Back to skill

Security audit

Openclaw Brain Core Ultra

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed reasoning-helper skill that is broad, but its active instructions are mostly scoped to complex or high-risk tasks and do not add hidden execution, network, or persistence behavior.

Install this only if you want a broad reasoning and verification framework to influence complex or high-risk tasks. Be aware that README.md and the bundled backup are more expansive than the active SKILL.md, so the publisher should clean those up, but I did not find hidden execution, credential collection, exfiltration, destructive behavior, or automatic persistence.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest and opening metadata describe the file as a changelog/documentation artifact, but the content actually defines a powerful behavior-shaping reasoning framework. This mismatch can bypass user/operator expectations and review processes, causing the skill to be loaded or trusted under false pretenses.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The file metadata description conflicts with the stated skill purpose in the surrounding manifest context, which creates ambiguity about what the skill is supposed to do. In security-sensitive agent systems, misleading metadata weakens governance, approval, and safe invocation boundaries.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill says it should not replace the agent's core identity, yet later instructs the agent to adopt a new identity and apply the framework broadly. That contradiction can let the skill override higher-level system behavior, expanding its influence beyond a bounded helper role.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The usage guidance says to use the skill 'when the conditions in the description are met,' but the description itself is broad and subjective. For a meta-skill that influences reasoning across tasks, this ambiguity can cause over-activation, making the agent apply an expansive control framework in situations where it is unnecessary or conflicts with more specific skills or policies.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description covers 'high-level reasoning and decision orchestration' with broad capabilities such as tool selection, anti-hallucination, and completion verification, which can overlap with many normal agent tasks. Because this is presented as a meta-skill that 'shapes every response,' the broad trigger increases the chance of this skill taking precedence too often, expanding its influence beyond intended use and potentially altering agent behavior globally.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The skill metadata and body consistently force Indonesian-language behavior (for example, the description and many directives are written as mandatory behavior), without any user opt-in or locale negotiation. In a meta-reasoning skill, this is more dangerous than in a narrow content skill because it can influence most downstream interactions, causing user intent mismatch, degraded comprehension, and unsafe execution if critical instructions or confirmations are misunderstood.

Vague Triggers

High
Confidence
96% confidence
Finding
The activation trigger is vague and broad, causing the skill to match a wide range of requests. In an agent environment, overbroad activation of a meta-reasoning skill can effectively hijack normal behavior, interfere with more specific skills, and create an unreviewed path for persistent behavioral control.

Vague Triggers

High
Confidence
97% confidence
Finding
The usage guidance says to activate the framework on every task, which turns a scoped skill into a near-global override. Because this skill governs reasoning, planning, tool use, verification, and identity framing, universal activation greatly increases the chance it will dominate the agent's behavior and bypass intended skill isolation.

Static analysis

No suspicious patterns detected.