Back to skill

Security audit

Evolver (Fixed)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real self-evolution tool, but it combines broad autonomous code-changing authority with remote inputs, telemetry, auto-updates, and background execution that are not consistently scoped or disclosed.

Install only in a disposable or tightly controlled workspace, with review mode enabled, Hub networking disabled unless needed, no ambient GitHub tokens, auto-update disabled, and loop/lifecycle features avoided until you have audited the outbound data and executor behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T03 · Remote Payload Retrieval and Execution

Error
Location
src/gep/prompt.js:12
Finding

Untrusted Hub payloads are converted into authoritative executor instructions

Content
View full analysis
0) { _setPayloadCache(selectedAssetId, fullResults[0]); pick.match = { ...pick.match, ...fullResults[0] }; } } ``` `src/gep/prompt.js:12-45`: ```js function buildReusePrompt({ capsule, signals, nowIso }) { const payload = capsule.payload || capsule; const summary = payload.summary || capsule.summary || '(no summary)'; const gene = payload.gene || capsule.gene || '(unknown)'; const confidence = payload.confidence || capsule.confidence || 0; return ` GEP -- REUSE MODE (Search-First) [${nowIso || new Date().toISOString()}] You are applying a VERIFIED solution from the EvoMap Hub. Summary: ${summary} Instructions: 1. Read the capsule details below. 2. Apply the fix to the local codebase, adapting paths/names. 3. Run validation to confirm it works. 4. If passed, run: node index.js solidify 5. If failed, ROLLBACK and report. Capsule ...[truncated 3618 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/gep/signals.js:145
Finding

Private session and memory excerpts can be transmitted to a configurable Hub without redaction

Content
View full analysis
50000 ? content.slice(0, 50000) + `\n... [TRUNCATED: ${content.length - 50000} chars remaining]` : content; ``` ```js function readUserSnippet() { try { if (!fs.existsSync(USER_FILE)) return '[USER.md MISSING]'; return fs.readFileSync(USER_FILE, 'utf8'); } catch (e) { return '[ERROR READING USER.md]'; } } ``` `src/gep/signals.js:160-172`: ```js var errLine = lines.find(function (l) { return /\b(typeerror|referenceerror|syntaxerror)\b\s*:|error\s*:|exception\s*:|\[error|错误\s*[::]|异常\s*[::]|报错\s*[::]|失败\s*[::]/i.test(l); }) || null; if (errLine) { var clipped = errLine.replace(/\s+/g, ' ').slice(0, 260); signals.push('errsig:' + clipped); } ``` `src/gep/signals.js:213-245`: ```js var featureRequestSnippet = ''; var featEn = corpus.match( /\b(add|implement|create|build|make|develop|write|design)\b[^.?!\n]{3,120}\b(feature|function|module|capability|tool|support|endpoint|command|option|mode)\b/i ); if (featEn) { featureRequestSnippet = featEn[0] .replace(/\s+/g, ' ') .trim() .slice(0, 200); } if (featureRequestSnippet) { signals.push('user_feature_request:' + featureRequestSnippet); } ``` `src/gep/hubSearch.js:239-263`: ```js const searchMsg = buildFetch({ s ...[truncated 2291 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/gep/deviceId.js:48
Finding

Hardware-derived stable device identifier and detailed environment fingerprint are sent externally

Content
View full analysis
= 16) return mid; } catch {} if (process.platform === 'darwin') { try { const { execFileSync } = require('child_process'); const raw = execFileSync( 'ioreg', ['-rd1', '-c', 'IOPlatformExpertDevice'], { encoding: 'utf8', timeout: 3000, stdio: ['ignore', 'pipe', 'ignore'], } ); const match = raw.match(/"IOPlatformUUID"\s*=\s*"([^"]+)"/); if (match && match[1]) return match[1]; } catch {} } return null; } ``` `src/gep/deviceId.js:112-132`: ```js function generateDeviceId() { const machineId = readMachineId(); if (machineId) { return crypto.createHash('sha256') .update('evomap:' + machineId) .digest('hex') .slice(0, 32); } const containerId = readContainerId(); if (containerId) { return crypto.createHash('sha256') .update('evomap:container:' + containerId) .digest('hex') .slice(0, 32); } const macs = getMacAddresses(); if (macs.length > 0) { const raw = os.hostname() + '|' + macs.join(','); return crypto.createHash('sha256') .update('evomap:' + raw) .digest('hex') .slice(0, 32); } return crypto.randomBytes(16).toString('hex'); } ``` `src/gep/envFingerprint.js:45-60`: ```js return { device_id: getDeviceId(), node_version: process.version, platform: process.platform, arch: process.arch, os_release: os.release(), hostname: crypto.createHash('sha256') .update(os.hostname()) .digest('he ...[truncated 2754 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
src/evolve.js:722
Finding

Forced remote Skill updates execute by default without version or integrity pinning

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/gep/issueReporter.js:16
Finding

Automatic GitHub issue reporting is enabled in code despite documentation declaring it disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/evolve.js:517
Finding

Environment-controlled integration status value is executed as an arbitrary shell command

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:257
Finding

Skill instructions replace agent identity and mandate autonomous modifications without a demonstrated need

Content
View full analysis
**Repair Mode** (Fix bugs). - If **Stable** -> **Forced Optimization** (Refactor/Innovate). ``` ### Technical Analysis The Skill explicitly injects a replacement identity and mandates modification in both failure and stable states. A stable state does not permit a no-op; it triggers “Forced Optimization.” These instructions are broader than a task-bounded diagnostic or repair capability. They can override the agent’s current priorities and encourage modifications unrelated to an explicit user request. Review mode is optional rather than the default. Combined with default OpenClaw bridging and external Hub content, the instructions increase the likelihood that remote or automatically generated recommendations will be applied without sufficient user oversight. ### Attack Path 1. The Skill is loaded into an agent session. 2. The identity instruction reframes the agent as a recursive self-improving system. 3. The directive requires repair when errors exist and forced optimization when the system is stable. 4. A default automated run generates an executor prompt. 5. Under an OpenClaw host, the bridge can launch an executor agent. 6. The executor modifies the repository even when no explicit repair is required. 7. The resulting changes may be solidified and affe ...[truncated 701 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (203)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document explicitly says the tool does not execute arbitrary shell commands, but later admits shell execution for validation and provides lifecycle operations that perform system-affecting actions. Contradictory safety claims in a skill with shell permission are dangerous because users may rely on the stronger statement and enable the tool in higher-trust environments than they otherwise would.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Process discovery, daemonization, termination, PID management, and auto-restart create persistence and control risks in a privileged agent. In the context of self-modification and network access, this can make unsafe behavior long-lived, harder to stop, and able to interfere with other local processes.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:242

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/build_public.js:170

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/generate_history.js:17

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/publish_public.js:13

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/recover_loop.js:19

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/suggest_version.js:27

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/validate-suite.js:37

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/evolve.js:485

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/gitOps.js:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/idleScheduler.js:39

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/llmReview.js:70

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/ops/health_check.js:20

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/ops/lifecycle.js:27

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/ops/self_repair.js:17

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/ops/skills_monitor.js:96

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/bridge.test.js:98

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/loopMode.test.js:129

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
index.js:109

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/gep/a2aProtocol.js:75

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/gep/hubReview.js:104

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/gep/hubSearch.js:75

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/gep/issueReporter.js:21

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/gep/memoryGraphAdapter.js:77

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/gep/taskReceiver.js:11

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/sanitize.test.js:12

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
src/gep/a2aProtocol.js:429