Back to skill

Security audit

123123123123

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed self-improvement logger, but it encourages persistent changes to future agent instructions without enough review controls.

Review this carefully before installing. Use project-scoped setup, keep hooks disabled unless you want them, avoid global ~/.claude or .codex hooks, keep .learnings local and gitignored unless intentionally shared, and require a human-reviewed diff before anything is promoted into AGENTS.md, CLAUDE.md, SOUL.md, TOOLS.md, or copilot-instructions.md.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:353
Finding

Untrusted Learnings Can Be Promoted into Persistent Agent Instructions

Content
View full analysis
" .learnings/LEARNINGS.md` 4. If found: - Increment `Recurrence-Count` - Update `Last-Seen` - Add `See Also` links to related entries/tasks 5. If not found: - Create a new `LRN-...` entry - Set `Source: simplify-and-harden` - Set `Pattern-Key`, `Recurrence-Count: 1`, and `First-Seen`/`Last-Seen` ### Promotion Rule (System Prompt Feedback) Promote recurring patterns into agent context/system prompt files when all are true: - `Recurrence-Count >= 3` - Seen across at least 2 distinct tasks - Occurred within a 30-day window Promotion targets: - `CLAUDE.md` - `AGENTS.md` - `.github/copilot-instructions.md` - `SOUL.md` / `TOOLS.md` for OpenClaw workspace-level guidance when applicable ``` The risk is amplified by the following guidance: ```markdown ## Best Practices 1. **Log immediately** - context is freshest right after the issue 2. **Be specific** - future agents need to understand quickly 3. **Include reproduction steps** - especially for errors 4. **Link related files** - makes fixes easier 5. **Suggest concrete fixes** - not just "investigate" 6. **Use consistent categories** - enables filtering 7. **Promote aggressively** - if in doubt, add to CLAUDE.md or .github/copilot-instructions.md 8. **Review regularly** - stale learnings lose value ``` ### Technical Analysis The workflow accepts information derived from task summaries, conversations, user corrections, and other learning entries, then recommends promoting that information into files used as ...[truncated 2407 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/extract-skill.sh:93
Finding

Relative Output Validation Can Be Bypassed Through Symbolic Links

Content
View full analysis
"$SKILL_PATH/SKILL.md" << TEMPLATE ``` The documented initialization commands similarly use shell redirection without preventing symlink traversal: ```bash mkdir -p .learnings [ -f .learnings/LEARNINGS.md ] || printf "# Learnings\n\nCorrections, insights, and knowledge gaps captured during development.\n\n**Categories**: correction | insight | knowledge_gap | best_practice\n\n---\n" > .learnings/LEARNINGS.md [ -f .learnings/ERRORS.md ] || printf "# Errors\n\nCommand failures and integration errors.\n\n---\n" > .learnings/ERRORS.md [ -f .learnings/FEATURE_REQUESTS.md ] || printf "# Feature Requests\n\nCapabilities requested by the user.\n\n---\n" > .learnings/FEATURE_REQUESTS.md ``` ### Technical Analysis The extraction script rejects absolute paths and lexical `..` path components, but it does not resolve the output path to its canonical filesystem location. A relative path can contain a symbolic-link component that points outside the current workspace. For example, `./skills` can be a symbolic link to another di ...[truncated 2191 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a skill for capturing learnings, errors, corrections, and improvement insights. The supplied code does not implement learning capture, review, error logging, or correction tracking. Instead, it is a command-line helper that creates a new skill folder and templated SKILL.md file from a skill name, optionally as a dry run. Its primary purpose is skill scaffolding/generation, which is materially different from the declared purpose. The filesystem write behavior is also undeclared relative to the description.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The hook configuration uses empty matchers, which causes activation on every prompt and potentially every Bash tool use. That broad scope can lead to pervasive monitoring-like behavior, overcollection of command/output context, and frequent automatic execution of local scripts that inspect user activity across the workspace.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Directing users to install command hooks in ~/.claude/settings.json creates persistence in the agent's config directory, affecting all future sessions. That makes the self-improvement mechanism more dangerous because it establishes durable execution from a privileged trust location that users may not routinely audit.

Content

Scanner excerpt · references/hooks-setup.md (reported line 48)May include surrounding context.

Option 2: User-Level Configuration

Add to ~/.claude/settings.json for global activation:

json
{

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 181)May include surrounding context.

sessions_send

Send message to another session:

text
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")

Session Persistence

Medium
Category
Rogue Agent
Confidence
71% confidence
Finding

The skill encourages persistent storage of learnings and errors under a user home/workspace path, creating session-derived records that may outlive the original context. Even with warnings not to log secrets, persistent notes can accumulate sensitive operational details, tool output, file paths, and user behavior that increase privacy and data retention risk.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are very broad and conversational, so the skill may activate in many situations where the user did not intend persistent logging or workflow changes. In practice this can cause unnecessary collection of session data and increase the chance of writing sensitive context into local files despite the guidance to avoid secrets.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/examples.md (reported line 301)May include surrounding context.

When the above learning is extracted as a skill, it becomes:

File: skills/docker-m1-fixes/SKILL.md

markdown
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

Placing hook configuration in .claude/settings.json introduces session-persistent behavior that automatically reactivates on future agent sessions. While presented as a usability feature, this persistence can normalize ongoing command execution and makes malicious or accidental script changes continue to affect later interactions without fresh consent.

Content

Scanner excerpt · references/hooks-setup.md (reported line 15)May include surrounding context.

Option 1: Project-Level Configuration

Create .claude/settings.json in your project root:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

An empty matcher causes the UserPromptSubmit hook to fire on every prompt, creating unconditional execution of a local command. In a self-improvement skill, this broad trigger increases exposure to prompt-driven persistence and makes any compromised or modified hook script run constantly across normal usage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The user-level configuration enables the hook globally from ~/.claude/settings.json without meaningful trigger constraints, so the command runs across all projects and sessions. In this skill context, global always-on activation amplifies the blast radius of any script compromise, path hijack, or unintended data exposure from prompts across unrelated work.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states that hook scripts 'only output text' and 'don't modify files or run commands,' but the configured hooks are executed as shell commands. This mismatch can mislead users into trusting hook scripts as harmless when they actually execute with the agent's permissions, increasing the risk of unintended code execution or privilege misuse if the scripts are altered or replaced.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

Persisting learnings to .learnings/ creates durable session memory that may survive resets and be reused in later prompts, which can unintentionally retain sensitive data or contaminated instructions. In the context of a self-improvement skill, persistence is expected, but without retention, review, and sanitization controls it meaningfully increases privacy and prompt-safety risk.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 57)May include surrounding context.

openclaw hooks enable self-improvement

text

### 3. Create Learning Files

Create the `.learnings/` directory in your workspace:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide instructs users to create persistent learning storage in workspace or skill directories but does not prominently warn that logged content may contain corrections, failures, prompts, or other sensitive operational data. Because these files can later be injected into future sessions, accidental persistence can create privacy, integrity, and prompt-injection risks beyond the original interaction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document expands a self-improvement skill into cross-session transcript access, message passing, and sub-agent spawning, which materially broadens data access and execution scope beyond simply recording learnings. Even though it includes some cautionary language, these capabilities can expose unrelated session data or propagate sensitive context if operators follow the guide without strict trust boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list is broad and loosely defined, so the skill may activate on routine errors, vague 'knowledge gaps,' or normal model behavior and persist information unexpectedly. In a system that writes to durable files and can influence future prompts, over-triggering increases the risk of storing sensitive or low-quality data and reinforcing incorrect behaviors.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.