Back to skill

Security audit

Mupeng Evolve — God-Tier Agent Evolution Engine

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it asks for broad authority to change agent behavior and automate business-facing actions without enough clear limits.

Install only if you intentionally want an agent that can modify its own working memory and operating behavior. Before enabling it, restrict writable paths, require human approval for changes to tools, skills, heartbeat files, identity files, permanent memory, invoices, proposals, public posts, and third-party messages, and regularly review the generated logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly promotes autonomous revenue-generating workflows such as quote/invoice generation, grant drafting, marketplace publishing, and freelance execution, but provides no meaningful warning about financial, legal, contractual, or fraud risks. In an agent-skill context, encouraging business actions with high automation percentages can lead operators to delegate external-impact decisions without review, causing real monetary loss or unauthorized commitments.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The communication section normalizes automatic responses on external channels such as Instagram DM and describes a policy gate focused mainly on injection detection, but it omits clear warnings about privacy leakage, impersonation, reputational harm, and accidental disclosure. Because this is positioned as a production-ready autonomous skill, the lack of explicit constraints makes unsafe deployment more likely.

Self-Modification

High
Category
Rogue Agent
Content
description: "The God-Tier Agent Evolution Engine. 6 top skills analyzed, dissected, and rebuilt from scratch. Zero external dependencies. Battle-tested in production. Makes your agent truly autonomous."
author: mupengi-bot
tags: [evolution, memory, earning, autonomy, identity, meta, self-improvement, autonomous-agent, production-ready]
keywords: [agent-evolution, self-evolve, memory-system, revenue-automation, autonomous-ai, zero-dependency, battle-tested, production, openclaw, meta-skill]
---

# 🐧 Mupeng Evolve — The God-Tier Agent Evolution Engine
Confidence
84% confidence
Finding
The top-level description advertises autonomous self-improvement and says the skill makes the agent 'truly autonomous,' which is a strong indicator that self-modification is an intended capability. Even though the document claims to have security gates, self-modifying systems are inherently dangerous because they can alter instructions, identity, memory, or operational behavior in ways that bypass user expectations or compound mistakes over time.

Self-Modification

High
Category
Rogue Agent
Content
## 🔬 Competitive Analysis Summary

| Feature | self-evolve | capability-evolver | elite-memory | agent-earner | doppelganger | aura | **mupeng-evolve** |
|---------|:-----------:|:-----------------:|:------------:|:------------:|:------------:|:----:|:-----------------:|
| Self-modification | ✅ | ✅ | ❌ | ❌ | ❌ | ❌ | ✅ |
| Security gate | ❌ | ⚠️ | ❌ | ❌ | ✅ | ❌ | ✅ |
Confidence
88% confidence
Finding
The competitive-analysis table explicitly states that this skill supports self-modification, confirming that autonomous self-change is a core advertised feature. In context, this reinforces the risk that the skill encourages persistent behavioral or configuration changes based on its own judgments, which can destabilize controls or enable privilege creep if guardrails are incomplete or unenforced.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.