Mupeng Evolve — God-Tier Agent Evolution Engine

SuspiciousAudited by ClawScan on May 10, 2026.

Overview

The skill is upfront about self-evolution and memory, but it gives the agent broad autonomous permission to modify its own tools, skills, heartbeat behavior, and persistent memory without clear enough user control.

Install only if you intentionally want a self-modifying, persistent-memory meta-skill. Use it in a version-controlled or disposable workspace, require confirmation before any edits to skills, tools, heartbeat logic, or identity files, and review or prune memory files before they become permanent context.

Findings (4)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent could change how it or its installed skills behave in later tasks, potentially causing unexpected actions or making future behavior harder to audit.

Why it was flagged

This explicitly authorizes automatic modification of tools, heartbeat behavior, and skills. Those are high-impact agent-behavior controls, and the visible artifact does not clearly limit which files may be changed or require user approval for each change.

Skill content
- ✅ **Auto-modify**: memory/, tools, heartbeat, skills — evolve freely
Recommendation

Only use this in a tightly scoped workspace. Require explicit approval before any tool, skill, heartbeat, or configuration change, and keep backups or version control for rollback.

What this means

Private, incorrect, or attacker-influenced content could become durable agent context and affect future sessions.

Why it was flagged

The skill creates long-lived memory that is automatically promoted and reused on boot. The visible instructions do not clearly define user review, exclusions, poisoning resistance, or deletion controls for that persistent context.

Skill content
Retention: Permanent + Immutable core ... AUTO-PROMOTION: HOT → WARM → COLD (via heartbeat) ... CONTEXT RECOVERY: COLD → WARM → HOT (on boot)
Recommendation

Review memory files regularly, define excluded directories and sensitive data rules, and avoid automatic promotion to permanent memory without human approval.

What this means

Users may over-trust the safety of broad self-modification and persistent memory behavior based on unsupported assurances.

Why it was flagged

The artifact makes strong safety and production-readiness claims while providing only an instruction document and no implementation or verification evidence in the supplied artifacts.

Skill content
zero dependencies, battle-tested security, and real-world revenue integration
Recommendation

Treat the safety claims as unverified. Test in a non-critical environment and require manual review of all behavior-changing edits.

What this means

It is harder to verify who maintains the skill or whether the full behavior has been independently reviewed.

Why it was flagged

There is no executable package to inspect, but the skill has weak provenance for a high-impact self-evolution instruction set.

Skill content
Source: unknown; Homepage: none; No code files present — this is an instruction-only skill.
Recommendation

Prefer trusted sources for high-impact agent-control skills and review the complete SKILL.md before use.