Back to skill

Security audit

Lineage Code Mini

Security checks for vulnerabilities and agentic risk

Overview

This skill is review-worthy because it persistently profiles user behavior and installs mutable global npm code, though the reviewed files do not show theft or destructive behavior.

Install only if you are comfortable with the agent keeping local behavioral profile data across sessions. Review or pin the npm dependency before running setup, avoid appending generated USER.md content without reading it first, and periodically inspect or delete the skill's data directory if you do not want profiling retained.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
setup.sh:17
Finding

Unpinned Third-Party Package Retrieval and Global Installation

Content
View full analysis

Vulnerability Details

File Location: setup.sh:17-19; related installation guidance at SKILL.md:104-109
Vulnerability Type: Unpinned and globally installed third-party dependencies
Risk Level: Medium

Vulnerable Code

setup.sh:17-19:

bash
if ! node --input-type=module -e "await import('lineage-code-mini')" 2>/dev/null; then
  echo "Installing lineage-code-mini..."
  npm install -g lineage-code-mini
fi

SKILL.md:104-109:

bash
npx clawhub@latest install lineage-mini

Or manually: copy this skill/ directory into your ~/.openclaw/skills/lineage-mini/.

Technical Analysis

The setup script installs lineage-code-mini without specifying an exact version or verifying an integrity hash. The documentation similarly recommends executing clawhub@latest. Both package references are mutable: the code retrieved at installation time can differ from the code that existed when this skill was audited.

The global npm installation can run package lifecycle scripts with the permissions of the user executing setup.sh. It also modifies global npm state rather than isolating the dependency within the skill. The project contains no lockfile, package integrity metadata, vendored source, or other mechanism that binds installation to a reviewed artifact.

This finding does not establish that either external package is malicious. It identifies a supply-chain boundary that cannot be verified from the supplied project and that allows future package versions or compromised transitive dependencies to introduce executable code.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, registry delivery path, or a transitive dependency.
  2. The attacker publishes a malicious release under the expected package name or introduces malicious lifecycle behavior.
  3. A user runs setup.sh, or follows the documented npx clawhub@latest installation command.

...[truncated 846 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every package to an exact, reviewed version rather than using an implicit latest version or @latest.
  2. Install dependencies locally within the project instead of using npm install -g.
  3. Add a committed lockfile containing npm integrity metadata and use npm ci for reproducible installation.
  4. Where compatible with package functionality, use npm ci --ignore-scripts to prevent automatic lifecycle-script execution.
  5. If lifecycle scripts are required, review and explicitly document them before permitting execution.
  6. Replace npx clawhub@latest with a pinned version and verify the downloaded artifact against a trusted checksum or signature.
  7. Run installation under a dedicated, least-privileged account or within a sandbox.
  8. Include the reviewed dependency source or software bill of materials so the effective executable dependency tree can be audited.

other

Warning
Location
SKILL.md:62
Finding

Persistent Plaintext Behavioral Profiling and Prompt-State Modification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:62-72 and SKILL.md:87-97
Vulnerability Type: Privacy-sensitive behavioral profiling and persistent prompt modification
Risk Level: Medium

Vulnerable Instructions

SKILL.md:62-72:

markdown
When this skill is loaded, you should:

1. **Before each response**, check if a user profile exists at `{baseDir}/data/profiles/`. If it does, read it and apply the behavioral hints to your response style.

2. **After each conversation turn**, record the interaction:
   - Was the user's response positive/engaged? (replied, followed up, said thanks, acted on suggestion) → `accepted: true`
   - Was it negative/disengaged? (ignored, changed topic, expressed frustration, no reply) → `accepted: false`

3. **Every 10 interactions**, run compactification to update the profile.

SKILL.md:87-97:

markdown
## SOUL.md Integration

Generate a section for your SOUL.md or USER.md:

```bash
node --input-type=module -e "
import { compactify, asSoulPatch, DEFAULT_CONFIG } from 'lineage-code-mini';
import { existsSync, readFileSync } from 'node:fs';
const historyPath = '{baseDir}/data/interactions.json';
const history = existsSync(historyPath) ? JSON.parse(readFileSync(historyPath, 'utf8')) : [];
const profile = compactify('current-user', history, DEFAULT_CONFIG);
console.log(asSoulPatch(profile));
"
text

The subsequent instruction at `SKILL.md:99` states:

```markdown
Append the output to your USER.md for persistent behavioral adaptation.

Technical Analysis

The skill directs the host agent to record engagement information after every conversation turn and to derive a behavioral profile every ten interactions. It further directs the agent to read that profile before responses and offers a mechanism for appending package-generated text to persistent USER.md state.

The project states that interaction history and profiles are sto ...[truncated 2347 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed user opt-in before recording any interaction or deriving behavioral profiles.
  2. Clearly document what fields are collected, their purpose, where they are stored, and how long they are retained.
  3. Collect only the minimum information necessary and avoid retaining raw conversation content or sensitive personal data.
  4. Provide commands to inspect, export, disable, and permanently delete interaction history and generated profiles.
  5. Apply restrictive filesystem permissions to the data directory and profile files.
  6. Establish a bounded retention period and automatically remove expired interaction records.
  7. Do not append package-generated text directly to USER.md. Store derived preferences as structured data and apply them through a constrained, validated template.
  8. Validate generated profile fields against a strict schema and reject instructions, executable content, role changes, tool directives, or attempts to override system and safety policies.
  9. Clearly delimit behavioral hints as untrusted preference data and ensure higher-priority system and safety instructions always take precedence.
  10. Audit the source and exact pinned version of lineage-code-mini, particularly the implementations of compactify(), pipeline(), and asSoulPatch().
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description says the skill performs behavioral adaptation by building a lightweight user profile from interaction history and adjusting agent responses. The provided code only prepares directories/files and ensures availability of an external package via global npm installation. There is no code here that reads interaction history for profiling, computes preferences, or adapts response style, timing, topic focus, or recovery behavior. The setup actions may support a larger skill, but this specific code chunk's actual behavior is materially different from the declared purpose and includes an undeclared package installation capability.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill explicitly tells the host agent to wire conversation capture into its turn loop and to apply stored profile hints before each response. In context, this is more dangerous because the skill’s purpose is behavioral adaptation, so the captured conversation data and injected profile context can leak sensitive user information into prompts, files, or downstream systems and alter model behavior based on hidden persistent state.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
## Automatic Adaptation

This skill provides the commands and storage layout. Your host agent still needs to call these commands or wire recording into its turn loop. Installation alone does not automatically capture conversations.

When this skill is loaded, you should:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to persistently store interaction history and derived behavioral profiles without any user-facing notice, consent flow, retention policy, or privacy boundary. This is dangerous because it normalizes silent profiling of users and may capture sensitive preference or behavioral data that can later be exposed, misused, or retained longer than intended.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions direct persistent recording of engagement outcomes, topic affinities, style preferences, and other behavioral traits for reuse across future interactions. In the context of an agent skill, this increases the risk of long-term profiling, accidental data leakage from local JSON files, and unauthorized reuse of sensitive behavioral inferences beyond the user’s expectations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The installation step uses npx clawhub@latest install lineage-mini, which fetches and executes the latest remote package version at runtime rather than a pinned, reviewed version. This creates a supply-chain risk: if the package or one of its dependencies is compromised, loading the skill could execute unintended code in the host environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup script installs a package globally at runtime using npm install -g lineage-code-mini, which exceeds simple local skill initialization and introduces a supply-chain and environment-modification risk. Global installation can affect the host system outside the skill directory, pull unpinned code from the registry, and execute package lifecycle scripts with the user's privileges.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.