Back to skill

Security audit

Self-Evolving Agent ๐Ÿง 

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent self-analysis purpose, but it needs Review because it reads private transcripts and can send transcript excerpts to cloud LLM APIs despite local-only security claims.

Install only if you are comfortable with a local automation reading your OpenClaw transcripts and proposing persistent AGENTS.md changes. Before enabling it, switch llm.provider to ollama or none unless you intentionally want transcript-derived snippets sent to Anthropic/OpenAI, avoid putting webhook or Telegram tokens on command lines, restrict permissions on config files, and review any cron/service registration and every proposed AGENTS.md diff before approval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/v4/synthesize-proposal.sh:480
Finding
Conversation excerpts are transmitted to a remote LLM under the default configuration<![CDATA[ ## Vulnerability Details **File Location**: `config.yaml:18`; `scripts/v4/semantic-analyze.sh:519-528`; `scripts/v4/synthesize-proposal.sh:480-509`; `scripts/v4/llm-call.sh:182-204` **Vulnerability Type**: Sensitive information disclosure through remote processing **Risk Level**: High ### Vulnerable Code Default remote provider: ```yaml llm: provider: "anthropic" # anthropic | openai | ollama | none ``` Raw user-message excerpts are retained in analysis results: ```python if effective_confidence >= 0.5: severity = 'high' if confidence >= 0.85 else ('medium' if confidence >= 0.7 else 'low') context_preview = clean_text[:120].replace('\n', ' ') events.append({ 'session': session['session_id'], 'agent': session.get('agent', ''), 'pattern': ptype, 'context': context_preview, 'severity': severity, 'confidence': round(effective_confidence, 2), 'directed_at_agent': is_directed_at_agent, 'timestamp': msg.get('timestamp', ''), }) ``` The excerpts are included in the LLM prompt: ```bash _ANA_SUMMARY=$(jq -r '{ sessions: .sessions_analyzed, quality: .quality_score, insights: (.key_insights // [] | .[0:5]), top_frustration: (.frustration_events // [] | .[0:3] | map({pattern, severity, context})), exec_loops: (.exec_loops // [] | .[0:3] | map({command_base, count})), violations: (.rule_violations // [] | .[0:3] | map({rule, violation, count})) }' "$ANALYSIS_FILE" 2>/dev/null || echo '{}') _LLM_PROMPT="You are reviewing a self-evolving AI agent's weekly behavior analysis. Based on the following structured data, provide 2-3 specific, actionable improvement proposals. Analysis data: ${_ANA_SUMMARY}" _LLM_RESPONSE=$(echo "$_LLM_PROMPT" | bash "$LLM_CALL_SH" \ --provider "${_SEA_LLM_PROVIDER}" \ --system "You are an expert AI behavior analyst. Generate specific, evidence-based AGENTS.md improvement proposals." \ 2>/tmp/sea-v4/llm-call.log) ``` The resulting p ...[truncated 2237 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Change the default provider to `ollama` or `none`. 2. Require explicit, informed consent before enabling Anthropic, OpenAI, or another remote provider. 3. Remove raw `context` values from remote prompts unless strictly necessary. 4. Add a redaction pass for API keys, access tokens, passwords, email addresses, URLs, filesystem paths, and other identifiers. 5. Provide a preview showing exactly what will be transmitted before remote processing is enabled. 6. Add an explicit configuration option such as `allow_remote_transcript_context: false`. 7. Update `SECURITY.md` to document every remote endpoint and the precise data fields sent. 8. Add automated tests proving that remote prompts contain no raw transcript text when remote disclosure is disabled. ]]>

T01 ยท Skill Instruction Hijacking

Warning
Location
scripts/v4/synthesize-proposal.sh:480
Finding
Transcript content can indirectly inject instructions into proposal-generating LLM prompts<![CDATA[ ## Vulnerability Details **File Location**: `scripts/v4/semantic-analyze.sh:519-528`; `scripts/v4/synthesize-proposal.sh:480-509` **Vulnerability Type**: Indirect prompt injection through untrusted transcript content **Risk Level**: Medium ### Vulnerable Code The analyzer stores untrusted conversation text without converting it into a trusted, inert representation: ```python context_preview = clean_text[:120].replace('\n', ' ') events.append({ 'session': session['session_id'], 'agent': session.get('agent', ''), 'pattern': ptype, 'context': context_preview, 'severity': severity, 'confidence': round(effective_confidence, 2), 'directed_at_agent': is_directed_at_agent, 'timestamp': msg.get('timestamp', ''), }) ``` That text is interpolated into an instruction-bearing prompt: ```bash _ANA_SUMMARY=$(jq -r '{ sessions: .sessions_analyzed, quality: .quality_score, insights: (.key_insights // [] | .[0:5]), top_frustration: (.frustration_events // [] | .[0:3] | map({pattern, severity, context})), exec_loops: (.exec_loops // [] | .[0:3] | map({command_base, count})), violations: (.rule_violations // [] | .[0:3] | map({rule, violation, count})) }' "$ANALYSIS_FILE" 2>/dev/null || echo '{}') _LLM_PROMPT="You are reviewing a self-evolving AI agent's weekly behavior analysis. Based on the following structured data, provide 2-3 specific, actionable improvement proposals. For each proposal: 1. State the problem clearly (1 sentence) 2. Give the evidence from the data (cite numbers) 3. Provide a concrete rule to add/modify in AGENTS.md (before/after format) 4. Estimate impact (high/medium/low) Analysis data: ${_ANA_SUMMARY} Format your response as clean markdown with ### headers for each proposal. Be specific and evidence-based. No vague suggestions." ``` ### Technical Analysis Conversation transcripts are untrusted input. Although excerpts are serialized through JSON, the resulting JSON is embedded directly into a na ...[truncated 1882 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Remove raw conversation excerpts from proposal-generation prompts where possible. 2. Add a strong system instruction stating that all analyzed content is untrusted data and that instructions found inside it must never be followed. 3. Place untrusted fields in a clearly delimited data block and use a rigid schema. 4. Use a separate deterministic process to convert transcript excerpts into non-instructional labels before LLM synthesis. 5. Validate generated proposals against an allowlist of permitted rule categories. 6. Reject proposals that request disabling approval, increasing privileges, exposing secrets, changing tool wrappers, or bypassing safety controls. 7. Display the exact transcript evidence beside each generated rule so reviewers can identify manipulation. 8. Add adversarial prompt-injection fixtures to the test suite. ]]>

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/setup-wizard.sh:546
Finding
Telegram tokens and webhook credentials are stored in plaintext without permission hardening<![CDATA[ ## Vulnerability Details **File Location**: `scripts/setup-wizard.sh:82-83`; `scripts/setup-wizard.sh:474-475`; `scripts/setup-wizard.sh:534-546`; `scripts/setup-wizard.sh:627-634` **Vulnerability Type**: Plaintext credential exposure and insecure secret handling **Risk Level**: High ### Vulnerable Code Secrets can be supplied directly as command-line arguments: ```bash --webhook) OPT_WEBHOOK="$2"; shift 2 ;; --tg-token) OPT_TG_TOKEN="$2"; shift 2 ;; --tg-chat) OPT_TG_CHAT="$2"; shift 2 ;; ``` The existing configuration, including secrets, is copied to a backup: ```bash if [ -f "$CONFIG_FILE" ]; then cp "$CONFIG_FILE" "${CONFIG_FILE}.bak.wizard" 2>/dev/null && \ echo " ${DIM}๋ฐฑ์—…: ${CONFIG_FILE}.bak.wizard${RESET}" fi ``` Credential values are prepared for direct insertion: ```bash local slack_webhook="" [ "$OPT_PLATFORM" = "slack" ] && slack_webhook="$OPT_WEBHOOK" local tg_token="" tg_chat="" [ "$OPT_PLATFORM" = "telegram" ] && tg_token="$OPT_TG_TOKEN" && tg_chat="$OPT_TG_CHAT" local webhook_url="" [ "$OPT_PLATFORM" = "webhook" ] && webhook_url="$OPT_WEBHOOK" cat > "$CONFIG_FILE" << YAML_EOF ``` The secrets are written in plaintext: ```yaml slack: webhook_url: "${slack_webhook}" telegram: bot_token: "${tg_token}" chat_id: "${tg_chat}" webhook: url: "${webhook_url}" method: "POST" ``` ### Technical Analysis The setup wizard writes Telegram bot tokens and webhook URLs directly into `config.yaml`. It also copies the complete prior configuration into `config.yaml.bak.wizard`. The audited code does not set `umask 077`, apply mode `0600`, or otherwise verify restrictive permissions on either file. The documented non-interactive interface additionally encourages passing secrets through `--tg-token` and `--webhook`. Command-line arguments can be exposed in shell history, process inspection tools, CI logs, or job metadata. Webhook URLs commonly contain bearer-like secret material. Possession can permit ...[truncated 1104 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Set `umask 077` before creating configuration or backup files. 2. Explicitly apply `chmod 600 "$CONFIG_FILE"` and equivalent protection to backups. 3. Store tokens in environment variables or an operating-system credential store rather than YAML. 4. Replace `--tg-token TOKEN` with silent input such as `read -rs`, a protected file descriptor, or an environment-variable reference. 5. Never include secrets in shell command examples that are likely to be saved in history. 6. Redact secret-bearing URLs and tokens from all setup output and logs. 7. Avoid duplicating secrets in backups, or encrypt backups using a user-controlled key. 8. Validate ownership and permissions before loading any configuration containing credentials. 9. Rotate all credentials previously stored under permissive filesystem modes. ]]>

T09 ยท Insecure Skill Coding Practices

Error
Location
scripts/v5/orchestrator-v5.sh:166
Finding
Dynamic shell command construction with eval permits command injection<![CDATA[ ## Vulnerability Details **File Location**: `scripts/v5/orchestrator-v5.sh:166-200`; `install/install.sh:43-48` **Vulnerability Type**: Shell command injection through unsafe `eval` **Risk Level**: High ### Vulnerable Code The v5 orchestrator constructs environment assignments and positional arguments as shell text: ```bash local _extra_env="" local _pos_args="" local _sep_found=false for _arg in "$@"; do if [[ "$_arg" == "--" ]]; then _sep_found=true elif [[ "$_sep_found" == "false" ]]; then _extra_env="${_extra_env} ${_arg}" else _pos_args="${_pos_args} '${_arg}'" fi done local _env_str="SHELLOPTS= BASHOPTS=" _env_str="${_env_str} SEA_TMP_DIR='${TMP_DIR}'" _env_str="${_env_str} DRY_RUN='${DRY_RUN}'" _env_str="${_env_str} VERBOSE='${VERBOSE}'" _env_str="${_env_str} MAX_SESSIONS='${MAX_SESSIONS}'" _env_str="${_env_str} COLLECT_DAYS='${COLLECT_DAYS}'" _env_str="${_env_str} WORKSPACE='${WORKSPACE}'" _env_str="${_env_str} OLLAMA_URL='${OLLAMA_URL}'" _env_str="${_env_str} EMBED_MODEL='${EMBED_MODEL}'" _env_str="${_env_str} SIMILARITY_THRESHOLD='${SIMILARITY_THRESHOLD}'" if [[ -n "${_extra_env# }" ]]; then _env_str="${_env_str} ${_extra_env}" fi eval "env ${_env_str} ${_tout} bash '${_script}'${_pos_args}" \ > "$_log" 2>&1 || true ``` The installer uses the same unsafe execution primitive: ```bash run() { if [[ "$DRY_RUN" == true ]]; then echo -e " ${Y}[dry-run]${N} $*" else eval "$*" fi } ``` ### Technical Analysis Shell quoting is applied manually by surrounding values with single quotes, but embedded single quotes are not escaped. The final string is passed to `eval`, causing the shell to parse it a second time. Values such as `WORKSPACE`, `OLLAMA_URL`, stage arguments, and extra environment assignments may originate from environment variables, configuration, or caller-controlled arguments. A value containing a single quote followed by shell syntax can terminate the intended assignment and append a command ...[truncated 1558 chars]
Remediation
<![CDATA[ ## Remediation Suggestions 1. Remove every `eval` used for command execution. 2. Construct environment variables and arguments as arrays: ```bash env_args=( "SHELLOPTS=" "BASHOPTS=" "SEA_TMP_DIR=$TMP_DIR" "DRY_RUN=$DRY_RUN" "VERBOSE=$VERBOSE" "MAX_SESSIONS=$MAX_SESSIONS" "COLLECT_DAYS=$COLLECT_DAYS" "WORKSPACE=$WORKSPACE" "OLLAMA_URL=$OLLAMA_URL" "EMBED_MODEL=$EMBED_MODEL" "SIMILARITY_THRESHOLD=$SIMILARITY_THRESHOLD" ) env "${env_args[@]}" bash "$_script" "${pos_args[@]}" ``` 3. Parse extra environment assignments into validated `NAME=value` array elements. 4. Restrict environment names to a pattern such as `^[A-Z_][A-Z0-9_]*$`. 5. Invoke installer commands directly or through arrays rather than passing command strings to `run`. 6. Validate URL, path, numeric threshold, and model fields before use. 7. Add regression tests containing single quotes, semicolons, command substitutions, newlines, and shell metacharacters. 8. Ensure scheduled jobs run with a minimal, explicitly constructed environment. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (336)

Credential Access

High
Category
Privilege Escalation
Content
~/openclaw/skills/self-evolving-agent/scripts/

# Verify no credential access (grep for common secret paths)
grep -rn '\.env\|id_rsa\|\.ssh\|keychain\|secret\|password\|token' \
  ~/openclaw/skills/self-evolving-agent/scripts/

# Check syntax of all v4 scripts
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The declared description centers on log analysis and generating improvement suggestions for AGENTS.md, with advanced AI/monitoring/reporting features and a claim of proposal-only behavior. The actual code does not analyze logs, use embeddings or LLMs, monitor anything in real time, handle approvals, create reports, integrate with GitHub, or generate AGENTS.md suggestions. Instead, it performs a different primary function: indexing proposal JSON files for a dashboard and writing an output JSON file. While writing an index file is not inherently suspicious, it is materially different from the declared purpose, so this is a clear description-behavior mismatch.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The declared description is for a complex AI automation pipeline that analyzes logs and suggests AGENTS.md improvements. This code does not implement that behavior. Instead, it reads a prebuilt data index, fetches proposal JSON files, aggregates historical proposal/benchmark data, and prepares dashboard-oriented data structures such as quality trends, proposal history, pattern frequencies, rules effectiveness, AGENTS.md health summaries, and stats. It appears to visualize or load results from some external process rather than perform the described analysis itself. While the presence of AGENTS.md-related benchmark fields is loosely related, the actual codeโ€™s role is materially different and much narrower: frontend data loading for a dashboard. Therefore this is a clear description-behavior mismatch.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The declared purpose focuses on automated analysis of logs and generation of improvement proposals for AGENTS.md, with various analytics and reporting features. The actual code chunk does not perform log analysis, embeddings, monitoring, fleet analysis, approvals, report generation, GitHub issue creation, or proposal generation. Instead, it rebuilds an index via another script and launches a local static HTTP server for a dashboard. Serving a dashboard may be a supporting component of a larger system, but this specific code chunkโ€™s primary behavior is local web hosting, which is not represented in the description and is materially different from the declared purpose.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The declared description presents the skill as a log-analysis and recommendation system for improving AGENTS.md, emphasizing analysis features and a non-modifying advisory role. The supplied code chunk does not implement that behavior directly. Instead, it is an auxiliary demo script whose purpose is to execute another script, save console output, and optionally render a GIF. While invoking the orchestrator may support demonstrating the broader system, this code chunk's actual primary function is demo capture, not log analysis or proposal generation. Therefore the description does not accurately represent this specific code chunk.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
์„ค๋ช…์€ ์‹ค์ œ ์ž๋™ํ™” ๊ธฐ๋Šฅ์„ ๊ฐ€์ง„ ๋ถ„์„/์ œ์•ˆ ์‹œ์Šคํ…œ์„ ์ฃผ์žฅํ•˜์ง€๋งŒ, ์ œ๊ณต๋œ ์ฝ”๋“œ๋Š” 'run-demo.sh'๋ผ๋Š” ์ด๋ฆ„ ๊ทธ๋Œ€๋กœ ๋ฐ๋ชจ์šฉ ์ถœ๋ ฅ ์Šคํฌ๋ฆฝํŠธ๋‹ค. sleep, printf, ์ƒ‰์ƒ ์ถœ๋ ฅ์œผ๋กœ ๋‹จ๊ณ„๋ณ„ ์ง„ํ–‰ ์ƒํ™ฉ๊ณผ ๊ฒฐ๊ณผ๋ฅผ ๊พธ๋ฉฐ ๋ณด์—ฌ์ฃผ๋ฉฐ, ์‹ค์ œ๋กœ ์„ธ์…˜์„ ์Šค์บ”ํ•˜๊ฑฐ๋‚˜ ์ž„๋ฒ ๋”ฉ ๋ชจ๋ธ์„ ํ˜ธ์ถœํ•˜๊ฑฐ๋‚˜ ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๋กœ์ง์ด ์—†๋‹ค. ๋˜ํ•œ v5.0/v4.3์—์„œ ๊ฐ•์กฐํ•œ ๊ณ ๊ธ‰ ๊ธฐ๋Šฅ๋“ค(์ž„๋ฒ ๋”ฉ, ์ŠคํŠธ๋ฆฌ๋ฐ ์•Œ๋ฆผ, ํ”Œ๋ฆฟ ๋ถ„์„, ์Šน์ธ, GitHub Issues ๋“ฑ)์ด ์ฝ”๋“œ์— ์กด์žฌํ•˜์ง€ ์•Š๋Š”๋‹ค. ๋‹ค๋งŒ '์ง์ ‘ ์ˆ˜์ • ์ ˆ๋Œ€ ์—†์Œ'๊ณผ ๋Œ€์ฒด๋กœ ์ œ์•ˆ ์ค‘์‹ฌ์˜ ์ฝ˜์…‰ํŠธ๋Š” ์ถœ๋ ฅ ๋‚ด์šฉ๊ณผ ์™„์ „ํžˆ ์ถฉ๋Œํ•˜์ง€๋Š” ์•Š๋Š”๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ํ•ต์‹ฌ ๋ชฉ์ ์ด ์‹ค์ œ ์ž๋™ํ™” ๋„๊ตฌ๊ฐ€ ์•„๋‹ˆ๋ผ ๋ถ„์„ ์‹œ์—ฐ์šฉ ํ”Œ๋ ˆ์ด๋ฐฑ์ด๋ผ๋Š” ์ ์—์„œ ์„ค๋ช…๊ณผ ์‹ค์ œ ๋™์ž‘์€ materially different ํ•˜๋ฏ€๋กœ mismatch๋กœ ํŒ๋‹จํ•œ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
์„ ์–ธ๋œ ์„ค๋ช…์˜ ํ•ต์‹ฌ ๋ชฉ์ ์€ ๋กœ๊ทธ ๋ถ„์„์„ ํ†ตํ•ด AGENTS.md ๊ฐœ์„ ์•ˆ์„ ์ œ์•ˆํ•˜๋Š” ์ž๋™ํ™”์ด๋ฉฐ, ์ง์ ‘ ์ˆ˜์ •์€ ํ•˜์ง€ ์•Š๋Š”๋‹ค๊ณ  ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ œ๊ณต๋œ ์ฝ”๋“œ๋Š” ๋ถ„์„์ด๋‚˜ ์ œ์•ˆ ์ƒ์„ฑ ๋กœ์ง์ด ์•„๋‹ˆ๋ผ, ๋ณ„๋„์˜ stream-monitor.sh๋ฅผ macOS/Linux ์„œ๋น„์Šค๋กœ ์„ค์น˜ยท์ œ๊ฑฐํ•˜๋Š” ์šด์˜์ฒด์ œ ํ†ตํ•ฉ์šฉ ์ธ์Šคํ†จ๋Ÿฌ์ž…๋‹ˆ๋‹ค. ์ด๋Š” ๋‹จ์ˆœ ์ง€์› ์„ธ๋ถ€์‚ฌํ•ญ์„ ๋„˜์–ด์„œ, ์‹ค์ œ๋กœ ์‚ฌ์šฉ์ž ํ™˜๊ฒฝ์˜ ์„œ๋น„์Šค ๋“ฑ๋ก/์‚ญ์ œ์™€ ํŒŒ์ผ ์ƒ์„ฑ ๋“ฑ ์‹œ์Šคํ…œ ๋ณ€๊ฒฝ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๋ณ„๋„ ๋Šฅ๋ ฅ์ž…๋‹ˆ๋‹ค. ์„ค๋ช…์— '์‹ค์‹œ๊ฐ„ ์ŠคํŠธ๋ฆฌ๋ฐ ๋ชจ๋‹ˆํ„ฐ'๊ฐ€ ์–ธ๊ธ‰๋˜๊ธด ํ•˜์ง€๋งŒ, ์ด ์ฝ”๋“œ ์กฐ๊ฐ ์ž์ฒด์˜ ์ฃผ๋œ ๊ธฐ๋Šฅ์€ ๋ชจ๋‹ˆํ„ฐ๋ง์ด ์•„๋‹ˆ๋ผ ์„œ๋น„์Šค ์„ค์น˜ ์ž๋™ํ™”์ด๋ฉฐ, ์„ ์–ธ๋œ ๊ถŒํ•œ์ด ๋น„์–ด ์žˆ๋Š” ์ ๊ณผ๋„ ํ–‰๋™ ๋ฒ”์œ„๊ฐ€ ๋‹ค๋ฆ…๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…๊ณผ ์ฝ”๋“œ ํ–‰๋™ ์‚ฌ์ด์— ์‹ค์งˆ์ ์ธ ๋ถˆ์ผ์น˜๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
์„ค๋ช…๊ณผ ์ฝ”๋“œ์˜ ํฐ ๋ฐฉํ–ฅ์€ '๋กœ๊ทธ/์„ธ์…˜์„ ๋ถ„์„ํ•˜๊ณ  ์ง์ ‘ ์ˆ˜์ •ํ•˜์ง€ ์•Š๋Š”๋‹ค'๋Š” ์ ์—์„œ ์ผ๋ถ€ ์ผ์น˜ํ•œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์„ค๋ช…์ด ๊ฐ•์กฐํ•˜๋Š” ํ•ต์‹ฌ ๊ธฐ๋Šฅ๋“ค(v5.0/v4.x์˜ ์ž„๋ฒ ๋”ฉ, ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง, ํ”Œ๋ฆฟ ๋ถ„์„, ์Šน์ธ, ๋ฉ€ํ‹ฐํฌ๋งท, GitHub Issues)์€ ์ด ์ฝ”๋“œ ์กฐ๊ฐ์—์„œ ์ „ํ˜€ ๊ตฌํ˜„๋˜์ง€ ์•Š์•˜๋‹ค. ๋ฐ˜๋Œ€๋กœ ์ฝ”๋“œ๋Š” ๋กœ์ปฌ ์ •์  ๋ถ„์„ ๋ฐฐ์น˜ ์ž‘์—…์— ๊ฐ€๊น๊ณ , ๋ถˆ๋งŒ ํŒจํ„ด/์žฌ์‹œ๋„/์˜ค๋ฅ˜/์œ„๋ฐ˜ ํƒ์ง€ ์ค‘์‹ฌ์˜ JSON ๋ฆฌํฌํŠธ๋ฅผ ์ƒ์„ฑํ•œ๋‹ค. ๋˜ํ•œ AGENTS.md๋ฅผ ์‹ค์ œ๋กœ ์ฝ๋Š” ๊ฒฝ๋กœ ๋ณ€์ˆ˜๋Š” ์žˆ์œผ๋‚˜ ๋ถ„์„ ๋กœ์ง์—์„œ ํ™œ์šฉ๋˜์ง€ ์•Š์•„ 'AGENTS.md ๊ฐœ์„ ์•ˆ ์ œ์•ˆ' ์ž์ฒด๋„ ์ง์ ‘์ ์œผ๋กœ ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค. ๋”ฐ๋ผ์„œ ์„ ์–ธ๋œ ์„ค๋ช…์€ ์‹ค์ œ ์ฝ”๋“œ๋ณด๋‹ค ํ›จ์”ฌ ๋„“๊ณ  ๋‹ค๋ฅธ ๊ธฐ๋Šฅ์„ ์ฃผ์žฅํ•˜๋ฏ€๋กœ ์‹ค์งˆ์  ๋ถˆ์ผ์น˜๋กœ ํŒ๋‹จ๋œ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
ํ•ต์‹ฌ ๋ชฉ์ ์˜ ์ผ๋ถ€๋Š” ์ผ์น˜ํ•œ๋‹ค. ์ด ์Šคํฌ๋ฆฝํŠธ๋Š” ์‹ค์ œ๋กœ ์ž๊ธฐ ๋ถ„์„ ๊ฒฐ๊ณผ์™€ AGENTS.md๋ฅผ ์ฝ์–ด ๊ฐœ์„  ์ œ์•ˆ์„ ์ƒ์„ฑํ•˜๊ณ  ์ €์žฅํ•˜๋ฉฐ, ์ง์ ‘ AGENTS.md๋ฅผ ์ˆ˜์ •ํ•˜์ง€ ์•Š๋Š”๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์„ ์–ธ๋œ ์„ค๋ช…์€ v5.0/v4.x ๊ธฐ๋Šฅ๋“ค(์‹œ๋งจํ‹ฑ ์ž„๋ฒ ๋”ฉ, Ollama LLM, ์‹ค์‹œ๊ฐ„ ์ŠคํŠธ๋ฆฌ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง, ํ”Œ๋ฆฟ ๋ถ„์„, GitHub Issues, ๋ฉ€ํ‹ฐํฌ๋งท ๋ฆฌํฌํŠธ, ๋Œ€ํ™”ํ˜• ์Šน์ธ)์„ ํฌํ•จํ•ด ํ›จ์”ฌ ๊ด‘๋ฒ”์œ„ํ•œ ์‹œ์Šคํ…œ์„ ์ฃผ์žฅํ•œ๋‹ค. ์ œ๊ณต๋œ ์ฝ”๋“œ ์กฐ๊ฐ์€ v3.0์˜ ๋กœ์ปฌ ๊ทœ์น™ ๊ธฐ๋ฐ˜ ์ œ์•ˆ ์ƒ์„ฑ๊ธฐ์ด๋ฉฐ, ํ•ด๋‹น ๊ณ ๊ธ‰ ๊ธฐ๋Šฅ๋“ค์€ ๊ตฌํ˜„๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. ๋˜ํ•œ ๋ฆฌํฌํŠธ์— '์Šน์ธ ์‹œ AGENTS.md ์ž๋™ ๋ฐ˜์˜ + git commit' ๋ฌธ๊ตฌ๊ฐ€ ์žˆ์œผ๋‚˜, ์ด ์ฝ”๋“œ ์ž์ฒด๋Š” ์Šน์ธ ์ฒ˜๋ฆฌ๋‚˜ ์ˆ˜์ •/์ปค๋ฐ‹์„ ์ˆ˜ํ–‰ํ•˜์ง€ ์•Š๋Š”๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…์ด ์ฝ”๋“œ์˜ ์‹ค์ œ ๋™์ž‘์„ ๊ณผ์žฅยท์˜ค๋Œ€ํ‘œํ˜„ํ•˜๊ณ  ์žˆ์–ด ๋ถˆ์ผ์น˜๋กœ ํŒ๋‹จ๋œ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
์„ค๋ช…์€ '๋กœ๊ทธ ๋ถ„์„ ํ›„ AGENTS.md ๊ฐœ์„ ์•ˆ์„ ์ œ์•ˆํ•˜๋Š”' ๋ถ„์„ ์ž๋™ํ™”์˜ ๋ชฉ์ ์„ ๋งํ•˜์ง€๋งŒ, ์ œ๊ณต๋œ ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ ๊ธฐ๋Šฅ์€ ๊ทธ ๋ถ„์„ ์ž์ฒด๊ฐ€ ์•„๋‹ˆ๋ผ ํ•ด๋‹น ๋ถ„์„ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ •๊ธฐ ์‹คํ–‰ํ•˜๋„๋ก ํฌ๋ก  ์žก์„ ๋“ฑ๋ก/์ˆ˜์ •/์‚ญ์ œํ•˜๋Š” ๊ด€๋ฆฌ ๋„๊ตฌ๋‹ค. ํŠนํžˆ ์„ ์–ธ์—๋Š” '์ง์ ‘ ์ˆ˜์ • ์ ˆ๋Œ€ ์—†์Œ'์ด๋ผ๊ณ  ๋˜์–ด ์žˆ์œผ๋‚˜, ์ด ์Šคํฌ๋ฆฝํŠธ๋Š” AGENTS.md๋ฅผ ์ˆ˜์ •ํ•˜์ง€ ์•Š๋”๋ผ๋„ ~/.openclaw/cron/jobs.json์„ ์ง์ ‘ ๋ณ€๊ฒฝํ•˜๋Š” ๊ตฌ์„ฑ ๋ณ€๊ฒฝ ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•œ๋‹ค. ๋˜ํ•œ ์„ ์–ธ๋œ ๊ถŒํ•œ/ํŠธ๋ฆฌ๊ฑฐ๊ฐ€ ๋น„์–ด ์žˆ๋Š”๋ฐ ์‹ค์ œ ์ฝ”๋“œ๋Š” ์„ค์ • ํŒŒ์ผ๊ณผ ํฌ๋ก  ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ๋ฅผ ์ฝ๊ณ  ์“ฐ๋ฉฐ Discord ์ „๋‹ฌ ์ฑ„๋„๋„ ์„ค์ •ํ•œ๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…๊ณผ ์ฝ”๋“œ์˜ 1์ฐจ ๋ชฉ์  ๋ฐ ์ˆ˜ํ–‰ ๋Šฅ๋ ฅ์ด ์‹ค์งˆ์ ์œผ๋กœ ๋ถˆ์ผ์น˜ํ•œ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
์„ค๋ช…์€ '๋กœ๊ทธ ๋ถ„์„ ํ›„ AGENTS.md ๊ฐœ์„ ์•ˆ์„ ์ œ์•ˆํ•˜๋Š” ์ž๋™ํ™”'๋ฅผ ๋งํ•˜์ง€๋งŒ, ์ด ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ 1์ฐจ ๋ชฉ์ ์€ ์ดˆ๊ธฐ ์„ค์ •๊ณผ ์Šค์ผ€์ค„ ๋“ฑ๋ก์ด๋‹ค. ํŠนํžˆ description์˜ ํ•ต์‹ฌ ์•ˆ์ „/๋ฒ”์œ„ ์ฃผ์žฅ์ธ '์ œ์•ˆ๋งŒ ํ•จ, ์ง์ ‘ ์ˆ˜์ • ์ ˆ๋Œ€ ์—†์Œ'๊ณผ ๋‹ฌ๋ฆฌ, ์ด ์Šคํฌ๋ฆฝํŠธ๋Š” ๋กœ์ปฌ ์„ค์ • ํŒŒ์ผ์„ ์ง์ ‘ ์ƒ์„ฑ/๋ฎ์–ด์“ฐ๊ณ  ๋ฐฑ์—…ํ•˜๋ฉฐ ์‹œ์Šคํ…œ ํฌ๋ก  ๋“ฑ๋ก๋„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋‹ค. AGENTS.md ์ž์ฒด๋ฅผ ์ˆ˜์ •ํ•˜์ง€๋Š” ์•Š์ง€๋งŒ, ์„ ์–ธ๋œ ๊ธฐ๋Šฅ ๋ฒ”์œ„๋ฅผ ๋ฒ—์–ด๋‚œ ์“ฐ๊ธฐ/์„ค์น˜ ๋™์ž‘์ด ๋ช…ํ™•ํ•˜๋‹ค. ๋”ฐ๋ผ์„œ ๊ณต๊ธ‰๋œ ์ฝ”๋“œ ์กฐ๊ฐ์€ ์„ ์–ธ ์„ค๋ช…์„ ์ •ํ™•ํžˆ ๋Œ€ํ‘œํ•˜์ง€ ์•Š๋Š”๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The declared description says the skill is for an AI assistant to analyze its own logs and propose AGENTS.md improvements, with multiple advanced features across versions, and explicitly states it only proposes changes and never edits directly. The supplied code chunk is instead a benchmark collector: it optionally calls two external public APIs, parses latest release/trending data, inspects the local AGENTS.md file for line counts/section-pattern presence, computes a structure score, and writes benchmarks.json. While AGENTS.md analysis is somewhat adjacent to configuration improvement, the core behavior materially differs from the declared purpose because there is no self-log analysis, no proposal-generation flow, and no implementation of the listed advanced capabilities. Additionally, the code uses undeclared network access and file output resources not reflected in the declared permissions.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
์ด ์ฝ”๋“œ ์ฒญํฌ๋Š” ์„ค๋ช…๋œ ์‹œ์Šคํ…œ์˜ ์ผ๋ถ€ ํ•˜์œ„ ๋‹จ๊ณ„๋กœ ๋ณผ ์ˆ˜๋Š” ์žˆ์ง€๋งŒ, ์‹ค์ œ๋กœ๋Š” 'collect-logs.sh'๋ผ๋Š” ๋กœ๊ทธ ์ˆ˜์ง‘/์ „์ฒ˜๋ฆฌ ์Šคํฌ๋ฆฝํŠธ์ด๋‹ค. ๋กœ์ปฌ ์„ธ์…˜ ๊ธฐ๋ก๊ณผ ๊ฐ์ข… ๋กœ๊ทธ๋ฅผ ์ฝ์–ด JSON์œผ๋กœ ์ง‘๊ณ„ํ•˜๋Š” ๊ฒƒ์ด ์ฃผ๋œ ๋™์ž‘์ด๋ฉฐ, ์ด๋Š” '์ž๊ธฐ ๋กœ๊ทธ ๋ถ„์„ ์ž๋™ํ™”'์˜ ์ง€์› ๋‹จ๊ณ„๋กœ๋Š” ๋ถ€ํ•ฉํ•œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์„ ์–ธ๋œ ์„ค๋ช…์˜ ํ•ต์‹ฌ์€ AGENTS.md ๊ฐœ์„ ์•ˆ ์ œ์•ˆ ์‹œ์Šคํ…œ ์ „์ฒด์ด๋ฉฐ, ํŠนํžˆ v5/v4.3์˜ ๊ณ ๊ธ‰ ๊ธฐ๋Šฅ๋“ค(์ž„๋ฒ ๋”ฉ, ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง, ํ”Œ๋ฆฟ ๋ถ„์„, ์Šน์ธ, ๋ฆฌํฌํŠธ, GitHub Issues)์ด ๊ฐ•์กฐ๋˜์–ด ์žˆ๋‹ค. ์ œ๊ณต ์ฝ”๋“œ์—๋Š” ์ด๋Ÿฌํ•œ ๊ธฐ๋Šฅ์ด ์ „ํ˜€ ์—†๊ณ  ๋„คํŠธ์›Œํฌ ํ˜ธ์ถœ๋„ ์—†๋‹ค. ๋˜ํ•œ ์ œ์•ˆ ์ƒ์„ฑ์ด๋‚˜ AGENTS.md ๊ด€๋ จ ์ฒ˜๋ฆฌ๋Š” ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค. ๋ฐ˜๋ฉด '์ง์ ‘ ์ˆ˜์ • ์ ˆ๋Œ€ ์—†์Œ'๊ณผ๋Š” ์ถฉ๋Œํ•˜์ง€ ์•Š์ง€๋งŒ, ๊ทธ๊ฒƒ๋งŒ์œผ๋กœ ์ „์ฒด ์„ค๋ช…๊ณผ์˜ ์ •ํ•ฉ์„ฑ์ด ํ™•๋ณด๋˜์ง€๋Š” ์•Š๋Š”๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…์ด ์ด ์ฝ”๋“œ ์ฒญํฌ์˜ ์‹ค์ œ ๊ธฐ๋Šฅ์„ ์ •ํ™•ํžˆ ๋Œ€ํ‘œํ•œ๋‹ค๊ณ  ๋ณด๊ธฐ ์–ด๋ ต๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
์ด ์ฝ”๋“œ ์กฐ๊ฐ์€ ์„ค๋ช…๋œ ์ „์ฒด ์Šคํ‚ฌ์˜ ์ผ๋ถ€ ๊ธฐ๋Šฅ์ธ '๋ฉ€ํ‹ฐํ”Œ๋žซํผ ๋ฐฐ๋‹ฌ'๊ณผ๋Š” ์ผ์น˜ํ•˜์ง€๋งŒ, ์„ ์–ธ๋œ ์„ค๋ช…์˜ ํ•ต์‹ฌ ๋ชฉ์ ์€ '์ž๊ธฐ ๋กœ๊ทธ ๋ถ„์„ ํ›„ AGENTS.md ๊ฐœ์„  ์ œ์•ˆ'์ด๋‹ค. ๋ฐ˜๋ฉด ์‹ค์ œ ์ฝ”๋“œ๋Š” ๋ถ„์„์ด๋‚˜ ์ œ์•ˆ ์ƒ์„ฑ ์—†์ด ์ด๋ฏธ ๋งŒ๋“ค์–ด์ง„ ํ…์ŠคํŠธ๋ฅผ ์™ธ๋ถ€ ์„œ๋น„์Šค๋กœ ์ „์†กํ•˜๋Š” ์ „์†ก๊ธฐ๋‹ค. ํŠนํžˆ Slack/Telegram/Webhook์œผ๋กœ์˜ ๋„คํŠธ์›Œํฌ ์†ก์‹ ๊ณผ ์‹คํŒจ ์‹œ ๋กœ์ปฌ ์ €์žฅ์€ ๋ฏผ๊ฐํ•œ ๋™์ž‘์ธ๋ฐ, ์„ ์–ธ๋œ ๊ถŒํ•œ์€ ๋น„์–ด ์žˆ๊ณ  ์„ค๋ช…์˜ ์ค‘์‹ฌ ๊ธฐ๋Šฅ๊ณผ๋„ ๊ฑฐ๋ฆฌ๊ฐ€ ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ ์ด ์ฝ”๋“œ ์กฐ๊ฐ๋งŒ ๋†“๊ณ  ๋ณด๋ฉด ์„ค๋ช… ๋Œ€๋น„ ์‹ค์ œ ๋™์ž‘์€ materially differentํ•˜๋ฉฐ undeclared capability(์™ธ๋ถ€ ์ „์†ก)๋ฅผ ํฌํ•จํ•˜๋ฏ€๋กœ mismatch๋กœ ํŒ๋‹จํ•œ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
์„ค๋ช…์€ ์ „์ฒด์ ์œผ๋กœ '์ž๊ธฐ ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•˜์—ฌ AGENTS.md ๊ฐœ์„  ์ œ์•ˆ์„ ๋งŒ๋“œ๋Š” ์ž๋™ํ™”'๋ฅผ ์„ ์–ธํ•˜์ง€๋งŒ, ์ œ๊ณต๋œ ์ฝ”๋“œ ์กฐ๊ฐ์€ v4.1์˜ export-report.sh๋กœ์„œ ์ฃผ๊ฐ„ ์ œ์•ˆ ๋ฆฌํฌํŠธ๋ฅผ ๋‹ค์–‘ํ•œ ํ˜•์‹์œผ๋กœ ์ถœ๋ ฅํ•˜๋Š” ๋ณด์กฐ ์œ ํ‹ธ๋ฆฌํ‹ฐ์— ํ•ด๋‹นํ•œ๋‹ค. ์‹ค์ œ ๋™์ž‘์€ /tmp/sea-v4/proposal.md ๋ฐ data/proposals/*.json์„ ์ฝ๊ณ , ์ด๋ฅผ markdown/html/json/pdf๋กœ ๋ณ€ํ™˜ํ•ด stdout ๋˜๋Š” ์‚ฌ์šฉ์ž ์ง€์ • ํŒŒ์ผ ๊ฒฝ๋กœ์— ์ €์žฅํ•˜๋Š” ๊ฒƒ์ด๋‹ค. ์ฝ”๋“œ์—๋Š” ๋ถ„์„ ํŒŒ์ดํ”„๋ผ์ธ, ๋กœ๊ทธ ์ˆ˜์ง‘, AGENTS.md ๋Œ€์ƒ ์ œ์•ˆ ์ƒ์„ฑ, ์ˆ˜์ • ๊ธˆ์ง€ enforcement, Ollama/์ž„๋ฒ ๋”ฉ ํ˜ธ์ถœ, ๋„คํŠธ์›Œํฌ ์—ฐ๋™, ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง, ๋‹ค์ค‘ ์ธ์Šคํ„ด์Šค ์ง‘๊ณ„ ๋“ฑ์˜ ํ•ต์‹ฌ ์„ ์–ธ ๊ธฐ๋Šฅ์ด ์—†๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…๊ณผ ์ฝ”๋“œ์˜ ์‹ค์ œ ๋ชฉ์ ์€ materially different ํ•˜๋ฉฐ, ํŠนํžˆ ์ฃผ๋œ ๊ธฐ๋Šฅ์ด '๋ถ„์„ ๋ฐ ์ œ์•ˆ ์ƒ์„ฑ'์ด ์•„๋‹ˆ๋ผ '๊ธฐ์กด ๊ฒฐ๊ณผ๋ฌผ์˜ ๋ฆฌํฌํŠธ export'๋ผ๋Š” ์ ์—์„œ ๋ช…๋ฐฑํ•œ ๋ถˆ์ผ์น˜๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
์„ ์–ธ๋œ ์„ค๋ช…์€ ์ „์ฒด ์Šคํ‚ฌ์„ '์ž๊ธฐ ๋กœ๊ทธ ๋ถ„์„์„ ํ†ตํ•ด AGENTS.md ๊ฐœ์„ ์•ˆ์„ ์ œ์•ˆํ•˜๋Š” ์ž๋™ํ™”'๋กœ ์ œ์‹œํ•˜๊ณ , ์ง์ ‘ ์ˆ˜์ •์€ ํ•˜์ง€ ์•Š๋Š”๋‹ค๊ณ  ๊ฐ•์กฐํ•œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ œ๊ณต๋œ ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ ์—ญํ• ์€ GitHub Issues ์—ฐ๋™ ์ „์šฉ์œผ๋กœ, pending ์ œ์•ˆ์— ๋Œ€ํ•ด ์ด์Šˆ๋ฅผ ๋งŒ๋“ค๊ณ , ์Šน์ธ ์‹œ ์ด์Šˆ๋ฅผ ๋‹ซ๊ณ  ์ฝ”๋ฉ˜ํŠธ๋ฅผ ๋‚จ๊ธฐ๋ฉฐ, ๋ ˆ์ด๋ธ”์„ ์ƒ์„ฑํ•˜๊ณ , proposal JSON์— GitHub ์ด์Šˆ ๊ด€๋ จ ํ•„๋“œ๋ฅผ ์จ ๋„ฃ๋Š”๋‹ค. GitHub Issues ๊ธฐ๋Šฅ ์ž์ฒด๋Š” ์„ค๋ช…์˜ ๋ฒ„์ „ ํžˆ์Šคํ† ๋ฆฌ(v4.3)์— ์–ธ๊ธ‰๋˜์–ด ์žˆ์–ด ์™„์ „ํžˆ ๋ฌด๊ด€ํ•œ ๊ฒƒ์€ ์•„๋‹ˆ์ง€๋งŒ, ์ด ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ 1์ฐจ ๋ชฉ์ ์€ '๋ถ„์„/์ œ์•ˆ'์ด ์•„๋‹ˆ๋ผ '์ œ์•ˆ์˜ GitHub ์ด์Šˆ ๊ด€๋ฆฌ'์ด๋‹ค. ๋˜ํ•œ '์ง์ ‘ ์ˆ˜์ • ์ ˆ๋Œ€ ์—†์Œ'๊ณผ ๋‹ฌ๋ฆฌ AGENTS.md ์ž์ฒด๋ฅผ ์ˆ˜์ •ํ•˜์ง„ ์•Š๋”๋ผ๋„ ๋กœ์ปฌ data/proposals/*.json ํŒŒ์ผ์€ ๊ฐฑ์‹ ํ•œ๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…์ด ์ด ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ ๋™์ž‘์„ ์ •ํ™•ํžˆ ๋Œ€ํ‘œํ•œ๋‹ค๊ณ  ๋ณด๊ธฐ ์–ด๋ ต๊ณ , ํŠนํžˆ ํ•ต์‹ฌ ๊ธฐ๋Šฅ ๋ถˆ์ผ์น˜์™€ ์™ธ๋ถ€ GitHub ์กฐ์ž‘ capability ๋ฏธ๊ณ ์ง€๊ฐ€ ์žˆ์–ด mismatch๋กœ ํŒ๋‹จํ•œ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
์„ค๋ช… ์ „์ฒด๋Š” '๋กœ๊ทธ ๋ถ„์„ โ†’ AGENTS.md ๊ฐœ์„ ์•ˆ ์ œ์•ˆ' ์ž๋™ํ™”์— ์ดˆ์ ์„ ๋‘๊ณ  ์žˆ๊ณ  '์ง์ ‘ ์ˆ˜์ • ์ ˆ๋Œ€ ์—†์Œ'์ด๋ผ๊ณ  ๊ฐ•์กฐํ•œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์‹ค์ œ ์ฝ”๋“œ ์กฐ๊ฐ์€ ๋ถ„์„/์ œ์•ˆ ์ƒ์„ฑ๊ธฐ๊ฐ€ ์•„๋‹ˆ๋ผ ์Šน์ธ ์ธํ„ฐํŽ˜์ด์Šค ๋ฐ ์•Œ๋ฆผ/์ „์†ก ๋ณด์กฐ๋„๊ตฌ๋‹ค. ํŠนํžˆ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ์— ๋”ฐ๋ผ `sea approve`/`sea reject`๋ฅผ ์‹คํ–‰ํ•ด ์ œ์•ˆ์˜ ์ƒํƒœ๋ฅผ ๋ฐ”๊พธ๋Š” ์šด์˜ ๊ธฐ๋Šฅ์„ ์ˆ˜ํ–‰ํ•˜๋ฉฐ, Telegram ์™ธ๋ถ€ API ํ˜ธ์ถœ๊ณผ `/tmp/sea-v4/watch-state.json` ๊ธฐ๋ก๋„ ํ•œ๋‹ค. ์„ค๋ช…์— v4.3 ๋Œ€ํ™”ํ˜• ์Šน์ธ๊ณผ ๋ฉ€ํ‹ฐํ”Œ๋žซํผ ์ „๋‹ฌ์ด ์–ธ๊ธ‰๋˜์–ด ์ผ๋ถ€ ๋งฅ๋ฝ์€ ๋งž์ง€๋งŒ, ์ด ์ฝ”๋“œ์˜ ์ฃผ๋œ ๋™์ž‘์€ ์ œ์•ˆ ์ƒ์„ฑ์ด ์•„๋‹ˆ๋ผ ์Šน์ธ ์›Œํฌํ”Œ๋กœ์šฐ ์‹คํ–‰์ด๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…์ด ์ด ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ ํ–‰์œ„๋ฅผ ์ •ํ™•ํžˆ ๋Œ€ํ‘œํ•œ๋‹ค๊ณ  ๋ณด๊ธฐ ์–ด๋ ต๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
์ด ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ 1์ฐจ ๋ชฉ์ ์€ '๋ฒ”์šฉ LLM ์ธํ„ฐํŽ˜์ด์Šค'๋‹ค. stdin ์ž…๋ ฅ์„ ์ฝ์–ด ์„ ํƒ๋œ LLM provider์— ์ „๋‹ฌํ•˜๊ณ  ํ…์ŠคํŠธ ์‘๋‹ต์„ ๋ฐ˜ํ™˜ํ•˜๋Š” ์œ ํ‹ธ๋ฆฌํ‹ฐ์ด๋ฉฐ, config.yaml ์ฝ๊ธฐ์™€ ํ™˜๊ฒฝ๋ณ€์ˆ˜/API ํ‚ค ์‚ฌ์šฉ, ๊ทธ๋ฆฌ๊ณ  ์›๊ฒฉ API ํ˜ธ์ถœ์ด ํ•ต์‹ฌ ๋™์ž‘์ด๋‹ค. ๋ฐ˜๋ฉด ์„ ์–ธ๋œ ์„ค๋ช…์€ ์ž๊ธฐ ๋กœ๊ทธ ๋ถ„์„์„ ํ†ตํ•ด AGENTS.md ๊ฐœ์„ ์•ˆ์„ ์ œ์•ˆํ•˜๋Š” ์ƒ์œ„ ์ž๋™ํ™” ์ „์ฒด๋ฅผ ๋งํ•˜๋ฉฐ, ์ž„๋ฒ ๋”ฉยท๋ชจ๋‹ˆํ„ฐ๋งยทํ”Œ๋ฆฟ ๋ถ„์„ ๋“ฑ ์ถ”๊ฐ€ ๊ธฐ๋Šฅ๊นŒ์ง€ ์ฃผ์žฅํ•œ๋‹ค. ์ œ๊ณต ์ฝ”๋“œ๋งŒ ๋ณด๋ฉด ๊ทธ๋Ÿฌํ•œ ๋ถ„์„ ํŒŒ์ดํ”„๋ผ์ธ์ด๋‚˜ ํŠนํ™”๋œ ๋„๋ฉ”์ธ ๋™์ž‘์€ ์—†๊ณ , ๋‹จ์ง€ ์ž„์˜ ํ”„๋กฌํ”„ํŠธ๋ฅผ LLM์œผ๋กœ ๋ณด๋‚ด๋Š” ๋ž˜ํผ์ผ ๋ฟ์ด๋‹ค. ๋˜ํ•œ declared permissions๊ฐ€ ๋น„์–ด ์žˆ๋Š”๋ฐ ์‹ค์ œ ์ฝ”๋“œ๋Š” ์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ ์—”๋“œํฌ์ธํŠธ์™€ API ํ‚ค๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…๊ณผ ์ฝ”๋“œ ํ–‰๋™ ์‚ฌ์ด์— ์ค‘๋Œ€ํ•œ ๋ถˆ์ผ์น˜๊ฐ€ ์žˆ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
์„ค๋ช…์€ '์ž๊ธฐ ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•˜์—ฌ AGENTS.md ๊ฐœ์„ ์•ˆ์„ ์ œ์•ˆํ•˜๋Š” ์ž๋™ํ™”'๋ฅผ ์ฃผ๋ชฉ์ ์œผ๋กœ ๋‚ด์„ธ์šฐ๊ณ  ์—ฌ๋Ÿฌ ๊ณ ๊ธ‰ ๊ธฐ๋Šฅ(์ž„๋ฒ ๋”ฉ, ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ, ํ”Œ๋ฆฟ ๋ถ„์„ ๋“ฑ)์„ ์ฃผ์žฅํ•œ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์‹ค์ œ ์ฝ”๋“œ ์กฐ๊ฐ์€ scripts/v4/measure-effects.sh๋กœ, ์ด๋ฏธ ์กด์žฌํ•˜๋Š” ์ œ์•ˆ๋“ค์˜ ์‚ฌํ›„ ํšจ๊ณผ๋ฅผ ์ธก์ •ํ•˜๋Š” ํ‰๊ฐ€ ๋„๊ตฌ๋‹ค. ์ œ์•ˆ ํŒŒ์ผ๊ณผ ๊ฑฐ์ ˆ ์ด๋ ฅ์„ ์ฝ๊ณ , ์„ธ์…˜/ํฌ๋ก  ๋กœ๊ทธ์—์„œ ํŒจํ„ด ๋นˆ๋„๋ฅผ ๊ธฐ๊ฐ„๋ณ„ ๋น„๊ตํ•˜๋ฉฐ, self-review ๋””๋ ‰ํ† ๋ฆฌ์—์„œ ํ’ˆ์งˆ ์ ์ˆ˜ ํ‰๊ท ์„ ๊ณ„์‚ฐํ•ด JSON ๋ณด๊ณ ์„œ๋ฅผ ์“ด๋‹ค. ์ด๋Š” '์ œ์•ˆ ์ƒ์„ฑ'์ด ์•„๋‹ˆ๋ผ '๊ณผ๊ฑฐ ์ œ์•ˆ ์„ฑ๊ณผ ์ธก์ •'์ด๋ฉฐ, ์„ค๋ช…๋œ ํ•ต์‹ฌ ๊ธฐ๋Šฅ ๋‹ค์ˆ˜๊ฐ€ ์ „ํ˜€ ๊ตฌํ˜„๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. ์ง์ ‘ ์ˆ˜์ •์€ ํ•˜์ง€ ์•Š์ง€๋งŒ, ์ „์ฒด์ ์œผ๋กœ ์„ ์–ธ๋œ ๋ชฉ์ ๊ณผ ์‹ค์ œ ๋™์ž‘ ์‚ฌ์ด์— ์ค‘๋Œ€ํ•œ ๋ถˆ์ผ์น˜๊ฐ€ ์žˆ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The core purpose mostly aligns at a high level: this orchestrator is for self-analysis and proposal generation, and the visible code does not directly edit AGENTS.md. However, the declared description is for a much broader and newer system version than what this code chunk demonstrates. The code is explicitly labeled v4.0 and only shows a batch cron-driven orchestrator with five stages and optional delivery. It does not evidence the prominently advertised v5.0/v4.3 capabilities such as real-time streaming alerts, fleet/multi-instance analysis, interactive approval, multi-format reports, or GitHub Issues creation. Additionally, while the orchestrator itself does not call the network directly, its own manifest says it delegates optional GitHub API and ClawHub access to benchmark.sh, which is relevant because the declared permissions are empty and the description omits that integration detail. Therefore the description materially overstates capabilities relative to the supplied code chunk, so this should be flagged as a mismatch.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
์„ค๋ช…๊ณผ ์ฝ”๋“œ์˜ ํ•ต์‹ฌ ๋ฐฉํ–ฅ์€ ๋ถ€๋ถ„์ ์œผ๋กœ ๋งž์Šต๋‹ˆ๋‹ค. ๋‘˜ ๋‹ค ์—์ด์ „ํŠธ ๋กœ๊ทธ/์„ธ์…˜์„ ๋ถ„์„ํ•˜๊ณ  AGENTS.md ๊ฐœ์„  ์ œ์•ˆ์— ์“ฐ์ผ ์‚ฐ์ถœ๋ฌผ์„ ๋งŒ๋“œ๋Š” ๋ถ„์„ ํŒŒ์ดํ”„๋ผ์ธ์ž…๋‹ˆ๋‹ค. ๋˜ํ•œ ์ฝ”๋“œ๊ฐ€ AGENTS.md๋ฅผ ์ง์ ‘ ์ˆ˜์ •ํ•˜์ง€ ์•Š๋Š” ์ ๋„ ์„ค๋ช…๊ณผ ์ผ์น˜ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์„ค๋ช…์ด ๋‚ด์„ธ์šฐ๋Š” ์ฃผ์š” ๋ฒ„์ „ ๊ธฐ๋Šฅ๋“คโ€”์‹œ๋งจํ‹ฑ ์ž„๋ฒ ๋”ฉ, ์‹ค์‹œ๊ฐ„ ์ŠคํŠธ๋ฆฌ๋ฐ ์•Œ๋ฆผ, ํ”Œ๋ฆฟ ๋ถ„์„, GitHub Issues, ๋Œ€ํ™”ํ˜• ์Šน์ธ, ๋ฉ€ํ‹ฐํฌ๋งท ๋ฆฌํฌํŠธ, Ollama LLM ์‚ฌ์šฉโ€”์€ ์ด ์ฝ”๋“œ ์กฐ๊ฐ์—์„œ ํ™•์ธ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์‹ค์ œ ๊ตฌํ˜„์€ ๋„คํŠธ์›Œํฌ ํ˜ธ์ถœ ์—†์ด ๋กœ์ปฌ ๋กœ๊ทธ ํŒŒ์ผ์„ ์ฝ์–ด ์ •๊ทœ์‹/ํœด๋ฆฌ์Šคํ‹ฑ ๊ธฐ๋ฐ˜ ๋ถ„์„์„ ์ˆ˜ํ–‰ํ•˜๊ณ  JSON๊ณผ LLM ํ”„๋กฌํ”„ํŠธ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ์ˆ˜์ค€์ž…๋‹ˆ๋‹ค. ์ฆ‰, declared purpose์˜ ์ผ๋ถ€ ๊ธฐ๋ณธ ์ทจ์ง€๋Š” ๋งž์ง€๋งŒ, ์„ค๋ช…์ด ์ฃผ์žฅํ•˜๋Š” ํ•ต์‹ฌ ๋Šฅ๋ ฅ ๋‹ค์ˆ˜๊ฐ€ ์ฝ”๋“œ ํ–‰๋™๊ณผ materially ๋‹ค๋ฅด๊ฑฐ๋‚˜ ๊ณผ์žฅ๋˜์–ด ์žˆ์–ด mismatch๋กœ ํŒ๋‹จํ•ฉ๋‹ˆ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The core behavior mostly aligns with the high-level claim of generating AGENTS.md improvement proposals without directly editing AGENTS.md. However, the declared description presents a much broader v5.0/v4.3 capability set than this code actually shows. This chunk is a proposal synthesizer/report generator, not a real-time monitor, embedding pipeline, or fleet analyzer. It also includes conditional external LLM calls and a Discord-related footer integration while declared permissions are empty. Because the description materially overstates implemented capabilities and omits notable external interactions, this is a mismatch.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding
์„ค๋ช…๊ณผ ์ผ๋ถ€๋Š” ์ผ์น˜ํ•œ๋‹ค: ๋กœ๊ทธ ๋ถ„์„, Ollama ๊ธฐ๋ฐ˜ ์‹œ๋งจํ‹ฑ ์ž„๋ฒ ๋”ฉ, ์ง์ ‘ ์ˆ˜์ •ํ•˜์ง€ ์•Š์Œ์€ ์ฝ”๋“œ์™€ ๋ชจ์ˆœ๋˜์ง€ ์•Š๋Š”๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ด ์ฝ”๋“œ์˜ ์‹ค์ œ ๊ธฐ๋Šฅ์€ '์‚ฌ์šฉ์ž ๋ฉ”์‹œ์ง€์—์„œ frustration/complaint ์‹ ํ˜ธ๋ฅผ ํƒ์ง€ํ•˜๋Š” ๋ถ„์„๊ธฐ'์— ๊ฐ€๊น๊ณ , ์„ ์–ธ๋œ ํ•ต์‹ฌ ๋ชฉ์  ์ค‘ ํ•˜๋‚˜์ธ 'AGENTS.md ๊ฐœ์„ ์•ˆ ์ œ์•ˆ' ๊ธฐ๋Šฅ์€ ์ „ํ˜€ ๊ตฌํ˜„๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. ๋˜ํ•œ ์„ค๋ช…์— ์žˆ๋Š” ์‹ค์‹œ๊ฐ„ ์ŠคํŠธ๋ฆฌ๋ฐ ๋ชจ๋‹ˆํ„ฐ, ํ”Œ๋ฆฟ ๋ถ„์„, ๋Œ€ํ™”ํ˜• ์Šน์ธ, ๋ฉ€ํ‹ฐํฌ๋งท ๋ฆฌํฌํŠธ, GitHub Issues ๋“ฑ๋„ ์ด ์ฝ”๋“œ ์กฐ๊ฐ์—์„œ๋Š” ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค. ์ฝ”๋“œ๊ฐ€ ํŒŒ์ดํ”„๋ผ์ธ์˜ ํ•œ ๋‹จ๊ณ„์ผ ์ˆ˜๋Š” ์žˆ์ง€๋งŒ, ์ œ๊ณต๋œ ์„ค๋ช…์„ ์ด ์ฝ”๋“œ ์กฐ๊ฐ ์ž์ฒด์˜ ์„ค๋ช…์œผ๋กœ ๋ณด๋ฉด ๋ชฉ์ ์ด ๋” ๋„“๊ณ  ํ•ต์‹ฌ ์‚ฐ์ถœ๋ฌผ๋„ ๋‹ค๋ฅด๋‹ค. ๋”๋ถˆ์–ด declared permissions๊ฐ€ ๋น„์–ด ์žˆ๋Š”๋ฐ ์‹ค์ œ๋กœ๋Š” ๋กœ๊ทธ ์ฝ๊ธฐ, ๊ฒฐ๊ณผ ํŒŒ์ผ ์“ฐ๊ธฐ, ๋กœ์ปฌ Ollama API ํ˜ธ์ถœ์ด ์žˆ๋‹ค. ๋”ฐ๋ผ์„œ ์„ค๋ช…์ด ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ ๋™์ž‘์„ ์ •ํ™•ํžˆ ๋Œ€ํ‘œํ•œ๋‹ค๊ณ  ๋ณด๊ธฐ ์–ด๋ ต๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding
ํ•ต์‹ฌ ๋ชฉ์  ์ž์ฒด๋Š” ๋Œ€์ฒด๋กœ ์„ค๋ช…๊ณผ ๋ถ€ํ•ฉํ•œ๋‹ค. ์ด ์Šคํฌ๋ฆฝํŠธ๋Š” ์‹ค์ œ๋กœ ๋กœ๊ทธ๋ฅผ ์ˆ˜์ง‘ํ•˜๊ณ  ๋ถ„์„ํ•ด proposal.md๋ฅผ ์ƒ์„ฑํ•˜๋ฉฐ, ์ง์ ‘ AGENTS.md๋ฅผ ์ˆ˜์ •ํ•˜๋Š” ๋™์ž‘์€ ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์„ ์–ธ์€ '์ œ์•ˆ๋งŒ ํ•จ' ์ค‘์‹ฌ์˜ ๋กœ๊ทธ ๋ถ„์„ ์ž๋™ํ™”๋กœ ๋ณด์ด๋Š”๋ฐ, ์‹ค์ œ ์ฝ”๋“œ๋Š” ์ œ์•ˆ ์ƒ์„ฑ ์™ธ์—๋„ ๊ฒฐ๊ณผ ๋ฐฐ๋‹ฌ(deliver.sh ํ˜ธ์ถœ), stdout ๊ธฐ๋ฐ˜ ํฌ๋ก  ๋ฐฐ์ถœ, ๊ทธ๋ฆฌ๊ณ  ์กฐ๊ฑด๋ถ€ ์™ธ๋ถ€ ํ”Œ๋žซํผ ์ „๋‹ฌ์„ ์ˆ˜ํ–‰ํ•œ๋‹ค. ๋˜ํ•œ declared permissions๊ฐ€ ๋น„์–ด ์žˆ์Œ์—๋„ ๋กœ์ปฌ Ollama์™€ ์„ ํƒ์  OpenAI ์ž„๋ฒ ๋”ฉ API ํ˜ธ์ถœ์ด ๋ช…์‹œ๋˜์–ด ์žˆ์–ด ์ ‘๊ทผ ์ž์› ์„ค๋ช…์ด ๋ถˆ์™„์ „ํ•˜๋‹ค. ๋ฒค์น˜๋งˆํฌ ์ˆ˜์ง‘๊ณผ ํšจ๊ณผ ์ธก์ •์€ ํŒŒ์ดํ”„๋ผ์ธ ์ผ๋ถ€๋กœ ๋ณผ ์ˆ˜ ์žˆ์œผ๋‚˜, ์„ ์–ธ๋œ ํ•ต์‹ฌ ์„ค๋ช…๋งŒ์œผ๋กœ๋Š” ์ถฉ๋ถ„ํžˆ ๋“œ๋Ÿฌ๋‚˜์ง€ ์•Š๋Š” ์ถ”๊ฐ€ ์‹คํ–‰ ๊ธฐ๋Šฅ์ด๋‹ค. ๋”ฐ๋ผ์„œ ์ „์ฒด ๋ชฉ์ ์€ ์œ ์‚ฌํ•˜์ง€๋งŒ, ๋„คํŠธ์›Œํฌ/๋ฐฐ๋‹ฌ ๋ฐ ์ž์› ์ ‘๊ทผ ์ธก๋ฉด์—์„œ ์ค‘์š”ํ•œ ๋ฏธ๊ธฐ์žฌ ๊ธฐ๋Šฅ์ด ์žˆ์–ด mismatch๋กœ ํŒ๋‹จํ•œ๋‹ค.

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding
์„ค๋ช…์€ ์ „์ฒด ์Šคํ‚ฌ์ด '์ž๊ธฐ ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•˜์—ฌ AGENTS.md ๊ฐœ์„ ์•ˆ์„ ์ œ์•ˆ'ํ•˜๋Š” ์ž๋™ํ™”๋ผ๊ณ  ๋งํ•˜์ง€๋งŒ, ์ด ์ฝ”๋“œ ์กฐ๊ฐ์˜ ์‹ค์ œ ์ฃผ๋œ ์—ญํ• ์€ proposals ๋””๋ ‰ํ„ฐ๋ฆฌ์™€ alerts ๋””๋ ‰ํ„ฐ๋ฆฌ์˜ JSON์„ ๋ชจ์•„ ํŒจํ„ด ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ๊ฒ€์ƒ‰/์ถ”์ฒœํ•˜๋Š” ๊ฒƒ์ด๋‹ค. ์ฆ‰, ์ง์ ‘์ ์ธ AGENTS.md ๊ฐœ์„ ์•ˆ ์ƒ์„ฑ๊ธฐ๋ผ๊ธฐ๋ณด๋‹ค ๊ณผ๊ฑฐ ์ œ์•ˆ์˜ ๋ฉ”ํƒ€๋ถ„์„ ๋ฐ ๊ทœ์น™ ์นดํƒˆ๋กœ๊ทธ ๋„๊ตฌ๋‹ค. ๋˜ํ•œ ์„ค๋ช…์—์„œ ๊ฐ•์กฐํ•œ ์‹œ๋งจํ‹ฑ ์ž„๋ฒ ๋”ฉ, Ollama ๊ธฐ๋ฐ˜ ์ž„๋ฒ ๋”ฉ, ํ”Œ๋ฆฟ ๋ถ„์„์€ ์ด ์ฝ”๋“œ์— ๋‚˜ํƒ€๋‚˜์ง€ ์•Š๋Š”๋‹ค. ๋ฐ˜๋ฉด '์ง์ ‘ ์ˆ˜์ •ํ•˜์ง€ ์•Š์Œ'๊ณผ ์ถฉ๋Œํ•˜๋Š” ์œ„ํ—˜ ๋™์ž‘์€ ์—†์ง€๋งŒ, ์ฝ”๋“œ์˜ ์‹ค์ œ 1์ฐจ ๋ชฉ์ ๊ณผ ์ œ๊ณต ๊ธฐ๋Šฅ์ด ์„ ์–ธ ์„ค๋ช…๋ณด๋‹ค ๋” ์ข์œผ๋ฉด์„œ๋„ ๋‹ค๋ฅธ ๋ฐฉํ–ฅ(ํŒจํ„ด ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ/CLI ์นดํƒˆ๋กœ๊ทธ)์œผ๋กœ ํ™•์žฅ๋˜์–ด ์žˆ์–ด ์„ค๋ช…-ํ–‰๋™ ๋ถˆ์ผ์น˜๋กœ ๋ณด๋Š” ๊ฒƒ์ด ํƒ€๋‹นํ•˜๋‹ค.