Back to skill

Security audit

myskill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed self-improvement logger, but it asks agents to persist and promote learnings into future instruction files and optional always-on hooks without enough scoping or redaction guidance.

Install only if you want a persistent agent memory workflow. Prefer project-scoped hooks over global hooks, use narrow matchers, review every write to .learnings and prompt-bearing files, and redact secrets, personal data, raw transcripts, command arguments, environment values, and business-sensitive context before anything is logged or shared across sessions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:346
Finding

Untrusted learning content can be promoted into persistent agent instructions

Content
View full analysis
= 3` - Seen across at least 2 distinct tasks - Occurred within a 30-day window Promotion targets: - `CLAUDE.md` - `AGENTS.md` - `.github/copilot-instructions.md` - `SOUL.md` / `TOOLS.md` for OpenClaw workspace-level guidance when applicable Write promoted rules as short prevention rules (what to do before/while coding), not long incident write-ups. ``` The broader promotion workflow also states: ```markdown 1. **Distill** the learning into a concise rule or fact 2. **Add** to appropriate section in target file (create file if needed) 3. **Update** original entry: - Change `**Status**: pending` → `**Status**: promoted` - Add `**Promoted**: CLAUDE.md`, `AGENTS.md`, or `.github/copilot-instructions.md` ``` ### Technical Analysis The skill instructs agents to capture corrections, tool failures, API behavior, and other observations in `.learnings/`. Some of those sources can contain attacker-controlled or otherwise untrusted text. It then provides a workflow for converting recurring entries into rules stored in prompt-bearing files such as `AGENTS.md`, `SOUL.md`, `TOOLS.md`, `CLAUDE.md`, and Copilot instructions. These files may be automatically loaded into later agent sessions. The promotion workflow does not require: - Validation of the original content's provenance. - Neutralization of embedded instructions. - Separation of quoted evidence from authoritative rules. - Human approval before persistent prompt files are modified. - Security review of rules inferred from user or tool ...[truncated 1884 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
hooks/openclaw/handler.js:8
Finding

Optional hooks establish a recurring agent instruction-injection channel

Content
View full analysis
After completing this task, evaluate if extractable knowledge emerged: - Non-obvious solution discovered through investigation? - Workaround for unexpected behavior? - Project-specific pattern learned? - Error required debugging to resolve? If yes: Log to .learnings/ using the self-improvement skill format. If high-value (recurring, broadly applicable): Consider skill extraction. EOF ``` ### Technical Analysis Once explicitly installed and enabled, the OpenClaw hook inserts a virtual bootstrap file containing behavioral instructions. The shell activator can also emit instructions after every matching user prompt. The hook content is ...[truncated 2050 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
hooks/openclaw/handler.js:27
Finding

JavaScript runtime handler omits the TypeScript sub-agent exclusion guard

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a logging and continuous-improvement mechanism, but it also instructs extraction of new reusable skills and references helper scripts that create directories and scaffold SKILL.md files. That expands its operational scope beyond passive note-taking into code/workspace mutation, which can surprise operators and bypass least-privilege expectations for a memory skill.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill describes cross-session tools for reading transcripts and sending learnings to other sessions, enabling sensitive conversation content to be copied or propagated in plain language. This broadens access boundaries and increases the blast radius of any accidentally logged secrets or confidential context.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Directing users to modify ~/.claude/settings.json establishes persistence in an agent configuration directory, causing automatic execution of a local command hook in all sessions for that user. Agent config directories are security-sensitive because changes there can silently affect future behavior, expand reach beyond a single project, and survive normal repository cleanup or review boundaries.

Content

Scanner excerpt · references/hooks-setup.md (reported line 48)May include surrounding context.

Option 2: User-Level Configuration

Add to ~/.claude/settings.json for global activation:

json
{

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 177)May include surrounding context.

sessions_send

Send message to another session:

text
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill when a user corrects Claude, when a capability doesn't exist, when a better approach is discovered, and to 'also review learnings before major tasks.' These conditions are broad and partly subjective, making it unclear when the skill should activate versus when normal conversation or routine work should proceed without invoking it.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages storing corrections, feature requests, and broader context in persistent files and promoting them into long-lived memory artifacts across sessions. This creates a clear data-retention pathway for user-supplied natural-language content, which may include sensitive business details, credentials, or personal information not intended for long-term storage.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill directs creation of persistent learning files under a workspace path, which establishes session persistence for conversational and operational data. Persistence is not inherently malicious, but without retention limits, consent, and sanitization, it increases the chance that sensitive data remains available beyond the original task or session.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Recording command inputs, parameters, and environment details in error logs can easily capture API keys, access tokens, connection strings, file paths, hostnames, and other sensitive operational data. Because the skill normalizes writing these details to persistent markdown, it creates a practical secret-spillage channel.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The feature-request template explicitly asks for the user's requested capability and why they needed it, which invites collection of business rationale, internal workflows, and potentially personal or regulated context. Persisting that information in markdown files increases exposure and makes later reuse or exfiltration more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Feature-request triggers such as 'Can you also...', 'I wish you could...', and 'Is there a way to...' are common everyday phrases that may appear in ordinary discussion, not just in situations warranting this skill. Without constraints or negative examples, they risk unintended invocation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/examples.md (reported line 301)May include surrounding context.

When the above learning is extracted as a skill, it becomes:

File: skills/docker-m1-fixes/SKILL.md

markdown
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/hooks-setup.md (reported line 15)May include surrounding context.

Option 1: Project-Level Configuration

Create .claude/settings.json in your project root:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The matcher field is set to an empty string for UserPromptSubmit, which effectively applies the hook to any prompt with no narrowing conditions. This is an ambiguous and overly broad trigger scope that can cause unintended invocations during ordinary usage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to place a command hook in ~/.claude/settings.json, which enables the script across all future sessions and prompts without meaningful scope limits. Because hooks execute automatically with the agent's permissions, global persistence increases blast radius if the script is later modified, replaced, or abused to inject misleading context into unrelated workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Codex configuration example applies the same unrestricted UserPromptSubmit hook with matcher set to an empty string. This lacks specificity on trigger phrases or contexts and risks invocation on routine prompts unrelated to self-improvement capture.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

Creating a persistent .learnings/ directory is not dangerous by itself, but within this skill it is part of a mechanism to retain operational and conversational artifacts across sessions. Without retention, access, and sanitization guidance, the persistence layer can accumulate sensitive data and make it available to future prompts or users of the workspace.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 57)May include surrounding context.

openclaw hooks enable self-improvement

text

### 3. Create Learning Files

Create the `.learnings/` directory in your workspace:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide encourages promoting learnings into persistent workspace files but does not instruct users to sanitize or minimize stored content. Because learnings may derive from failures, corrections, or session context, this can cause sensitive prompts, secrets, internal paths, or user data to be retained beyond the session and later injected into future runs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The cross-session communication section describes reading transcripts and sending messages between sessions without any privacy boundary, authorization check, or data-handling warning. In a system with prompt injection and shared workspace context, this can facilitate lateral movement of sensitive data across sessions and unnecessary exposure of transcript contents.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Phrases like 'Remember this pattern' and 'This would be useful for other projects' are ambiguous and can occur casually without clearly signaling that a learning should become a reusable skill. The file does not provide exclusion rules or disambiguation guidance for these broad prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Although presented as a lower-overhead configuration, the example still sets matcher to an empty string, so activation remains universal for UserPromptSubmit. The guide does not specify boundaries or exclusions for when the hook should avoid running.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The phrase 'Avoid unnecessary caveats and disclaimers' is a natural-language instruction that discourages safety-oriented disclosures in general communication style. While framed as stylistic guidance, it is not scoped or justified and may conflict with organizational expectations to provide appropriate warnings or limitations when needed.

Content

No source excerpt is available for this finding.