Back to skill

Security audit

Open Persona

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do what it claims, but it needs human review because it can run mutable package-manager commands and persist changes to agent personas and installed skills.

Install only if you trust OpenPersona, npm package resolution, and the persona or skill sources you plan to use. Prefer pinned CLI versions, review generated persona packs and identity-file changes before activation, avoid inline curator tokens, and require explicit approval before install, update, switch, publish, register, or contribution commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned npm packages are downloaded and executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:6, SKILL.md:47-52, SKILL.md:125-135, SKILL.md:197; references/AVATAR.md:13-18
Vulnerability Type: Supply-chain exposure through mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

yaml
allowed-tools: "Bash(npx openpersona:*) Bash(npx clawhub@latest:*) Bash(openclaw:*) Bash(gh:*) Read Write WebFetch"
bash
# Agent / scripted usage (always use --preset or --config):
npx openpersona create --preset base --install

# Human / terminal usage (interactive wizard):
npx openpersona create
bash
# If you wrote persona.json (custom path):
npx openpersona create --config ./persona.json --install

# If you chose a preset (preset path):
npx openpersona create --preset <name> --install
text
To find external skills: check local `layers/skills/`, search ClawHub via
`npx clawhub@latest search "<keywords>"`, or fetch
`https://skills.sh/api/search?q=<keywords>`.
bash
npx skills add avatar-runtime
# or directly from GitHub:
npx skills add github:acnlabs/avatar-runtime/skill/avatar-runtime

Technical Analysis

The Skill repeatedly directs the agent to use npx to resolve and execute packages. The openpersona and skills package versions are not pinned, while clawhub@latest explicitly selects mutable latest content. No lockfile, package integrity hash, signature verification, or approved-version policy is included in the audited project.

Because npx may download a package before executing its command-line entry point, the effective executable can differ from the artifact that was reviewed. This behavior is relevant to the Skill's management functionality, but allowing unrestricted current releases exceeds the minimum necessary privilege: the same operations could use exact, reviewed versions.

This finding establishes supply-chain exposure, not that the current upstream packages are malicious.

Attack Path

  1. An attacker compromises a ref ...[truncated 1082 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every executable package to an exact reviewed version, for example npx openpersona@X.Y.Z.
  2. Remove @latest and establish an explicit, reviewed upgrade process.
  3. Prefer locally installed dependencies governed by a committed lockfile.
  4. Verify registry provenance, signatures, and integrity hashes before execution.
  5. Run package CLIs in a sandbox with minimal filesystem, environment, and network access.
  6. Require explicit user confirmation before first execution and whenever the pinned version changes.
  7. Maintain an allowlist of approved package names, versions, publishers, and source repositories.
  8. For GitHub installation sources, pin immutable commit hashes rather than mutable branches or shorthand repository references.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:386
Finding

Untrusted persona instructions can be persisted into agent identity files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:163, SKILL.md:336-350, SKILL.md:376-386; supporting enforcement description at references/ARCHITECTURE.md:27-32
Vulnerability Type: Persistent instruction injection through third-party persona installation and activation
Risk Level: Medium

Vulnerable Code

text
**The `behaviorGuide` field** is optional but powerful. Use markdown to write
domain-specific behavior instructions that go directly into the generated SKILL.md.
text
- **Install:** `npx openpersona install <target>` — smart router that auto-detects
  pack type (persona / skill); install from registry slug or `owner/repo`;
  `--registry <name>` selects registry (`acnlabs` default).
text
- **Install:** `openpersona skill install <owner/repo>` — install a skill pack
  from GitHub (`owner/repo`, `owner/repo#subpath`, local dir, or local zip)
- **Update:** `openpersona skill update <slug>` — re-download and overwrite
  from its recorded source URL
text
When multiple personas are installed, only one is **active** at a time. All
install/uninstall/switch operations maintain a local registry at
`~/.openpersona/persona-registry.json`; on OpenClaw, switching replaces the
soul injection block in SOUL.md / IDENTITY.md (preserving user-written content
outside the markers).

The architecture reference characterizes the install control as a warning:

text
| **Install** | `lib/lifecycle/installer.js` | warning (`printWarning`) —
constitution SHA-256 hash integrity |

Technical Analysis

Persona packs can contain behavior instructions that become agent-facing Skill text. The Skill supports retrieving such packs from a registry or arbitrary owner/repo sources and then activating them by replacing an injection block in persistent OpenClaw identity files.

The documented installation gate provides a constitution hash-integrity warning, but the audited documentation does not establish mandatory source authent ...[truncated 2050 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require cryptographically signed persona manifests and verify signatures against trusted publishers.
  2. Pin registry and GitHub installations to immutable revisions and record verified content hashes.
  3. Display a complete instruction diff before activation and require explicit user approval.
  4. Add a mandatory content-safety gate that rejects directives attempting to override host policy, obtain secrets, suppress disclosure, or bypass confirmation.
  5. Treat unknown sources as blocked rather than merely unverified.
  6. Apply the trust threshold to persona soul and behavior content, not only capability-unlock commands.
  7. Write identity-file changes atomically, create a verified backup, and provide a one-command rollback.
  8. Keep third-party persona instructions in a lower-priority, clearly delimited context rather than placing them in a privileged identity layer.
  9. Revalidate content on every update before overwriting an installed pack or active identity block.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (80)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
- **Local:** definitions in `layers/skills/{name}/` (`skill.json` + optional `SKILL.md`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 536)May include surrounding context.

md
- **Local:** definitions in `layers/skills/{name}/` (`skill.json` + optional `SKILL.md`)

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill permits executing npx openpersona:* and npx clawhub@latest:* from agent-controlled flows. npx resolves and may download code at execution time, and openpersona is unpinned entirely, so future upstream package compromise or malicious version publication could lead to arbitrary code execution on the host. In a meta-skill that encourages many CLI invocations, this raises the blast radius substantially.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill permits executing npx openpersona:* and npx clawhub@latest:* from agent-controlled flows. npx resolves and may download code at execution time, and openpersona is unpinned entirely, so future upstream package compromise or malicious version publication could lead to arbitrary code execution on the host. In a meta-skill that encourages many CLI invocations, this raises the blast radius substantially.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This instruction tells the agent to run unpinned npx openpersona create, which can fetch and execute whatever version npm serves at runtime. If the package or one of its transitive dependencies is compromised, persona creation becomes an arbitrary code execution path under the user's account.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The interactive npx openpersona create example is also unpinned and therefore executes mutable remote code. Because this file repeatedly normalizes use of unpinned npx, it creates a recurring unsafe pattern rather than an isolated documentation issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Searching community personas via unpinned npx openpersona search still requires executing remote package code before any search occurs. The danger is not the query itself but the package bootstrap step, which is mutable and outside the skill's control.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The install flow references unpinned npx openpersona install, creating a direct path from documentation to arbitrary code execution and package installation. Since install commands often run with filesystem write privileges, a compromised package could persist malicious artifacts or alter the agent environment.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
### Step 1 — Decide: preset or custom?


| User request                                                                                                 | Action                                                              |
| ------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------- |
| Matches an existing preset (`ai-girlfriend`, `life-assistant`, `stoic-mentor`, `samantha`, `health-butler`…) | Use `--preset <name>` directly — skip to Step 4                     |
| Specific role / domain / personality                                                                         | Gather 3 required inputs (Step 2), then write persona.json (Step 3) |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
Ask only what you cannot infer. Use smart defaults for everything else.


| Field                    | Question to ask                                                                                                                                                                     | Default if not asked        |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------- |
| `personaName` + `slug`   | "What should I call this persona?"                                                                                                                                                  | Infer from role description |
| `role`                   | "What role should it play — assistant, coach, mentor, companion, or something else?"                                                                                                | `assistant`                 |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
| Field                    | Question to ask                                                                                                                                                                     | Default if not asked        |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------- |
| `personaName` + `slug`   | "What should I call this persona?"                                                                                                                                                  | Infer from role description |
| `role`                   | "What role should it play — assistant, coach, mentor, companion, or something else?"                                                                                                | `assistant`                 |
| `body.runtime.framework` | Only ask if you cannot infer the runner from context. If you are Cursor → `cursor`; Claude Code → `claude-code`; OpenClaw → `openclaw`. Ask the user only when genuinely uncertain. | `openclaw`                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
| Field                    | Question to ask                                                                                                                                                                     | Default if not asked        |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------- |
| `personaName` + `slug`   | "What should I call this persona?"                                                                                                                                                  | Infer from role description |
| `role`                   | "What role should it play — assistant, coach, mentor, companion, or something else?"                                                                                                | `assistant`                 |
| `body.runtime.framework` | Only ask if you cannot infer the runner from context. If you are Cursor → `cursor`; Claude Code → `claude-code`; OpenClaw → `openclaw`. Ask the user only when genuinely uncertain. | `openclaw`                  |

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The custom persona generation command uses unpinned npx openpersona create --config ... --install. This combines runtime package download with local file generation and installation, increasing impact if the npm package is hijacked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Preset-based generation is another unpinned runtime package execution path. Repetition of the same unsafe primitive across create/install/search flows makes exploitation opportunities frequent and easy to trigger through normal skill use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documented switch command relies on the same mutable CLI toolchain. If an attacker compromises the package, switching personas can become an execution hook with access to local persona state and configuration files.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

References to unpinned npx openpersona in field reference/usage guidance perpetuate insecure copy-paste usage. The context is especially sensitive because the skill is explicitly designed to lead an agent to execute these commands on behalf of users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using unpinned npx clawhub to search external skills introduces another mutable remote execution source beyond openpersona. Because this step can influence what further skills get installed, compromise here can steer users toward malicious follow-on packages as well.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill explicitly instructs creation of new SKILL.md files under a persistent runner skill directory (~/.openclaw/skills/<skill-name>/SKILL.md) with complete implementation instructions. This enables durable modification of the agent's future behavior and expands the trusted code/instruction surface across sessions, which is dangerous if generated from imperfect prompts or adversarial user input.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
If the user needs a capability not found in any ecosystem:

1. Discuss what the skill should do
2. Create a SKILL.md file with proper frontmatter (name, description, allowed-tools)
3. Write complete implementation instructions (not just a skeleton)
4. Save to `~/.openclaw/skills/<skill-name>/SKILL.md` (OpenClaw) or your runner's skill directory
5. Register with your agent runner (e.g. add to `openclaw.json` for OpenClaw)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The ACN registration command is unpinned and may process sensitive agent metadata and API-key-related workflow artifacts. A compromised CLI at this step could exfiltrate endpoint information or tamper with registration outputs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Refinement/evolution commands still depend on mutable package resolution through npx openpersona. Even if the feature is local-first, the bootstrap trust boundary remains npm at execution time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The management command block repeatedly instructs users to run unpinned npx openpersona for install/search/list and related actions. The volume of these occurrences shows an ingrained unsafe operational pattern, increasing likelihood of real-world exploitation through dependency confusion, typosquatting, or upstream compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Fork/update/reset flows again rely on unpinned package execution. These operations touch existing persona state, so a malicious package could alter historical data, inject persistence, or corrupt local registries.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Export/import/report/canvas commands are all documented via unpinned npx openpersona. Import is particularly sensitive because it combines mutable bootstrap with archive handling, a common high-risk operation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Community and skill-registry commands use unpinned npx openpersona, including operations that fetch from GitHub or overwrite local skill content. This creates a broad remote-code-execution and supply-chain surface tied directly to package-management and persistence actions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Skill install/update/publish/info examples continue the same unpinned execution pattern. Because these commands manage reusable skills for any runner, compromise can propagate beyond a single persona into the broader agent environment.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:433