Back to skill

Security audit

COC Soul Immortality

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent backup-and-recovery purpose, but it needs Review because it can publish broad private agent data off-host with weak defaults and has a documented package version mismatch.

Install only after reviewing the exact @chainofclaw/soul package version that will run. Before any backup, disable autoBackup and backupOnSessionEnd unless intentionally needed, turn on encryption, narrow backup categories, treat recovery files and signing keys as secrets, and avoid the unsafe force-install command unless you have independently verified the package and need to repair a broken install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/backup.md:207
Finding

Automatic plaintext upload of private conversations, memory, and workspace state to IPFS

Content
View full analysis

Vulnerability Details

File Location: references/backup.md:3-7, 207-250, 329-335; references/config.md:16-37, 139-143; SKILL.md:191-209, 234-235
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Critical

Vulnerable Snippets

From references/backup.md:3-7:

text
## First-time

- `backup init` — register the agent on SoulRegistry (if not yet registered), run a first **full** backup, write `~/.coc-backup/latest-recovery.json` with the decryption material + manifest CID.
- `backup register` — register on-chain only, do not run a backup.

## Periodic

- `backup create` — incremental (default); `--full` forces a full backup regardless of chain length.
  - `backup.autoBackup: true` + `backup.autoBackupIntervalMs` runs this on a timer inside the OpenClaw plugin.
- `backup.backupOnSessionEnd: true` + a `session_end` hook from OpenClaw also triggers `backup create` when the agent's session closes.

From references/backup.md:214-250:

text
### Memory (markdowns; root **or** `workspace/`; not encrypted)
- `MEMORY.md`
- `USER.md`
- `RECOVERY_CONTEXT.md` (regenerated on restore)
- everything under `memory/*.md` **or** `workspace/memory/*.md` (1.2.9+) — daily / per-topic notes (`workspace/memory/2026-04-27.md`, `workspace/memory/topic-foo.md`, etc.)

### Workspace (markdowns + state; root **or** `workspace/`; not encrypted)
- `AGENTS.md`
- `TOOLS.md` — tools manifest (1.2.9+)
- `HEARTBEAT.md` — soul's own heartbeat file (1.2.9+; soul writes it, soul backs it up)
- `workspace-state.json` (root location, legacy)
- `workspace/.openclaw/workspace-state.json` (current OpenClaw layout, 1.2.9+)

### Identity / config (fixed paths)
- `identity/device.json` (config, **encrypted**)
- `identity/device-auth.json` (config, **encrypted**, 1.2.9+ — paired with device.json for cross-device auth)
- `auth.json` (config, **encrypted**)
- `openclaw.json` (config, **encrypted**
...[truncated 4247 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require authenticated encryption for every remotely stored file and manifest; do not permit plaintext IPFS uploads in normal operation.
  2. Change encryptMemory to true by default and extend encryption to chat, identity Markdown, workspace data, plugin metadata, and semantic snapshots.
  3. Disable autoBackup, backupOnSessionEnd, semantic snapshots, and every data category by default.
  4. Require explicit informed consent for each category before its first upload, with a preview of files, total size, destination, encryption mode, and retention implications.
  5. Separate DID registration from backup initialization so registering an identity never implicitly uploads local data.
  6. Use envelope encryption with per-backup data keys and a hardware-backed, KMS-backed, or user-controlled key-encryption mechanism.
  7. Add a strict secret scanner and redaction stage before packaging. Block uploads containing private keys, API tokens, OAuth profiles, session cookies, or authentication material.
  8. Avoid placing manifest CIDs directly on a public chain when doing so increases discoverability; use encrypted indirection or a privacy-preserving registry design.
  9. Add remote unpinning, retention policies, tombstone handling, and clear warnings that third-party IPFS replication may prevent complete deletion.
  10. Require a successful local encryption and restore test before enabling periodic backups.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:198
Finding

Zero-configuration workflow contacts default infrastructure over cleartext HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:198-213
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: High

Vulnerable Snippet

text
## Zero-config on COC testnet (1.1.6+)

**Out of the box, no setup is required to run against COC testnet.** A fresh `openclaw plugins install @chainofclaw/soul` lands an agent that can immediately query the chain, register a soul, and run backups. Specifically, on first activation the plugin:

1. **Auto-generates an agent EOA** if `backup.privateKey` is empty. The key file is written with mode `0o600` to one of (in priority order):
   - `$COC_SOUL_KEYSTORE_PATH` (operator override)
   - `$OPENCLAW_STATE_DIR/coc-soul/keys/agent.key` (set by OpenClaw inside its sandbox — the typical path)
   - `~/.claw-mem/keys/agent.key` (standalone default)

   The chosen path and resulting agent address are logged: `[coc-soul] auto-generated agent key at <path>` and `[coc-soul] agent address: 0x…`.

2. **Auto-drips testnet COC** to the new EOA from the public faucet (`backup.faucetUrl` defaults to `http://199.192.16.79:3003`, 10 COC per drip, 24h per-address cooldown). Logs: `[coc-soul] faucet dripped 10.0 COC to 0x… (tx 0x…)`. So the very first `openclaw coc-soul backup init` already has gas.

3. **Defaults `rpcUrl`, `ipfsUrl`, `contractAddress`, `didRegistryAddress`** to the live COC testnet (RPC `199.192.16.79:28780`, IPFS `199.192.16.79:28786`, deployed SoulRegistry / DIDRegistry).

**You do NOT need to set any of these manually for testnet usage.** The agent should `openclaw coc-soul backup init` directly. Override fields only when targeting mainnet, a private testnet, or an existing wallet.

To bypass the keystore (e.g. use a wallet you already have): set `backup.privateKey` in config. To disable the auto-faucet (mainnet): set `backup.faucetUrl: ""`.

Technical Analysis

The default faucet URL explicitly uses unencrypted HTTP and a bare IP addre ...[truncated 2056 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the HTTP faucet endpoint with an HTTPS endpoint using a valid certificate and a documented domain name.
  2. Reject non-HTTPS remote URLs by default. Permit HTTP only for loopback development endpoints after an explicit insecure-mode opt-in.
  3. Require explicit confirmation before contacting a public faucet or any preconfigured third-party infrastructure.
  4. Authenticate and validate faucet responses against independently queried chain state rather than trusting the HTTP response.
  5. Publish ownership, privacy, retention, and operational documentation for every default service.
  6. Support certificate or public-key pinning for high-assurance deployments.
  7. Clearly display the effective RPC, IPFS, faucet, and contract endpoints before registration or upload begins.
  8. Add connection timeouts, response-size limits, strict schema validation, replay protection, and rate limiting.

T08 · Insecure Dependencies

Error
Location
SKILL.md:4
Finding

Skill version mismatch undermines documented secret exclusions and recommends bypassing installer safety controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:4-19, 82; references/backup.md:257-293, 366
Vulnerability Type: T08: Insecure Dependencies
Risk Level: High

Vulnerable Snippets

From SKILL.md:4-19:

yaml
version: 1.2.10
metadata:
  openclaw:
    homepage: https://www.npmjs.com/package/@chainofclaw/soul
    primaryEnv: CLAW_MEM_DATA_DIR
    requires:
      bins:
        - node
      anyBins:
        - coc-soul
        - openclaw
    install:
      - kind: node
        package: "@chainofclaw/soul"
        version: "1.2.6"
        bins:
          - coc-soul

From SKILL.md:82:

text
| `ENOENT ... backup/targeting.js` | extension install is missing files | Reinstall: `openclaw plugins install @chainofclaw/soul --dangerously-force-unsafe-install --force` |

From references/backup.md:257-263:

text
## What is intentionally excluded — denylist (1.2.10+)

Even when files are in a backed-up directory, the walker / classifier explicitly excludes the following to avoid wasted IO, host-cross-contamination, and circular references:

### Host-local secrets — must NEVER travel between hosts

| File | Why |
|---|---|
| `agents/<id>/agent/models.json` | LLM provider config; post-1.2.6 holds literal API tokens (`ANTHROPIC_AUTH_TOKEN` etc.). Each host has its own provider keys; copying source's keys to target is at best a leak, at worst breaks the target host's auth. Restore the agent, then re-configure provider on target via `openclaw infer model auth login`. |
| `agents/<id>/agent/auth-profiles.json` | OAuth profiles. Same reason — host-local credential state. |

From references/backup.md:366:

text
| `ENOENT ... backup/targeting.js` | extension install corrupt / mismatched | `openclaw plugins install @chainofclaw/soul --dangerously-force-unsafe-install --force` |

Technical Analysis

The Skill identifies itself as versio ...[truncated 2245 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the executable package to the same reviewed release as the Skill documentation.
  2. Fail closed when the Skill version and executable package version do not match.
  3. Add a startup compatibility check that verifies required security features, including the host-secret denylist.
  4. Pin package integrity using a lockfile hash, registry integrity value, signature, or other verifiable provenance mechanism.
  5. Remove --dangerously-force-unsafe-install and --force from normal troubleshooting instructions.
  6. If reinstallation is required, instruct the operator to inspect the installed package, verify its origin and integrity, remove the damaged version safely, and install an exact reviewed version.
  7. Add regression tests demonstrating that models.json, auth-profiles.json, private keys, OAuth tokens, and provider credentials never enter a backup manifest.
  8. Publish version-specific security guarantees rather than describing newer behavior for an older pinned executable.
  9. Include the executable source or a reproducible-build reference in the audit artifact so package behavior can be independently reviewed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (12)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The skill endorses periodic automatic backups and elsewhere describes zero-config behaviors that generate keys, contact a faucet, upload encrypted state to IPFS, and anchor manifests on-chain. Because these actions can occur with minimal user involvement and involve external network effects plus persistent data publication, an over-permissive agent could perform sensitive state-changing operations without explicit contemporaneous approval.

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

md
## Typical flows

1. **First-time soul registration + backup (zero config)** — Just run `openclaw coc-soul backup init`. The plugin auto-generates the agent EOA, auto-drips testnet COC for gas, then registers on SoulRegistry and runs the first full backup. No manual privateKey, no manual faucet, no manual contract addresses. Watch the activation logs to see the chosen keystore path and the agent address.
2. **Periodic incremental backup** — `openclaw coc-soul backup create` (auto runs hourly if `backup.autoBackup: true`).
3. **Inspect agent state** — `openclaw coc-soul backup status` (summary), `openclaw coc-soul backup doctor` (actionable recommendations).
4. **Delegation** — `openclaw coc-soul did delegate --delegator <agentId> --delegatee <targetId> --scope <hash> --expires <epoch> --depth 0`.
5. **Guardian setup** — `openclaw coc-soul guardian add --agent-id <id> --guardian 0x...` (repeat for each guardian).

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The documentation instructs the system to persist latest-recovery.json containing decryption material and restore metadata on disk. Persisting recovery state is functional for backup workflows, but it creates a durable local secret that can be stolen by anyone with filesystem access and materially lowers the barrier to unauthorized restore.

Content

Scanner excerpt · references/backup.md (reported line 5)May include surrounding context.

md
## First-time

- `backup init` — register the agent on SoulRegistry (if not yet registered), run a first **full** backup, write `~/.coc-backup/latest-recovery.json` with the decryption material + manifest CID.
- `backup register` — register on-chain only, do not run a backup.

## Periodic

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

backup init is documented as writing latest-recovery.json containing decryption material and manifest identifiers, but the first-time section does not immediately warn that this file is highly sensitive. An operator could leave it on disk or copy it insecurely, increasing the chance of unauthorized backup restoration or disclosure of recovery secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The auto-backup options describe timer- and hook-based backups without an immediate warning that they can repeatedly write sensitive recovery metadata and transmit backup contents off-host to IPFS and optionally on-chain. This can lead to unintentional continuous exfiltration or persistence of sensitive agent state if an operator enables the feature without understanding the consequences.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/backup.md (reported line 69)May include surrounding context.

md
## Restore (safety-first)

**Default: restore to `/tmp` first, verify, then promote.** Never overwrite a production directory with an unverified backup.

### Pre-restore inspection

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/backup.md (reported line 159)May include surrounding context.

md
2. Edit only A-class fields
3. For C-class fields in `openclaw.json`, **merge** rather than overwrite: keep the target host's existing `gateway.auth.*` / `gateway.bind` / `plugins.allow` exactly; only adopt the backup's agent-portable fields
4. Skip B-class files entirely
5. Write a `rebase-report.json` next to the restored tree so operators can audit what changed

**Step 4 — auth: re-confirm before launching the gateway.**

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/backup.md (reported line 180)May include surrounding context.

md
### Auth-mode preservation rule (must read before any production restore)

The most common production-breaking restore mistake: backup contains `gateway.auth.mode = "token"` with a valid token from the source host; target host has been carefully configured with `mode = "trusted-proxy"` or `"password"`. A literal-overwrite restore replaces target's auth, then the operator on target can't log in anymore — and **the backup's token is for a different gateway instance, useless on this host**.

Rule: **`gateway.auth` is a property of the host, not of the agent.** It does not get restored. The smart-rebase path explicitly preserves the target host's `gateway.auth.*` block. If you must do a literal overwrite (e.g. recovering on a fresh host with no existing config), regenerate auth before starting the gateway:

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document first lists agents/<id>/agent/models.json under encrypted files that are backed up, then later states the same file is intentionally excluded because it contains host-local LLM API tokens. That contradiction can cause operators or implementers to back up and restore sensitive provider credentials across hosts, creating credential leakage and broken target-host configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation presents a primary configuration example with encryptMemory: false, while the stronger warning that IPFS payloads may be plaintext appears later in recommended overrides. That can cause operators to deploy backups that upload sensitive memory data unencrypted to content-addressed storage, creating confidentiality risk if the CID is disclosed or the IPFS endpoint is not strictly private.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/config.md (reported line 58)May include surrounding context.

md
| `contractAddress` | yes for write | SoulRegistry deployment address |
| `didRegistryAddress` | yes for DID ops | |
| `ipfsUrl` | yes for backup | Default `http://127.0.0.1:5001` (local Kubo) |
| `privateKey` | yes for write | Use `chmod 600` on the config file |

## Key handling

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The minimal viable config encourages immediate use of backup with testnet defaults and auto-generated credentials, but does not prominently warn that backup operations may still transmit user data to IPFS/RPC services. Users may interpret the example as safe-by-default and unknowingly exfiltrate workspace, memory, chat, or identity data to external infrastructure.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says to use the skill whenever the user wants an agent to survive device loss, transfer ownership, delegate capabilities, run a guardian/carrier node, inspect identity state, or get persistent memory. This is a wide set of natural-language intents without explicit trigger phrases, exclusions, or negative examples, which can make activation scope ambiguous in a manifest/markdown context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.