Back to skill

Security audit

wangkang-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it persistently records session-derived content and can promote it into future agent instruction files with weak scoping and privacy controls.

Install only if you want persistent self-improvement logs and understand that they may affect future agent behavior. Prefer project-scoped setup over global hooks, avoid empty every-prompt matchers, redact secrets and private details before logging, do not share session history across agents without consent, and require human review before promoting anything into CLAUDE.md, AGENTS.md, SOUL.md, TOOLS.md, or Copilot instructions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:18
Finding

Untrusted Conversational Content Can Be Promoted into Persistent Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:18-26, 120-129, 265-289, 446-447
Vulnerability Type: Persistent agent memory poisoning
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:18-26:

markdown
| User corrects you | Log to `.learnings/LEARNINGS.md` with category `correction` |
| User wants missing feature | Log to `.learnings/FEATURE_REQUESTS.md` |
| API/external tool fails | Log to `.learnings/ERRORS.md` with integration details |
| Knowledge was outdated | Log to `.learnings/LEARNINGS.md` with category `knowledge_gap` |
| Found better approach | Log to `.learnings/LEARNINGS.md` with category `best_practice` |
| Simplify/Harden recurring patterns | Log/update `.learnings/LEARNINGS.md` with `Source: simplify-and-harden` and a stable `Pattern-Key` |
| Similar to existing entry | Link with `**See Also**`, consider priority bump |
| Broadly applicable learning | Promote to `CLAUDE.md`, `AGENTS.md`, and/or `.github/copilot-instructions.md` |
| Workflow improvements | Promote to `AGENTS.md` (OpenClaw workspace) |
| Tool gotchas | Promote to `TOOLS.md` (OpenClaw workspace) |
| Behavioral patterns | Promote to `SOUL.md` (OpenClaw workspace) |

SKILL.md:120-129:

markdown
### Add reference to agent files AGENTS.md, CLAUDE.md, or .github/copilot-instructions.md to remind yourself to log learnings. (this is an alternative to hook-based reminders)

#### Self-Improvement Workflow

When errors or corrections occur:
1. Log to `.learnings/ERRORS.md`, `LEARNINGS.md`, or `FEATURE_REQUESTS.md`
2. Review and promote broadly applicable learnings to:
   - `CLAUDE.md` - project facts and conventions
   - `AGENTS.md` - workflows and automation
   - `.github/copilot-instructions.md` - Copilot context

SKILL.md:265-289:

markdown
## Promoting to Project Memory

When a learning is broadly applicable (not a one-off fix), promote it to permanent project memory.

### When to Promote

- Learning applies across multiple files/features
- 
...[truncated 3616 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit workspace-owner approval before modifying any persistent agent-context file.
  2. Never copy conversational text directly into CLAUDE.md, AGENTS.md, SOUL.md, TOOLS.md, or Copilot instructions.
  3. Record proposed promotions in a review queue or generated patch rather than applying them automatically.
  4. Add provenance fields identifying the source session, author, evidence, reviewer, and approval timestamp.
  5. Verify factual claims against trusted project documentation, code, tests, or authoritative external documentation.
  6. Treat recurrence only as a prioritization signal, never as evidence that content is trustworthy.
  7. Reject proposed rules that:
    • Override system, developer, or user instructions
    • Weaken security checks or approval requirements
    • Expand permissions or tool access
    • Request secrets or sensitive data
    • Introduce external communication or code execution
    • Instruct the agent to conceal activity
  8. Store untrusted learning content as quoted data and clearly delimit it from executable agent instructions.
  9. Add automated scanning for prompt-injection phrases and security-sensitive directives before promotion.
  10. Replace “Promote aggressively” with a conservative, review-gated policy requiring verified evidence and least-privilege impact analysis.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about capturing and using learnings/corrections for continuous improvement after failures, user corrections, missing capabilities, or outdated knowledge. The supplied code does not implement learning capture, error tracking, correction storage, or review behavior. Instead, it is a helper utility for extracting/promoting a learning into a new skill by creating directories and a template file on disk. This is a materially different primary purpose and introduces undeclared filesystem-writing capabilities. While the script references learnings conceptually, its behavior is specifically skill scaffolding, not maintaining a continuous-improvement memory or reacting to the listed triggers.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Guidance to modify ~/.claude/settings.json directs users to a high-trust agent configuration location that persists across sessions. While not inherently malicious, placing command hooks in a global config directory creates a strong persistence mechanism and expands the impact of any compromised script or unsafe configuration.

Content

Scanner excerpt · references/hooks-setup.md (reported line 48)May include surrounding context.

Option 2: User-Level Configuration

Add to ~/.claude/settings.json for global activation:

json
{

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 177)May include surrounding context.

sessions_send

Send message to another session:

text
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use the skill when a command fails, when the user corrects the agent, when a capability is missing, when an API fails, when knowledge is outdated, and also to review learnings before major tasks. This is a very broad set of activation conditions and does not provide exclusions or negative examples, increasing the chance of unintended invocation in routine conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill repeatedly instructs the agent to write learnings, errors, and corrections into durable markdown files without any sanitization, redaction, or warning about secrets and personal data. In practice, command output, user corrections, and troubleshooting context often contain tokens, internal URLs, stack traces, proprietary code, or personal information that would then be persistently stored.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Creating persistent learning files under a user workspace is not dangerous on its own, but in this skill it directly supports long-term retention of potentially sensitive session-derived content. The context makes persistence more dangerous because the surrounding instructions encourage broad collection and reuse of conversational and operational data.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cross-session features explicitly encourage reading other session transcripts and sending learnings between sessions without a privacy boundary or consent model. That creates a straightforward path for conversation-derived sensitive data to move beyond its original context and be exposed to other agents, sessions, or operators.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section normalizes persistence and propagation of conversation-derived content across sessions, which is a classic data leakage pattern for agent systems. Because the content is natural language rather than structured secrets scanning output, sensitive information can be copied semantically into durable or shared memory where later agents may re-expose it.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The logging workflow asks the agent to capture full user corrections, context, and requested capabilities in persistent files. Those fields can easily include confidential project details, internal architecture, customer data, or operational incidents, turning ordinary conversation into a long-lived data store.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The templates explicitly request storage of actual error messages, outputs, inputs, and user context in markdown records. Error output and inputs are especially likely to contain credentials, API keys, file paths, internal endpoints, proprietary source snippets, or regulated data, making this persistent logging behavior materially dangerous.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The 'Detection Triggers' section includes generic phrases like 'Can you also...', 'Is there a way to...', and broad conditions such as 'Unexpected output or behavior.' These patterns are common in everyday assistance requests and lack constraints or exclusion criteria, making activation ambiguous.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to 'promote aggressively' increases the blast radius of any sensitive content already captured in learnings by copying it into higher-visibility memory and instruction files. Once promoted, the data is more likely to be injected into future sessions and repeatedly exposed or relied upon out of context.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/examples.md (reported line 301)May include surrounding context.

When the above learning is extracted as a skill, it becomes:

File: skills/docker-m1-fixes/SKILL.md

markdown
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Creating .claude/settings.json in the project root establishes persistent automatic behavior for future agent sessions in that repository. In the context of a self-improvement skill with command hooks, this persistence increases the chance that users forget the hook is active, leading to ongoing execution and repeated capture of prompt or tool-related context.

Content

Scanner excerpt · references/hooks-setup.md (reported line 15)May include surrounding context.

Option 1: Project-Level Configuration

Create .claude/settings.json in your project root:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

An empty matcher causes the hook to fire on every prompt, greatly broadening execution frequency and data exposure. In this skill, that means the activator script runs continuously across all user interactions, increasing the chance of prompt leakage, unintended persistence, and abuse if the script is modified or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-level setup installs the hook globally in ~/.claude/settings.json with no matcher constraints, so it affects all sessions and repositories. Global, unconditional activation increases blast radius: a flawed or tampered script can influence every future interaction and observe broad prompt content over time.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Using an empty matcher in Codex CLI similarly causes invocation on every prompt, making execution conditions overly broad. The skill context makes this more dangerous because it is designed for persistent learning capture, so broad triggering can normalize constant collection and increase exposure of sensitive prompts or operational context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document states that hook scripts 'only output text' and 'don't modify files or run commands', yet the configuration explicitly installs shell command hooks that execute local scripts. This is misleading security guidance because users may underestimate the trust and execution risk of those scripts, which run with the agent's permissions and could perform arbitrary actions if changed or replaced.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 57)May include surrounding context.

openclaw hooks enable self-improvement

text

### 3. Create Learning Files

Create the `.learnings/` directory in your workspace:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill focused on recording learnings and reviewing them for future improvement. This script instead scaffolds entirely new skill directories and writes templated SKILL.md files, which is a broader repository-modification capability than merely capturing or reviewing learnings.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Creating directories, generating manifests, and instructing the user to add scripts introduces a skill-authoring capability rather than a learning-capture capability. That capability may be useful operationally, but it is not an obvious requirement of recording failures, corrections, or outdated knowledge.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains setup steps that write into ~/.openclaw/skills/, ~/.openclaw/hooks/, and create .learnings/ directories, which affect local configuration and persistent data. The instructions are presented as straightforward commands without any user-facing warning about their impact, backup considerations, or that they alter agent behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.