Back to skill

Security audit

OpenClaw自动进化系统

Security checks for vulnerabilities and agentic risk

Overview

The skill does not show malicious code, but it asks for automatic self-learning and persistent memory behavior without clear user controls and its description overstates what the implementation does.

Review this before installing if you do not want an agent skill that can persist learning notes or encourage automatic rule/memory behavior. It appears non-destructive and local-only, but its memory and auto-activation behavior should be narrowed and made opt-in before routine use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

描述强调的是较完整的自我改进系统,核心在于自动化分析、学习、验证和规则沉淀;但代码只实现了基础的文件存在性检查、规则文件摘要读取以及手动追加学习记录,功能范围明显更窄,且主要目的更接近“状态/记录工具”而非真正的自进化系统。代码访问的资源(工作区状态目录、学习记录目录、关键 Markdown 文件)与该主题相关,不属于额外越权能力,但描述与实际行为存在显著夸大,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
76% confidence
Finding

The skill advertises capabilities consistent with environment access and file-writing behavior, but it does not declare any explicit tool scope or permissions boundary. In an agent framework, missing scope declarations can cause overbroad execution privileges, making unintended persistence or host/environment access harder to audit and restrict.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes persistent memory and automatic rule-base initialization but does not present a clear user-facing warning about what data is stored, how long it persists, or when writes occur. In a self-evolution context, silent persistence is more dangerous because users may unknowingly provide sensitive operational or personal data that becomes part of long-lived memory or rules.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Broad natural-language triggers can activate the skill in unrelated conversations, causing it to run outside the user's intended scope. In a skill that references memory, health state, and rule initialization, accidental invocation can lead to unintended state changes, privacy exposure, or persistence operations without clear consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file contains user-facing text and operational descriptions only in Chinese, including the main module description and later response messages. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation because users are not offered any locale or language choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes automatic problem discovery, root-cause analysis, suggestion generation, effect validation, and rule formation. In practice, the skill only checks for existence of three local files, counts bullet lines in one markdown file, and appends learning notes; there is no analysis, validation, or rule-extraction loop implemented.

Content

No source excerpt is available for this finding.

Tainted flow: 'learning_file' from os.environ.get (line 52, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
85% confidence
Finding

The path used for file writes is derived from the OPENCLAW_WORKSPACE environment variable, so an attacker who can influence the runtime environment can redirect writes outside the intended workspace via symlinks or a crafted path. In an agent/plugin context, writing attacker-influenced content to arbitrary files can enable state corruption, persistence, or tampering with other agent data.

Content

Scanner excerpt · self_evolution.py (reported line 65)May include surrounding context.

python
记录时间: {datetime.now().isoformat()}
"""
    
    with open(learning_file, "a") as f:
        f.write(content + "\n")
    
    return {"status": "success", "file": str(learning_file)}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invoke() entrypoint returns Chinese-only status and help messages to users, with no mechanism to select another language. This creates a locale policy issue because the skill enforces one language by default rather than offering choice or clearly documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The module documentation presents this file as an 'OpenClaw self-evolution system' with 'directly usable core functionality'. However, the actual behavior is limited to basic file-existence health checks, markdown rule counting, and manual learning record writes, which does not match the documented impression of a functioning self-improvement system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.