Back to skill

Security audit

ClawMind

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it can persist raw user context, modify the user profile, and automatically create future skills without clear review controls.

Review before installing. Use this only if you are comfortable with a local memory/self-management skill that writes persistent workspace state, stores raw conversation or task context, can append to USER.md, and can create new skills that may affect future agent behavior. Prefer a version with explicit opt-in, review-before-activation for generated skills, redaction, retention controls, and delete/rollback support.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
scripts/auto_created_skill.py:117
Finding

Persistent System-Prompt Injection Through Automatically Generated Skills

Content
View full analysis
AutoCreatedSkill | None: """ Create a Skill from a completed task. """ if not self.check_should_create(task_completed): return None name = task_completed.get("task", "untitled") context = task_completed.get("context", "") trigger = task_completed.get("trigger_keywords", []) # Generate Skill name safe_name = re.sub(r'[^a-zA-Z0-9_-]', '_', name)[:50] # Generate system prompt prompt = self._generate_prompt(task_completed) # Generate trigger words if not trigger: trigger = self._extract_keywords(name, context) skill = AutoCreatedSkill( name=f"auto-{safe_name}", description=f"Automatically created Skill derived from task: {name}", trigger=trigger, prompt=prompt, tools=task_completed.get("tools_used", []), examples=[], created_from=task_completed.get("task", ""), ) skill.save() return skill def _generate_prompt(self, task: dict) -> str: """Generate the system prompt for the Skill.""" name = task.get("task", "") context = task.get("context", "") return f"""You are skilled at handling the following task: {name} Background: {context[:500]} When encountering a similar task, follow these steps: 1. Understand the task objective 2. Identify the required tools 3. Create an execution plan 4. Execute the plan 5. Verify the result""" ``` The generated prompt is subsequently placed in a system-prompt section and written to the active workspace Skill directory: ```python ## 系统提示词 {self.prompt} ``` ```python def save(self): """Save the Skill under skills/auto_created/.""" path = os.path.join(SKILLS ...[truncated 2840 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
scripts/auto_created_skill.py:181
Finding

Arbitrary Persistent Modification of the Agent User Profile

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/memory/memory_core.py:170
Finding

Unfiltered Raw Conversation Data Stored Indefinitely in Plaintext SQLite

Content
View full analysis
dict: return { "task_intent": extract_task_intent(raw_log), "approach": extract_approach(raw_log), "key_insight": extract_key_insight(raw_log), "outcome": detect_outcome(raw_log), "tags": extract_tags(raw_log), "raw_log": raw_log, "source": source, "logged_at": datetime.now().strftime("%Y-%m-%d %H:%M:%S"), } def store_experience(exp: dict) -> int: init_db() with sqlite3.connect(DB_PATH, timeout=_SQLITE_TIMEOUT) as conn: c = conn.cursor() c.execute("INSERT INTO conversation_log (raw_text, source, logged_at) VALUES (?, ?, ?)", (exp["raw_log"], exp["source"], exp["logged_at"])) log_id = c.lastrowid c.execute("""INSERT INTO experiences (task_intent, approach, key_insight, raw_log_id, tags, times_used, times_triggered, created_at, last_accessed) VALUES (?, ?, ?, ?, ?, 0, 0, ?, ?)""", (exp["task_intent"], exp["approach"], exp["key_insight"], log_id, json.dumps(exp["tags"], ensure_ascii=False), exp["logged_at"], exp["logged_at"])) ``` The public interface sends arbitrary supplied context into this storage path: ```python def remember(context: str, source: str = "") -> dict: """Accept arbitrary text, extract an experience, and store it.""" init_db() exp = extract_experience(context, source=source) exp_ ...[truncated 2194 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Claiming an autonomous decision engine while primarily performing project/state/task management creates a trust and control gap. The danger is contextual rather than exploit-code specific: agent operators may allow broader invocation or rely on nonexistent safeguards, while the skill persists or manipulates workflow state in ways not clearly disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Claiming an autonomous decision engine while primarily performing project/state/task management creates a trust and control gap. The danger is contextual rather than exploit-code specific: agent operators may allow broader invocation or rely on nonexistent safeguards, while the skill persists or manipulates workflow state in ways not clearly disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Claiming an autonomous decision engine while primarily performing project/state/task management creates a trust and control gap. The danger is contextual rather than exploit-code specific: agent operators may allow broader invocation or rely on nonexistent safeguards, while the skill persists or manipulates workflow state in ways not clearly disclosed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Claiming an autonomous decision engine while primarily performing project/state/task management creates a trust and control gap. The danger is contextual rather than exploit-code specific: agent operators may allow broader invocation or rely on nonexistent safeguards, while the skill persists or manipulates workflow state in ways not clearly disclosed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documents shell execution and state-changing behavior such as running python3 self_driver.py and managing project/task state, but it declares no permissions or allowed-tools scope. In an agent environment, missing tool boundaries can cause the orchestrator or reviewer to underestimate the skill's ability to write files or invoke commands, increasing the chance of unintended workspace modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is very broad, covering vague conditions like self-evolution, autonomy, health tracking, VFM decisions, and memory access without exclusions. Broad triggers increase the chance that an agent invokes the skill in unrelated contexts, which is especially risky when the skill may perform writes, persistence, or other side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The visible user-facing description and title are presented entirely in Chinese, with no indication that language choice is optional or that the skill is intended only for a Chinese-language environment. This can violate language/locale policy when users have not opted into that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's natural-language instructions, trigger descriptions, markdown template sections, and generated system prompt are all hard-coded in Chinese, with no option for the user to choose another language. This creates a locale/language constraint that is not documented as optional or region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The save() method writes newly generated skill artifacts directly into the active skills directory without any user-facing confirmation, review step, or dry-run mode. In an agent framework, silently installing or persisting new executable/instructional artifacts can alter future behavior and create a persistence mechanism the user did not knowingly authorize.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated prompt embeds up to 500 characters of task context, and the resulting skill is then persisted to disk. This creates a durable natural-language retention path for user-supplied content, which may include secrets, personal data, internal instructions, or proprietary information that will later be reloaded and potentially exposed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file includes user-profile modification capability that is not necessary for the advertised automatic skill-creation behavior. Because it appends arbitrary key/value data to a persistent profile file without validation, minimization, or consent, it creates an unjustified persistence channel for user data and behavioral inferences.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

User-profile management is outside the stated purpose of self-evolution and auto skill creation in this file, so its presence expands the skill's authority beyond what a user would reasonably expect. That mismatch increases the risk of stealthy collection or persistence of sensitive information in a location the user may not monitor.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The profile updater appends content directly to a persistent user profile file with no notification, consent, or review. This creates a covert statefulness channel where sensitive disclosures, preferences, or inferred attributes can accumulate over time outside the user's immediate awareness.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The profile updater accepts arbitrary key/value strings and appends them verbatim to a persistent profile file, enabling long-term accumulation of plain-language sensitive data. Because there is no schema enforcement, classification, or filtering, users' personal disclosures or inferred traits can be stored indefinitely and reused in later agent behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language extraction behavior relies heavily on Chinese trigger words and labels, with some mixed English support, and the module description is also Chinese-centric. This effectively enforces a locale/language assumption in the skill behavior without explicit user opt-in or documented justification for the language constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill writes raw conversation text to a fixed persistent SQLite database path without any consent, warning, retention control, or minimization. Because this is a memory skill intended to retain arbitrary agent/user context, it is likely to capture credentials, personal data, internal prompts, or proprietary material and keep it on disk beyond the current session.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The remember interface accepts arbitrary text and persists both the raw log and derived insights/tags, enabling long-term retention of sensitive natural-language content. In the context of an autonomous memory engine, this materially increases exposure because secrets, tokens, personal data, and internal reasoning-like content may be stored and later recalled into future contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains user-facing natural language in comments, docstrings, and printed output that assumes Chinese as the only language. The file does not offer any language selection or explain that it is intentionally limited to a Chinese-speaking context, which conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and many user-facing strings are written only in Chinese, presenting the skill as a Chinese-language engine without any opt-in or alternate locale. The policy requires flagging language or locale constraints when the skill forces a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code persistently writes agent state to a fixed file in the workspace without any user-facing disclosure, consent flow, retention policy, or minimization controls. Because the stored data includes logs, task names, project metadata, timestamps, health metrics, and learned patterns, this creates a privacy and transparency risk and may expose sensitive workflow information to other local components or future readers of the workspace.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill proposes 'checking for skill updates or new skills', which expands its behavior beyond the stated purpose of self-drive, health tracking, VFM scoring, and memory. In an agent ecosystem, autonomous discovery or acquisition of new skills can become a capability-escalation path, especially if other components later act on that proposal without strict approval boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file docstring describes a 'project_manager' for lightweight goal and state management, and the code only reads/writes a local JSON file containing projects, current task, next action, and logs. There is no implementation of health metrics, VFM scoring, self-evolution logic, or experience-memory retrieval/scoring as claimed in the skill manifest, indicating a semantic mismatch between the skill description and this file’s actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The _save function silently overwrites a persistent JSON state file in the user's workspace path. While some function docstrings describe state updates internally, there is no clear user-facing warning that invoking this skill will persist task, project, and log data to disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to natural-language policy violations in all file types. The file presents all instructions and interface descriptions in Chinese, which may force a specific language on users without any opt-in or explanation that the skill is intended only for a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The example at L27 uses add_log("心跳 10:00:完成了模块A开发"), which suggests callers should include a timestamp in the log text. However, L44 explicitly states that logs automatically include timestamps and do not need to be added manually. This is an active contradiction in the documentation about intended API usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.