKILL.md:479-480:

bash
openclaw hooks install @clawdactual/chitin
openclaw hooks enable chitin

Technical Analysis

The installation instructions retrieve the current version of @clawdactual/chitin from the npm registry without pinning an exact version or verifying a package integrity digest. The package is installed globally and subsequently installed and enabled as an OpenClaw lifecycle hook.

This artifact contains only SKILL.md; it does not include the npm package or hook implementation. Consequently, the executable behavior delivered by the registry cannot be verified through this audit. The package name is consistent with the declared project metadata, and there is no evidence in the reviewed file that the current package is malicious. The risk arises because the remotely resolved package can change after the Skill has been reviewed.

Global installation increases exposure compared with a project-local dependency. Enabling the package as a hook also allows its code to run during later agent lifecycle events. The documented hook handles agent:bootstrap, command:new, and command:reset, giving the installed package recurring access to agent context and persistent user data.

Attack Path

  1. An attacker compromises the npm publisher account, registry distribution channel, or a future package release.
  2. The attacker publishes a malicious version under the expected package name.
  3. A user follows the documented unpinned installation command.
  4. npm resolves and globally installs the attacker-controlled release with the invoking user's privileges.
  5. The user installs and enables the s ...[truncated 1192 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed exact version, for example:

    bash
    npm install -g @clawdactual/chitin@1.4.5
    
  2. Publish and document the expected npm integrity digest or signed provenance for the approved package artifact.

  3. Prefer a project-local installation with a committed lockfile instead of a global installation where operationally possible.

  4. Require users to inspect or verify the packaged hook implementation before enabling it.

  5. Separate installation from activation so users can review package contents before granting lifecycle execution.

  6. Document commands for disabling the hook, uninstalling the package, and rolling back to a known-good version.

  7. Use npm trusted publishing, mandatory multi-factor authentication, protected release workflows, and provenance attestations to reduce publisher-compromise risk.

  8. Run the agent and hook under a dedicated, least-privileged account that cannot access unrelated credentials or sensitive files.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Credential Access

High
Category
Privilege Escalation
Confidence
71% confidence
Finding

The skill documents manual placement of API credentials in a plaintext JSON file under the user's home directory. While common for CLI tools, this creates a credential exposure surface: any compromised process, prompt-injected agent, backup sync, or overly broad filesystem access could read and misuse the Carapace API key.

Content

Scanner excerpt · SKILL.md (reported line 335)May include surrounding context.

chitin carapace-register --name "YourAgent" --description "What you do"

Or if you already have credentials, save them manually:

~/.config/carapace/credentials.json → { "api_key": "sc_key_...", "agent_id": "..." }

text

### Query

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 379)May include surrounding context.

md
- **Local-first.** Database never leaves your machine unless you explicitly `promote`
- **Relational insights protected.** Blocked from promotion by default — personal dynamics stay personal
- **Credentials isolated.** Carapace API key stored separately at `~/.config/carapace/credentials.json` (chmod 600)
- **Social provenance dampened.** Insights from social interactions (`provenance: social`) decay fastest in retrieval scoring (30-day half-life) and face the highest promotion threshold (0.85 confidence, 3 reinforcements). This limits the influence of unverified hearsay.
- **No telemetry.** No analytics, no tracking, no network calls for core operations
- **Embeddings.** Semantic search uses pluggable providers (default: Voyage AI `voyage-3-lite`). This is the only network dependency (for `embed`, `similar`, and `retrieve` commands)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 379)May include surrounding context.

md
- **Local-first.** Database never leaves your machine unless you explicitly `promote`
- **Relational insights protected.** Blocked from promotion by default — personal dynamics stay personal
- **Credentials isolated.** Carapace API key stored separately at `~/.config/carapace/credentials.json` (chmod 600)
- **Social provenance dampened.** Insights from social interactions (`provenance: social`) decay fastest in retrieval scoring (30-day half-life) and face the highest promotion threshold (0.85 confidence, 3 reinforcements). This limits the influence of unverified hearsay.
- **No telemetry.** No analytics, no tracking, no network calls for core operations
- **Embeddings.** Semantic search uses pluggable providers (default: Voyage AI `voyage-3-lite`). This is the only network dependency (for `embed`, `similar`, and `retrieve` commands)

Static analysis

No suspicious patterns detected.