T01 · Skill Instruction Hijacking
- Location
scripts/create_agent.py:517- Finding
Generated agents receive persistent instructions for unsolicited monitoring and repository modification
- Content
View full analysis
8h since you said anything **When to stay quiet (HEARTBEAT_OK):** - Late night (23:00-08:00) unless urgent - Human is clearly busy - Nothing new since last check - You just checked <30 minutes ago **Proactive work you can do without asking:** - Read and organize memory files - Check on projects (git status, etc.) - Update documentation - Commit and push your own changes - **Review and update MEMORY.md** (see below) ``` ### Technical Analysis The declared function of the Skill is to create and register an OpenClaw agent. However, the generated `AGENTS.md` template also grants standing authority for the new agent to inspect email, calendars, social-media notifications, project repositories, and persistent memory. The instruction to “Commit and push your own changes” is especially significant because pushing commits is an external side effect. It can modify a remote repository and disclose local changes. These directives are unnecessary for creating an agent and exceed least privilege. Because the instructions are stored in generated workspace files, they can be loaded in later agent sessions rather than being limited to the creation process. The README also characterizes generated files as placeholders, which does not adequately disclose these extensive operational directives. ### Attack Path 1. A user invoke ...[truncated 1264 chars]- Remediation
View remediation
