Back to skill

Security audit

wangkang-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed self-improvement logger, but it encourages broad persistent agent-memory changes and always-on hooks without enough consent, sanitization, or scoping.

Install only if you want persistent self-improvement logs and agent-memory promotion. Keep logs local, redact secrets and private user data, avoid global hooks unless necessary, review diffs before editing CLAUDE.md/AGENTS.md/SOUL.md/TOOLS.md, and do not promote untrusted user text into future agent instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:23
Finding

Untrusted learning content can be promoted into persistent agent-control files

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
hooks/openclaw/handler.js:8
Finding

Opt-in hooks inject persistent behavioral directives into agent context

Content
View full analysis
{ // Safety checks for event structure if (!event || typeof event !== 'object') { return; } // Only handle agent:bootstrap events if (event.type !== 'agent' || event.action !== 'bootstrap') { return; } // Safety check for context if (!event.context || typeof event.context !== 'object') { return; } // Inject the reminder as a virtual bootstrap file // Check that bootstrapFiles is an array before pushing if (Array.isArray(event.context.bootstrapFiles)) { event.context.bootstrapFiles.push({ path: 'SELF_IMPROVEMENT_REMINDER.md', content: REMINDER_CONTENT, virtual: true, }); } }; ``` `scripts/activator.sh:8-19`: ```bash # Output reminder as system context cat << 'EOF' After completing this task, evaluate if extractable knowledge emerged: - Non-obvious solution discovered through investigation? - Workaround for unexpected behavior? - Project-specific pattern learned? - Error re ...[truncated 2446 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented primarily as a learning/error logging aid, but it also instructs the agent to extract learnings into reusable skills and run helper scripts that create new skill directories and files from command-line arguments. That capability expansion is not inherently malicious, but it widens the write surface and can cause an agent or user to approve filesystem-modifying behavior they did not expect from the declared purpose.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/hooks-setup.md (reported line 48)May include surrounding context.

Option 2: User-Level Configuration

Add to ~/.claude/settings.json for global activation:

json
{

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 177)May include surrounding context.

sessions_send

Send message to another session:

text
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation guidance is very broad and includes common conversational situations such as corrections, missing capabilities, and major tasks. In practice this can cause the skill to trigger in many ordinary interactions and normalize persistent logging or promotion of content into memory files without sufficiently specific scope limits.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill instructs creation of a persistent workspace directory under the user's home path for storing learning files. This creates session persistence outside the immediate project scope, which can retain sensitive operational history across tasks and increase the chance of unintended reuse, disclosure, or inclusion in backups and synced storage.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill recommends inter-session tools to read transcripts and send learnings between sessions, which creates a clear path for durable retention and redistribution of user-provided context. Even if intended for productivity, this broadens access to potentially sensitive information beyond the original session boundary.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The logging templates explicitly call for storing full context, inputs, parameters, environment details, and user context in durable markdown files. This is dangerous because secrets, PII, internal URLs, tokens, prompts, and proprietary data can be copied into plaintext records that persist and may later be searched, shared, or committed.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The promotion workflow encourages moving learnings into persistent memory and instruction files such as CLAUDE.md, AGENTS.md, TOOLS.md, and workspace guidance. If the original learning contains sensitive or context-bound material, promotion amplifies the leak by spreading it into files that are more likely to be loaded automatically in future sessions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are generic everyday language like 'Can you also...' or 'Actually...' and are treated as signals to log durable records. Without exclusions or sensitivity checks, normal chat content can be transformed into persistent artifacts, increasing privacy risk and causing overcollection.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/examples.md (reported line 301)May include surrounding context.

When the above learning is extracted as a skill, it becomes:

File: skills/docker-m1-fixes/SKILL.md

markdown
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/hooks-setup.md (reported line 15)May include surrounding context.

Option 1: Project-Level Configuration

Create .claude/settings.json in your project root:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The empty matcher causes the hook to run on every user prompt, creating an always-on trigger surface rather than a narrowly scoped reminder. In a self-improvement skill, that broad activation increases the chance of unnecessary context injection, prompt pollution, and abuse if the hooked script is changed or replaced.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The user-level configuration instructs operators to install a globally active hook in ~/.claude/settings.json, which extends the behavior across all sessions and repositories without clear scope boundaries. That persistence magnifies the blast radius of any mistake, noisy behavior, or future script compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Codex example also uses an empty matcher, so the hook will trigger for every prompt with no filtering. As with the Claude setup, that creates unnecessary always-on behavior and expands the opportunity for context injection or misuse of the configured command path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document explicitly describes workspace-based prompt injection, injected context from local files, and cross-session hooks/transcript access, but provides no warning about sensitive data exposure or trust boundaries. In a system that reads workspace files into model context and allows session-history access, users may inadvertently place secrets, personal data, or untrusted instructions where they can influence agent behavior or be disclosed across sessions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The guide instructs users to create persistent .learnings/ storage in the workspace or skill directory for continuous improvement without discussing retention, review, or sensitivity controls. Because this skill is specifically designed to capture errors, corrections, and operational details, the persisted notes may accumulate prompts, tool outputs, internal paths, credentials, or other sensitive project information over time.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 57)May include surrounding context.

openclaw hooks enable self-improvement

text

### 3. Create Learning Files

Create the `.learnings/` directory in your workspace:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file header and usage text state that this helper 'Creates a new skill from a learning entry,' and the implementation writes a new skill directory and SKILL.md template. That behavior is not reflected in the manifest description, which frames the skill as capturing learnings, errors, and corrections for continuous improvement.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill focused on recording and reviewing learnings for continuous improvement. This script goes beyond capture/review by generating new skill directories and templated SKILL.md files, effectively authoring new capabilities rather than merely storing or surfacing learnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes shell commands such as cp -r ... ~/.openclaw/... and mkdir -p ... that create or modify directories in the user's local environment. The guide presents them as setup steps but does not include any user-facing warning about filesystem changes or their impact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.