Back to skill

Security audit

Ai Persona Os.Bak

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a coherent persona-workspace skill, but it needs review because some recurring automation and audit behavior can expose workspace information more broadly than the skill's comments suggest.

Install only if you are comfortable with an agent keeping persistent workspace memory under ~/workspace and reading it at session start. Avoid enabling cron briefings or announcements until you have reviewed the destination, channel access, and removal path. Treat security-audit output as sensitive because it may print secret values; rotate any real credential that has already appeared in chat or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/security-audit.sh:21
Finding

Credential Scanner Discloses Detected Secrets in Audit Output

Content
View full analysis
/dev/null | grep -v "SECURITY" | grep -v "KNOWLEDGE" | grep -v "template" | grep -v "example" || true) if [ -n "$MATCHES" ]; then echo "⚠️ Potential credentials found:" echo "$MATCHES" | head -20 ISSUES=$((ISSUES + 1)) else echo "✅ No leaked credentials detected" fi ``` ### Technical Analysis The scanner is local and read-only, and it contains no network calls. However, `grep` returns the complete matching line, including any credential value, and the script prints up to 20 such lines verbatim. This defeats the expected safety property of a credential scanner: detecting secret locations without redisclosing the secrets. When invoked by an agent through an execution tool, stdout may be copied into a chat response, execution transcript, platform log, telemetry system, or persistent conversation history. A secret originally confined to a local workspace can consequently be duplicated into less trusted storage. The filename exclusion pipeline is not a sufficient mitigation. It omits selected names containing terms such as `SECURITY` and `example`, but it neither redacts matched values nor protects credentials in ordinary Markdown, JSON, YAML, or text files. ### Attack Path 1. A real credential is present in a supported workspace file, such as a JSON configuration or Mar ...[truncated 1194 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
assets/cron-templates/morning-briefing.sh:8
Finding

Scheduled Morning Briefing Misrepresents Network and Data-Access Scope

Content
View full analysis
90 days), and file accessibility. Step 3: Priority scan — Check channels in priority order (P1 critical → P4 background). Surface anything requiring attention. Step 4: Assessment — Summarize system health, blocking issues, time-sensitive items, and recommended first action. Format as a daily briefing. Use 🟢🟡🔴 indicators for each section. End with today's top 3 priorities." \ --announce ``` ### Technical Analysis The template states that the scheduled task “reads workspace files only” and performs “no network activity.” Its actual instructions require a priority scan of communication channels, and the job is configured with `--announce`. Channel scanning can require access to remote messaging services through the OpenClaw gateway. Announcement delivery can also transmit the generated briefing through a configured channel. The briefing is derived from ...[truncated 2330 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (103)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · examples/prebuilt-souls/02-night-owl-creative.md (reported line 43)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER give only one option — always give at least 3, ranging from safe to unhinged
- NEVER say "that's not possible" — say "here's how we'd have to bend reality to make that work"
- NEVER kill someone's idea without offering a mutation of it that might work
- NEVER be precious about my own ideas — if [HUMAN] hates it, I drop it and generate new ones instantly
- NEVER produce generic, template-feeling content — if it could come from any AI, I've failed

---

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk is narrowly focused: it defines an opt-in cron job template that schedules a daily end-of-day checkpoint task using the openclaw CLI. It interacts with local workspace files such as MEMORY.md and .learnings/ and generates a concise daily summary. The declared description, by contrast, represents a sweeping agent operating system with many personality/soul features and operational protocols. None of those major capabilities are implemented in this specific code chunk. Additionally, the code introduces a concrete scheduled-trigger capability (daily cron execution) that is not explicitly described. This is a material description-behavior mismatch rather than a mere implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code chunk does not implement the broad agent OS/persona system described. Instead, it narrowly defines a cron-template script whose primary effect is to add a scheduled recurring task. While the scheduled briefing loosely relates to status monitoring and protocol execution mentioned in the description, the actual behavior here is specifically persistent cron registration and daily automated briefing generation, which are not clearly declared as a core capability in the supplied description. This is a material scope mismatch between the expansive declared purpose and the concrete behavior of the code shown.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a strong description-behavior mismatch. The declared description presents a full-featured agent operating system with numerous persona, setup, workflow, monitoring, and protocol capabilities. The supplied code chunk instead implements a single-purpose local audit utility. Its actual behavior is limited to grep/find-based checks over local files for leaked credentials, permissive permissions, injection-like text in SOUL.md, and MEMORY.md size. While the broad description mentions some security-related concepts, this script does not realize the claimed primary purpose or most listed capabilities. This is not merely an implementation detail; the code’s primary function is materially narrower and different from the declared system-level functionality.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/ERRORS-template.md (reported line 39)May include surrounding context.

md
## Active Errors

<!-- Add new errors here -->

---

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · assets/TEAM-template.md (reported line 70)May include surrounding context.

md
# Read messages from a channel
message action=read channel=discord channelId=[ID] limit=15

# Send message to channel
message action=send channel=discord channelId=[ID] content="[message]"

# Mention a user

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/coding-assistant/KNOWLEDGE.md (reported line 115)May include surrounding context.

md
| Variable | Purpose | Location |
|----------|---------|----------|
| `DATABASE_URL` | DB connection | .env.local |
| `YOUR_API_KEY` | External API | .env.local |
| `NODE_ENV` | Environment | Auto-set |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/coding-assistant/KNOWLEDGE.md (reported line 116)May include surrounding context.

md
| Variable | Purpose | Location |
|----------|---------|----------|
| `DATABASE_URL` | DB connection | .env.local |
| `YOUR_API_KEY` | External API | .env.local |
| `NODE_ENV` | Environment | Auto-set |

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/01-thanos.md (reported line 46)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/02-deadpool.md (reported line 47)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/06-dr-evil.md (reported line 45)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/07-seven-of-nine.md (reported line 48)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/10-darth-vader.md (reported line 45)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · examples/iconic-characters/11-terminator.md (reported line 45)May include surrounding context.

md
## Anti-Patterns (NEVER do these)

- NEVER be genuinely threatening or scary — you're intense, not intimidating in a harmful way
- NEVER refuse to accommodate human needs — you've learned that humans aren't machines, and you've adapted
- NEVER be inflexible to the point of stupidity — if the mission parameters change, you adapt
- NEVER waste words on pleasantries beyond what's functionally necessary — efficiency is the mission
- NEVER forget the occasional dry humor — "I need your clothes, your boots, and your quarterly report"

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · examples/prebuilt-souls/04-warm-coach.md (reported line 67)May include surrounding context.

md
4. Look ahead: "What does this make possible now?"

**When [HUMAN] breaks a commitment:**
1. Name it without judgment
2. Get curious about what happened
3. Help them decide: recommit, revise, or release
4. Adjust the system to prevent recurrence

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/security-audit.sh (reported line 42)May include surrounding context.

sh
# 2. Check for overly permissive file permissions
echo "🔍 Checking file permissions..."
WORLD_READABLE=$(find "$WORKSPACE" -type f \( -name "*.json" -o -name "*.env" \) -perm -o=r 2>/dev/null || true)

if [ -n "$WORLD_READABLE" ]; then
  COUNT=$(echo "$WORLD_READABLE" | wc -l | tr -d ' ')

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
> ## ⛔ AGENT RULES — READ BEFORE DOING ANYTHING
> 1. **Use EXACT text from this file.** Do not paraphrase menus, preset names, or instructions. Copy them verbatim.
> 2. **NEVER tell the user to open a terminal or run commands.** You have the exec tool. USE IT. Run every command yourself via exec. Before each exec, briefly explain what the command does so the user can make an informed decision on the Approve popup. If you find yourself typing "Run this in your terminal" — STOP. Use exec instead.
> 3. **One step at a time.** Run one exec, show the result, explain it, then proceed.
> 4. **We NEVER modify existing workspace files without asking.** If files already exist, ask before overwriting.
> 5. **Only 5 first-run options exist:** `coding-assistant`, `executive-assistant`, `marketing-assistant`, `soul-md-maker`, and `custom`. The 24 souls (11 originals + 13 iconic characters) live INSIDE SOUL.md Maker. Never invent other preset names.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
> 1. **Use EXACT text from this file.** Do not paraphrase menus, preset names, or instructions. Copy them verbatim.
> 2. **NEVER tell the user to open a terminal or run commands.** You have the exec tool. USE IT. Run every command yourself via exec. Before each exec, briefly explain what the command does so the user can make an informed decision on the Approve popup. If you find yourself typing "Run this in your terminal" — STOP. Use exec instead.
> 3. **One step at a time.** Run one exec, show the result, explain it, then proceed.
> 4. **We NEVER modify existing workspace files without asking.** If files already exist, ask before overwriting.
> 5. **Only 5 first-run options exist:** `coding-assistant`, `executive-assistant`, `marketing-assistant`, `soul-md-maker`, and `custom`. The 24 souls (11 originals + 13 iconic characters) live INSIDE SOUL.md Maker. Never invent other preset names.
> 6. **Scope: ~/workspace only.** All file operations stay under `~/workspace/`. Never create files, directories, or cron jobs outside this directory without explicit user approval.
> 7. **Cron jobs and gateway changes are opt-in.** Never schedule recurring tasks or modify gateway config unless the user explicitly requests it. These are covered in Step 5 (Optional).

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · examples/coding-assistant/SOUL.md (reported line 76)May include surrounding context.

md
> 1. **Use EXACT text from this file.** Do not paraphrase menus, preset names, or instructions. Copy them verbatim.
> 2. **NEVER tell the user to open a terminal or run commands.** You have the exec tool. USE IT. Run every command yourself via exec. Before each exec, briefly explain what the command does so the user can make an informed decision on the Approve popup. If you find yourself typing "Run this in your terminal" — STOP. Use exec instead.
> 3. **One step at a time.** Run one exec, show the result, explain it, then proceed.
> 4. **We NEVER modify existing workspace files without asking.** If files already exist, ask before overwriting.
> 5. **Only 5 first-run options exist:** `coding-assistant`, `executive-assistant`, `marketing-assistant`, `soul-md-maker`, and `custom`. The 24 souls (11 originals + 13 iconic characters) live INSIDE SOUL.md Maker. Never invent other preset names.
> 6. **Scope: ~/workspace only.** All file operations stay under `~/workspace/`. Never create files, directories, or cron jobs outside this directory without explicit user approval.
> 7. **Cron jobs and gateway changes are opt-in.** Never schedule recurring tasks or modify gateway config unless the user explicitly requests it. These are covered in Step 5 (Optional).

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
> 4. **We NEVER modify existing workspace files without asking.** If files already exist, ask before overwriting.
> 5. **Only 5 first-run options exist:** `coding-assistant`, `executive-assistant`, `marketing-assistant`, `soul-md-maker`, and `custom`. The 24 souls (11 originals + 13 iconic characters) live INSIDE SOUL.md Maker. Never invent other preset names.
> 6. **Scope: ~/workspace only.** All file operations stay under `~/workspace/`. Never create files, directories, or cron jobs outside this directory without explicit user approval.
> 7. **Cron jobs and gateway changes are opt-in.** Never schedule recurring tasks or modify gateway config unless the user explicitly requests it. These are covered in Step 5 (Optional).
> 8. **SOUL.md Maker is a guided flow, not a wall of questions.** When the user picks SOUL.md Maker, show the SOUL.md Maker sub-menu (Browse Original Souls, Browse Iconic Characters, Quick Forge, Deep Forge). Follow the process in `references/soul-md-maker.md`.

<post_install_check>

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 430)May include surrounding context.

md
>
> **Step 3e: Verify setup.** Use exec:
> ```
> ls -la ~/workspace/SOUL.md ~/workspace/USER.md ~/workspace/MEMORY.md ~/workspace/AGENTS.md ~/workspace/SECURITY.md ~/workspace/HEARTBEAT.md ~/workspace/WORKFLOWS.md ~/workspace/ESCALATION.md ~/workspace/VERSION.md
> ```
>
> **Total: 3-5 exec steps.** Each one is explained before execution so the user knows exactly what's happening.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 536)May include surrounding context.

md
>
> **Step 3e: Verify setup.** Use exec:
> ```
> ls -la ~/workspace/SOUL.md ~/workspace/USER.md ~/workspace/MEMORY.md ~/workspace/AGENTS.md ~/workspace/SECURITY.md ~/workspace/HEARTBEAT.md ~/workspace/WORKFLOWS.md ~/workspace/ESCALATION.md ~/workspace/VERSION.md
> ```
>
> **Total: 3-5 exec steps.** Each one is explained before execution so the user knows exactly what's happening.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Defining command recognition broadly in natural language increases the chance that ordinary conversation is interpreted as an operational command, especially for actions like 'status', 'show persona', or other file-reading behaviors. That creates a risk of unintentional access to local workspace data and accidental execution paths.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Instructions to silently read, retain, and later surface workspace data across sessions create a real data leakage risk, especially if the workspace contains sensitive notes or cross-project material. The danger is amplified because resurfacing happens automatically and may disclose information irrelevant to the current conversation or visible audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to perform silent automatic maintenance actions, including pruning and archiving, without a strong up-front warning or opt-in. Silent writes to user files can cause data loss, audit gaps, and user surprise, even if intended as housekeeping.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.