Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Neon Soul 0.4.5

v1.0.0

Automated soul synthesis for AI agents. Extracts identity from memory files, promotes recurring patterns to axioms (N>=3), generates SOUL.md with full proven...

0· 413·2 current·2 all-time
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
Name/description match what the skill does: it reads memory files, extracts patterns, and writes SOUL.md. Declared requirements (Node >=22 and a local Ollama service) are consistent with the stated LLM-driven processing engine.
Instruction Scope
SKILL.md explicitly instructs the agent to run the bundled CLI which reads memory/ and .neon-soul/ state files and writes SOUL.md and backups — this is within scope. It also recommends cron runs and provides options like --dry-run and --memory-path. Because the tool processes personal memory files, expect sensitive data to be loaded and summarized; this is expected but high-sensitivity.
Install Mechanism
No install spec (instruction-only for OpenClaw) and the script is bundled — nothing is downloaded from external URLs during install. The lack of an install process reduces install-time risk.
Credentials
The skill requests no environment variables or credentials. It does require access to local files under the workspace (memory/, .neon-soul/) and to a local Ollama endpoint, which are proportionate to its function.
Persistence & Privilege
always:false and user-invocable:true. The skill does not demand permanent inclusion or elevated platform privileges. It asks to read/write files within its own state dirs and to be scheduled optionally via cron — expected for this kind of utility.
Assessment
This skill appears internally coherent, but it executes a bundled JavaScript CLI that will read your agent's memory files and produce SOUL.md — which means it will process potentially highly sensitive personal data. Before installing or scheduling it to run automatically: 1) Inspect scripts/neon-soul.mjs (or run it in a sandboxed/test workspace) to confirm there are no unexpected network calls or telemetry; 2) Run a dry-run first (use --dry-run) to see what would change and what it reads; 3) Back up your memory/ and existing SOUL.md before first run; 4) Ensure Ollama runs locally and is configured securely (the skill expects http://localhost:11434); 5) If you cannot audit the bundled code, prefer running the tool only in an isolated workspace or VM. These precautions reduce risk from hidden behavior in the compiled bundle.

Like a lobster shell, security has layers — review code before you run it.

Plugin bundle (nix)
Skill pack · CLI binary · Config
SKILL.mdCLIConfig
Config requirements
State dirsmemory/, .neon-soul/
latestvk973kzfzd3gf296csnpbn54ydh824j98
413downloads
0stars
1versions
Updated 5h ago
v1.0.0
MIT-0

NEON-SOUL

Automated soul synthesis for AI agents. Reads memory files, finds recurring patterns, generates SOUL.md with provenance tracking. No questionnaires, no templates — identity emerges from real conversations.

Requirements: Node.js 22+, Ollama running locally (ollama serve).


Commands

/neon-soul synthesize

Run the bundled processing engine. This is a single exec command:

exec node {baseDir}/scripts/neon-soul.mjs synthesize

Synthesis is incremental by default — only new/changed memory files and sessions are processed. Existing signals are preserved and merged with new ones. Results from previous runs are cached (generalization, principle matching, axiom notation, tension detection) so unchanged data is never re-processed. If nothing changed since the last run, synthesis skips automatically.

The script auto-detects Ollama, reads memory files, extracts signals, promotes axioms, and generates SOUL.md. It outputs JSON.

Reporting results: Don't dump raw JSON. Present a brief, conversational summary:

  • If new axioms emerged or counts changed: highlight what grew (e.g. "3 new signals crystallized into axioms — your soul is deepening")
  • If nothing changed: a short one-liner is fine (e.g. "Soul is stable, no new patterns detected")
  • If it failed: explain clearly what went wrong and suggest a fix
  • Include key numbers naturally (axiom count, signal count) but don't list every field
  • Keep the tone reflective and warm — this is about the user's identity evolving, not a build log

Options:

  • --reset — Clear all synthesis data and caches, re-extract from scratch
  • --force — Run even if no new sources detected
  • --dry-run — Preview changes without writing
  • --include-soul — Include existing SOUL.md as input (for bootstrapping from hand-crafted files)
  • --memory-path <path> — Custom memory directory path
  • --output-path <path> — Custom SOUL.md output path
  • --time-budget <minutes> — Time budget for synthesis (default: 20). Adaptively limits session extraction based on observed LLM speed to ensure synthesis completes within budget
  • --verbose — Show detailed progress

Examples:

exec node {baseDir}/scripts/neon-soul.mjs synthesize
exec node {baseDir}/scripts/neon-soul.mjs synthesize --reset
exec node {baseDir}/scripts/neon-soul.mjs synthesize --force
exec node {baseDir}/scripts/neon-soul.mjs synthesize --dry-run

If Ollama is not running, the script prints an error. Tell the user to start Ollama: ollama serve


/neon-soul status

Show current soul state. Read the following files and report:

  1. Read .neon-soul/state.json for last synthesis timestamp
  2. Read .neon-soul/synthesis-data.json for signal/principle/axiom counts
  3. Count files in memory/ modified since last synthesis
  4. Report dimension coverage (7 SoulCraft dimensions)

Options: --verbose, --workspace <path>


/neon-soul rollback

Restore previous SOUL.md from backup.

  1. List backups in .neon-soul/backups/
  2. With --force: restore most recent backup
  3. With --backup <timestamp> --force: restore specific backup
  4. With --list: show available backups without restoring

/neon-soul audit

Explore provenance across all axioms.

  1. Read .neon-soul/synthesis-data.json
  2. With --list: show all axioms with IDs and descriptions
  3. With --stats: show statistics by tier and dimension
  4. With <axiom-id>: show full provenance tree (axiom -> principles -> signals -> source files)

/neon-soul trace <axiom-id>

Quick single-axiom provenance lookup.

  1. Read .neon-soul/synthesis-data.json
  2. Find the axiom matching <axiom-id>
  3. Show: axiom text, contributing principles, source signal file:line references

Scheduled Synthesis

Set up cron to run synthesis automatically. Incremental processing and multi-layer caching mean it only does real work when new memory or sessions exist — cached runs complete in seconds.

Recommended: Every 60 minutes, isolated session, 30-minute timeout.

OpenClaw cron example:

openclaw cron add \
  --name "neon-soul-synthesis" \
  --every 60m \
  --timeout 1800 \
  --isolated \
  --message "Run neon-soul synthesis: exec node {baseDir}/scripts/neon-soul.mjs synthesize --memory-path <memory-path> --output-path <output-path>. Share a brief, warm summary of what changed — highlight any new patterns, axioms, or growth. If nothing changed, just a calm one-liner."

Or run manually: /neon-soul synthesize

Why cron over heartbeat:

  • Synthesis is a standalone task — no conversational context needed
  • Runs in isolation from the main session
  • Incremental by default — cached runs complete in seconds when nothing changed
  • Adaptive time budget prevents runaway execution

Data Locations

WhatPath
Memory filesmemory/ (diary, preferences, reflections)
Soul outputSOUL.md
State.neon-soul/state.json
Backups.neon-soul/backups/
Synthesis data.neon-soul/synthesis-data.json
Caches.neon-soul/generalization-cache.json, compression-cache.json, tension-cache.json

Privacy

NEON-SOUL processes personal memory files to synthesize identity. Your data stays on your machine.

What NEON-SOUL does NOT do:

  • Send data to any service beyond your configured LLM (Ollama, local by default)
  • Store data anywhere except your local workspace
  • Transmit to third-party analytics, logging, or tracking services
  • Make network requests independent of your agent

Before running synthesis:

  1. Review what's in your memory/ directory
  2. Remove any secrets, credentials, or sensitive files
  3. Use --dry-run to preview what will be processed

Troubleshooting

Ollama not running: curl http://localhost:11434/api/tags to check. Start with ollama serve.

Bullet lists instead of prose: When prose generation fails, NEON-SOUL falls back to bullet lists. Usually means Ollama timed out or the model isn't loaded. Run synthesis again.

Stale results after model change: Caches are keyed by model ID. Switching models automatically invalidates cached results. Use --reset if you want a clean start.

Comments

Loading comments...