Back to skill

Security audit

my-first-test-01

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed self-improvement logger, but it also encourages persistent hooks, cross-session access, and creating new skills in ways users should review before installing.

Install only if you want persistent self-improvement behavior. Prefer project-local .learnings and project-local hooks, avoid global ~/.claude or broad empty-matcher hooks unless you understand the scope, do not log secrets or full command outputs, and review any promotion into agent instruction files before accepting it. Treat the skill extraction helper as a manual tool and avoid running it in workspaces with untrusted symlinks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/extract-skill.sh:94
Finding

Workspace Boundary Bypass Through Symbolic-Link Traversal

Content
View full analysis
"$SKILL_PATH/SKILL.md" << TEMPLATE ``` ### Technical Analysis The script attempts to confine generated Skills to the current workspace by rejecting absolute output paths and paths containing `..`. These lexical checks do not account for symbolic links in existing path components. For example, `./skills` can be a symbolic link to an external directory. The path still passes both validation checks because it is relative and contains no `..` segment. Both `mkdir -p` and the subsequent shell redirection follow the symbolic link, causing `SKILL.md` to be created outside the intended workspace. The validation and write are also separate operations. Even if a path is checked before use, an attacker with concurrent access to the workspace could potentially replace a checked directory with a symbolic link before the file is written, creating a time-of-check to time-of-use race. ### Attack Path 1. An attacker gains control over, or can modify, the project workspace layout. 2. The attacker creates a symbolic link such as: ```bash ln -s /attacker-selected/writable/directory skil ...[truncated 1085 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill’s declared purpose is logging learnings and errors, but it also expands into skill extraction/scaffolding and broader filesystem modification workflows. That mismatch increases the chance an agent will perform writes or create artifacts outside a user’s expected scope, which can lead to unintended persistence or privilege creep even if the content is not overtly malicious.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Documenting installation into ~/.claude/settings.json establishes persistent behavior in the agent's user-level configuration directory. In the context of executable command hooks, that is security-relevant because it creates cross-project persistence and can affect unrelated sessions with the same privileges as the user.

Content

Scanner excerpt · references/hooks-setup.md (reported line 48)May include surrounding context.

Option 2: User-Level Configuration

Add to ~/.claude/settings.json for global activation:

json
{

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 181)May include surrounding context.

sessions_send

Send message to another session:

text
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill promotes writing persistent data under ~/.openclaw/workspace/.learnings, which creates durable cross-session storage outside the immediate project scope. Persistent storage can accumulate sensitive operational details, user corrections, error output, or project metadata over time, making accidental retention and later exposure more likely.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs use of cross-session tools including transcript reading and session messaging, which exceeds what is necessary for local learning capture. Accessing other sessions can expose unrelated prompts, sensitive data, or context boundaries, and even though the text advises trusted environments and explicit consent, the capability itself is high-risk because it normalizes cross-session data access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Phrases like 'Can you also...', 'I wish you could...', and 'Is there a way to...' are common everyday requests and are not specific to logging a feature request. In a markdown skill file, these broad examples can overlap with normal conversation and cause the skill to activate in situations outside its intended scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This section authorizes creating new reusable skills and running helper scripts, which is materially broader than simple note-taking. In an agent environment, capability expansion like this can transform a passive logging skill into an active code-generation and filesystem-writing skill, raising the risk of unauthorized modifications or propagation of unsafe patterns.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/examples.md (reported line 301)May include surrounding context.

When the above learning is extracted as a skill, it becomes:

File: skills/docker-m1-fixes/SKILL.md

markdown
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

Placing hook configuration in .claude/settings.json creates session-persistent automatic behavior for the project. In this skill's context, persistence is more dangerous because the hooks execute commands and may process prompt or tool-output data repeatedly over time, even after the user forgets they were enabled.

Content

Scanner excerpt · references/hooks-setup.md (reported line 15)May include surrounding context.

Option 1: Project-Level Configuration

Create .claude/settings.json in your project root:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

An empty matcher causes the hook to fire on every prompt, creating broad and continuous automatic execution. In this skill's context, that increases exposure to prompt-derived data, raises the chance of sensitive context being processed unnecessarily, and makes any future change to the hooked script high blast radius.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Using an empty matcher in a user-level config applies automatic execution across all sessions, not just a single project. That greatly expands persistence and blast radius: any compromise, bug, or over-collection behavior in the script affects every future interaction using that profile.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Although labeled 'minimal,' this setup still triggers on every prompt because the matcher is empty. That means reduced hook count but not reduced activation scope, so users may incorrectly believe they have meaningfully minimized risk when automatic execution remains ubiquitous.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Codex CLI example repeats the same empty-matcher pattern, causing universal activation for all prompts in that environment. Reproducing the pattern across tools normalizes overly broad execution and increases the likelihood that users deploy it without appreciating the security and privacy tradeoffs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document states that the scripts 'don't modify files or run commands,' but the hook configuration explicitly invokes shell scripts via command hooks. That mismatch can mislead users into granting trust or enabling the hooks under a false assumption about execution behavior, which is risky because hook scripts run automatically with the agent's privileges.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 57)May include surrounding context.

openclaw hooks enable self-improvement

text

### 3. Create Learning Files

Create the `.learnings/` directory in your workspace:

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description includes a broad activation condition to 'review learnings before major tasks' without defining what qualifies as a 'major task' or when the skill should not activate. This creates an unclear trigger boundary for a markdown skill description, increasing the chance of over-invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown template tells authors to 'Include trigger conditions' but does not require concrete trigger phrases, scope limits, or negative examples. Because this file is a template, that ambiguity can propagate into many skill manifests and cause unintended invocations from overly broad descriptions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.