Back to skill

Security audit

Self Evolving Skill

Security checks for vulnerabilities and agentic risk

Overview

This looks like a local self-learning skill rather than malware, but it needs review because its storage/runtime behavior is inconsistent and it can log full tool inputs.

Install only if you are comfortable with a skill that stores learning data locally and may receive arbitrary task context. Avoid passing secrets or personal data in skill execution context, check which storage directory is actually used, and prefer a version that ships the documented core files, redacts logs, and clearly documents retention and deletion controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.ts:139
Finding

Sensitive MCP Tool Arguments Disclosed Through Unfiltered Logging

Content
View full analysis

Vulnerability Details

File Location: src/index.ts, lines 139-141
Vulnerability Type: Sensitive data exposure through application logs
Risk Level: Medium

Vulnerable Code

ts
private simulateCall(tool: string, args: Record<string, any>): any {
  // Simplified implementation
  console.log(`[SelfEvolvingSkill] ${tool}:`, args);

Sensitive values can reach this logging statement from the execution interface at src/index.ts, lines 243-250:

ts
const result = await this.server.call('skill_execute', {
  skill_id: params.skillId,
  context: params.context || {},
  embedding: params.embedding,
  success: params.success !== false,
  value_realization: params.value !== undefined ? params.value : 1.0
});

Technical Analysis

When the Python MCP server is unavailable, MCPServer.call() invokes simulateCall(). The audited package does not contain the expected core/mcp_server.py, so this fallback is likely to be used in the supplied artifact.

The fallback logs the complete args object without field allowlisting, redaction, or sensitivity checks. The skill_execute interface permits arbitrary data in context and also passes embeddings and skill identifiers. Callers may reasonably include confidential task content, credentials, access tokens, personal data, internal identifiers, or proprietary information in that context.

Application logs commonly have broader and longer-lived access than the original request data. They may be retained in terminal histories, CI output, container logs, process supervisors, or centralized logging systems.

Attack Path

  1. The Python MCP server is absent or otherwise fails to start.
  2. Initialization silently enables the JavaScript simulation fallback.
  3. A user or upstream agent invokes skill_execute with sensitive information in context or another argument.
  4. MCPServer.call() forwards the complete argument object to simulateCall().
  5. simulateCall() writes the complete obj ...[truncated 893 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove complete argument logging from simulateCall():

    ts
    console.log(`[SelfEvolvingSkill] Simulating tool: ${tool}`);
    
  2. If diagnostics require argument metadata, use a strict allowlist and log only non-sensitive properties:

    ts
    console.log('[SelfEvolvingSkill] Simulating tool', {
      tool,
      hasContext: Boolean(args.context),
      embeddingLength: Array.isArray(args.embedding) ? args.embedding.length : 0
    });
    
  3. Never log arbitrary context objects, embeddings, authorization values, tokens, cookies, passwords, or user-supplied payloads.

  4. Add a centralized redaction function for all structured logging. Recursively redact keys such as authorization, token, secret, password, cookie, and apiKey.

  5. Disable diagnostic logging by default in production and control it through an explicit logging-level configuration.

  6. Avoid silently entering simulation mode when the expected server implementation is absent. Return a clear initialization error unless callers explicitly opt into fallback behavior.

  7. Add automated tests that pass canary secrets through every MCP method and verify that no secret appears in standard output, standard error, or structured logs.

  8. Apply least-privilege access controls and appropriate retention limits to all application and centralized logs.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (38)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a meta-cognitive learning system, but the documented interfaces indicate CRUD-style skill management, persistent storage access, command dispatch, and hardcoded/default storage paths. This creates a description-behavior mismatch that can mislead users about data handling and operational reach, especially where persistent state and external invocation are involved.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill is presented as a meta-cognitive learning system, but the documented interfaces indicate CRUD-style skill management, persistent storage access, command dispatch, and hardcoded/default storage paths. This creates a description-behavior mismatch that can mislead users about data handling and operational reach, especially where persistent state and external invocation are involved.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · INSTALLATION.md (reported line 43)May include surrounding context.

md
python3 ~/.openclaw/skills/self-evolving-skill/mcporter_adapter.py skill_list '{}'

# 创建新Skill
python3 ~/.openclaw/skills/self-evolving-skill/mcporter_adapter.py skill_create '{"name":"MySkill"}'

# 分析嵌入
python3 ~/.openclaw/skills/self-evolving-skill/mcporter_adapter.py skill_analyze '{"embedding":[0.1,0.2,0.3]}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation advertises a skill_clear tool that wipes all data and cache but provides no warning, confirmation workflow, backup guidance, or scope description. In an agent-tooling context, exposing destructive operations without guardrails increases the chance of accidental or automated irreversible data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill documentation is presented in Chinese, with no indication that other languages are supported or that the Chinese-only presentation is a deliberate, justified regional constraint. This can violate language/locale policy when users are not given a language choice or opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documentation describes capabilities that involve environment/filesystem interaction and local installation paths, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, undeclared capability scope reduces transparency and can cause the agent or user to invoke a skill with broader access than expected, increasing the chance of unintended file or environment access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation states that learned experience is automatically persisted and later loaded, but it does not warn the user where data is stored, what data may be retained, or the impact on local user data. Silent persistence can expose sensitive prompts, embeddings, or behavioral history and may create privacy and integrity risks if data accumulates without user awareness.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
68% confidence
Finding

The documented workflow indicates creating, executing, analyzing, and persisting skill state across sessions, which implies session persistence and accumulation of behavioral data. In this skill's context, persistent cross-session state is more sensitive because the tool is explicitly designed to learn and evolve over time, so retained state may influence future executions in opaque ways.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
openclaw skill self-evolving-skill list

# 创建Skill
openclaw skill self-evolving-skill create --name "MySkill"

# 执行
openclaw skill self-evolving-skill execute <id> --success

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script creates directories, overwrites a symlink, and copies files into $HOME/.openclaw paths. Although it prints success messages afterward, there is no pre-action disclosure or confirmation that user files in those locations will be created or replaced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Docstrings, status messages, and CLI usage text are presented in Chinese only, with no indication that the user can choose another language or locale. This creates a language-policy concern because the skill appears to enforce a specific language by default rather than offering opt-in or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes a meta-cognitive self-learning and automated evolution system, but this adapter also provides explicit file-backed save/load operations for skills and embeddings. Persisting, reloading, and enumerating stored skills are broader lifecycle/storage-management behaviors not clearly conveyed by the manifest description itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The adapter performs persistent load and save operations on local storage without any user-facing warning, confirmation, or clear disclosure. In an agent skill context, silent persistence can surprise operators, retain sensitive data longer than expected, and create privacy and integrity risks if users do not realize state is being written and reloaded across sessions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The usage text and examples are presented in Chinese, and additional runtime messages throughout the CLI also use Chinese. For a general-purpose CLI, this imposes a specific language on users without opt-in or any indication that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code spawns a local Python subprocess and passes it a writable storage path without any integrity check, trust boundary documentation, or user consent. That expands the skill's execution surface beyond the TypeScript wrapper and means any compromise, replacement, or unexpected behavior in mcp_server.py executes with the agent's local privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill starts a Python server automatically during initialization, with no confirmation, disclosure, or permission gate. In an agent environment, silently launching an executable is security-relevant because it changes local state, may expose services, and may surprise operators who did not expect code execution beyond the current process.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/index.ts:90