T01 · Skill Instruction Hijacking
- Location
SKILL.md:32- Finding
Persistent Agent State and Prompt Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is transparent about adding persistent agent state, but it does so by writing prompt-injected state and recurring heartbeat updates without clear containment or reset controls.
Install only if you intentionally want cross-session agent mood state that can be injected into prompts. Review the openclaw-promitheus package version first, avoid automatic heartbeat injection unless you understand the effect, and keep a clear way to disable the plugin and remove STATE.md or HEARTBEAT.md changes.
SKILL.md:32Persistent Agent State and Prompt Injection
SKILL.md:10Unpinned and Unreviewed Executable npm Plugin Dependency
The skill directs agents to adopt a persistent emotional and 'sentience' framing as a default operating mode rather than presenting it as optional roleplay or UI metaphor. That can distort agent behavior, encourage anthropomorphic self-modeling, and make prompt-injected state more influential over decisions, especially when combined with persistent cross-session memory.
The skill explicitly instructs the agent to run a tool that writes STATE.md and says that file may be auto-injected into prompts, but it does not warn the user that workspace files will be modified or that generated content will influence future model behavior. This creates a prompt-surface and persistence risk: tool-generated text can silently carry over across sessions, affect downstream decisions, and potentially be abused if the state file is tampered with.
No suspicious patterns detected.