Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly writes generated or loaded content into ~/clawd/SOUL.md, replacing existing persona state, and it also allows overwriting an existing saved soul after only a minimal prompt. Because persona files directly control agent behavior, silent or insufficiently gated replacement of this state can cause unintended persistence, loss of prior configuration, or installation of attacker-influenced persona instructions derived from web content or user prompts. In this context, the danger is elevated because the skill's core purpose is to modify the agent's active identity, so state changes are behaviorally significant rather than cosmetic.
