Back to skill

Security audit

Context Hygiene

Security checks for vulnerabilities and agentic risk

Overview

This is a plain Markdown guidance skill for trimming agent context, with some practical cautions around deleting memory notes and using a fixed timezone example.

Install only if you want an agent to maintain and prune its own workspace context. Ask the agent to show diffs before deleting memory or editing startup files, back up important notes, confirm your real timezone, and avoid running the optional validator unless you trust and verify the installed package.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:117
Finding

Unpinned Third-Party Package Installation and Immediate Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 117
Vulnerability Type: Supply-chain exposure through an unpinned executable dependency
Risk Level: Medium

Complete Code Snippet:

markdown
This tool follows the [Agent-Native CLI Convention](https://ancc.dev). Validate with: `clawhub install ancc && ancc validate .`

Technical Analysis

The documented validation procedure installs the mutable package name ancc without specifying an audited version, immutable digest, trusted registry identity, or signature-verification requirement. It then immediately runs the installed executable.

Package names alone do not cryptographically bind an installation to the linked website or stated canonical repository. If the package source, publishing account, registry resolution process, or latest release is compromised, the installed program can contain behavior that was not present when this skill was audited.

Attack Path

  1. An attacker compromises the package publisher, registry entry, distribution channel, or another component involved in resolving ancc.
  2. The attacker publishes a modified package under the same mutable package name.
  3. A user or agent follows the documented command and installs the current package.
  4. The shell proceeds directly to ancc validate . after installation succeeds.
  5. Package-controlled code executes with the permissions of the invoking user and receives the project directory as its validation target.

Impact Assessment

Successful exploitation could provide code execution with the invoking user's privileges. The malicious dependency could read or modify files accessible to that account, tamper with the audited workspace, inspect locally available configuration or credentials, and potentially initiate network activity. The effective scope is limited by the operating-system permissions and sandbox restrictions applied to the invoking process.

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specifically reviewed version and, where supported, an immutable artifact digest or repository commit.
  • Document the exact trusted registry and publisher identity from which the package must be obtained.
  • Require verification of a cryptographic signature or published checksum before execution.
  • Separate installation and execution into distinct, user-approved steps rather than chaining them.
  • Run validation in a restricted environment with minimal filesystem access, no unnecessary credentials, and network access disabled unless explicitly required.
  • Explain which files the validator reads or changes and provide a non-executing verification alternative where possible.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Destructive Context-Pruning Rules Lack Confirmation and Recovery Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20, 39–43, and 59
Vulnerability Type: Unsafe deletion of persistent workspace and agent context
Risk Level: Medium

Complete Code Snippets:

markdown
3. **Collapse** — write the decision, delete the exploration
markdown
- Version changed → update in place, don't append
- Problem solved → remove from open issues
- Tool replaced → remove old entry
- Info >30 days with no recent relevance → remove
- Never duplicate what's in a SKILL.md or config file
markdown
A reference to something that no longer exists (old path, removed tool, fixed bug) is ghost context. It biases reasoning toward a past state. Find and remove during heartbeat maintenance.

Technical Analysis

The skill instructs an agent to delete information classified as exploration, stale material, solved issues, replaced tools, or ghost context. These classifications require subjective judgment, but the instructions do not require a preview, user confirmation, protected-file allowlist, backup, version-control checkpoint, or reversible archival process.

Because the targeted files represent persistent agent memory and operational context, an incorrect classification can remove valid evidence, unresolved issue history, configuration rationale, or information needed by future sessions. The line-age rule also treats age and perceived relevance as deletion criteria without accounting for retention, compliance, or audit requirements.

Attack Path

  1. The skill is loaded for routine context or heartbeat maintenance.
  2. The agent reviews persistent memory and workspace files.
  3. Valid information is mistakenly classified as exploration, solved, replaced, stale, or a ghost reference.
  4. Following the skill's instructions, the agent removes or overwrites that information without presenting a proposed diff or requesting approval.
  5. Later sessions operate with ...[truncated 776 chars]
Remediation
View remediation

Remediation Suggestions

  • Archive content by default instead of permanently deleting it.
  • Require the agent to produce a proposed diff and obtain explicit user approval before modifying persistent memory or operational files.
  • Restrict automated pruning to an explicit allowlist of files and prohibit changes outside the active workspace.
  • Create a version-control checkpoint or timestamped backup before every pruning operation.
  • Define objective deletion criteria and protected categories, including security decisions, unresolved risks, compliance records, configuration rationale, and user constraints.
  • Treat age as a review trigger rather than an automatic deletion criterion.
  • Preserve a concise deletion log containing the affected file, reason, timestamp, and recovery location.
  • Validate references before labeling them as obsolete, and move uncertain entries to a quarantine or review section.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description says to use the skill when 'setting up a new OpenClaw agent,' 'optimizing token usage,' or when 'conversation quality degrades from context bloat.' These activation conditions are descriptive but not tied to explicit trigger phrases, boundaries, or exclusion conditions, which could cause the skill to be invoked in a wide range of ordinary agent-maintenance situations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup section tells users to set a timezone value to a specific example and frames omission as harmful, without clearly making it an example or requiring user confirmation. In practice, this can cause agents to assume or overwrite locale-sensitive preferences, leading to incorrect scheduling, timestamps, reminders, or region-specific behavior that affects integrity of downstream actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.