Self-Modification
- Category
- Rogue Agent
- Confidence
- 90% confidence
- Finding
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
- Content
md - **Does the description trigger?** Try three prompts a real user would type without naming the skill. - **Secrets.** Search the folder for keys, tokens, internal URLs and personal paths before the first push; git history is public too. - **Rights.** The user must own or be allowed to redistribute everything bundled, including scripts, fonts and reference text. - **Security scan triggers.** Instructions to pipe remote scripts into a shell, read credential files, disable safety checks or ignore the user get skills flagged or delisted on ClawHub, agentskill.sh, skills.sh and the Hermes hub.
