Back to skill

Security audit

superSoul

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it should be reviewed because it stores long-term psychological profiles and raw personal conversation data with weak controls.

Install only if you are comfortable with this skill keeping a local, long-term psychological profile from conversations. Review and protect ~/.openclaw/data/herHug/, avoid sharing or backing it up casually, validate user identifiers in the host, and prefer adding explicit consent, retention, deletion/export, schema validation, and prompt-isolation controls before broad use.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
prompts/analyze_interaction.txt:7
Finding

Persistent Psychological Profile Poisoning Through Untrusted Prompt Interpolation

Content
View full analysis
s.timestamp.startsWith(today) ); if (todayScores.length === 0) { return { date: today, hasData: false }; } const hourlyData = Array(24).fill(null).map(() => []); todayScores.forEach(score => { const hour = new Date(score.timestamp).getHours(); if (hour >= 0 && hour < 24) { hourlyData[hour].push({ ...score, hour }); } }); ``` ### Technical Analysis The analysis templates interpolate conversation content and context directly in ...[truncated 3106 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:59
Finding

Filesystem Path Traversal Through Unvalidated Context User Identifier

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (40)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 5)May include surrounding context.

text
node_modules/

# Environment variables
.env

# Log files
logs/

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly describes persistent storage of highly sensitive psychological profiling data, emotional history, intimacy data, triggers, and raw user content under a user directory, but provides no warning, consent model, retention policy, minimization guidance, or protection expectations. In the context of a psychology-scoring skill, this is especially dangerous because the stored data is unusually intimate and could enable surveillance, manipulation, stigma, or severe privacy harm if accessed by other local processes, backups, logs, or operators.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is intentionally designed to persist detailed disclosures, inferred personality traits, attachment style, intimacy progression, and follow-up memory across sessions. In the context of a psychological scoring engine, that creates a durable behavioral dossier that can be resurfaced or repurposed far beyond the user's immediate request.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill persistently writes psychological, attachment, coping, and behavioral inference data to disk without any visible user disclosure or consent flow in this file. These are highly sensitive mental-health-adjacent attributes, and long-term local storage increases exposure in case of compromise or unauthorized reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill writes multiple sensitive artifacts, including interaction preferences, emotion triggers, intimacy state, and personality inferences, to disk with no visible disclosure or privacy controls. The breadth of persisted sensitive data materially raises privacy harm and secondary-use risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The follow-up memory mechanism stores excerpts of emotionally sensitive content, emotion labels, intensity, timing, and suggested approaches for later resurfacing. Retaining and replaying vulnerable disclosures creates substantial privacy and manipulation risk, especially when users may not expect enduring memory of distress-related content.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest explicitly supports saving psychologically sensitive user profiling data, including personality, emotion, coping, and relationship-related assessments, yet provides no user-facing disclosure about retention, consent, access, or privacy protections. In this context, the skill is designed to infer and persist intimate mental-state data, which increases the risk of non-consensual profiling, privacy harm, and downstream misuse if users are unaware that the data is stored.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest includes collection and storage of daily emotional rhythm analysis, which is highly sensitive behavioral and mental-health-adjacent data, but does not warn users that this information may be persisted or used for ongoing profiling. Because the skill context centers on long-term emotional understanding ('越用越懂你'), the absence of transparency makes the capability more dangerous by enabling continuous psychological tracking without clear informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README presents the skill entirely in Chinese and gives no indication that users may choose another language or locale. Under SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation when no choice or justification is documented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly documents persistent storage of highly sensitive psychological profiling data, including raw scores, inferred emotional state, confidence assessments, and potentially raw user input, in a local directory without any mention of consent, minimization, retention limits, encryption, or access controls. Because this data concerns mental state and behavioral profiling, compromise or misuse could cause serious privacy harm, profiling abuse, or secondary exposure of intimate user information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly promotes persistent psychological profiling, emotional tracking, and continuous learning from conversations, but does not present a prominent informed-consent warning proportional to the sensitivity of the data. Because the data concerns inferred mental state and personality traits, users may not realize the scope of collection, retention, and downstream use, creating privacy and safety risks even if storage is local.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · USAGE.md (reported line 101)May include surrounding context.

bash
# 创建偏好文件
mkdir -p ~/.openclaw/workspace/memory

创建 ~/.openclaw/workspace/memory/interaction-preferences.json:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples instruct callers to save raw user message content together with psychological scores and evidence, creating a durable record of both source conversations and sensitive inferences. This is dangerous because it increases exposure in the event of local compromise, accidental sharing, backup leakage, or unauthorized access, and users are not clearly warned that their content may be retained verbatim.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions normalize persistent collection of full user input plus inferred psychological data in a scoring history. In the context of a psychology-oriented skill, this materially increases sensitivity because the stored corpus can reveal emotions, vulnerabilities, routines, and personality traits over time, enabling privacy harm or manipulation if accessed by others.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow directs analysis of every user input and continuous profile building across conversations, establishing ongoing surveillance-like behavioral inference. In this skill context, that is more dangerous than ordinary session memory because it creates long-term psychological models that can influence future responses and expose highly sensitive traits if compromised or misused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The storage section enumerates multiple files containing intimate psychological, emotional, and behavioral records, but provides no strong caution about file permissions, access control, encryption, backup risk, or secure deletion. Listing these stores in documentation without companion safeguards normalizes retention of highly sensitive data in plain local files, which can be exposed to other local users, malware, or support bundles.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation describes long-term per-user storage of psychological state, intimacy, triggers, emotional rhythm, and confidence reports, creating a concentrated dossier of sensitive mental-health-adjacent data. Such records are especially risky because they support intimate inference and longitudinal tracking, amplifying harm from local compromise, insider misuse, or accidental exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains user-facing labels, recommendations, and interaction guidance in Chinese throughout the implementation, indicating the skill effectively forces a single language/locale. The code does not expose any opt-in language selection or clearly justify that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill reads workspace files such as IDENTITY.md, USER.md, and interaction-preferences.json that are outside the immediate scoring input, then uses them to infer personality and intimacy state. In a psychology-oriented skill, this expands collection from volunteered conversation data to unrelated profile artifacts, creating covert cross-context profiling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill accesses workspace profile and preference files without any user-facing warning that these files will be read. Even if the files are local, silently ingesting personal profile content violates least surprise and can disclose unrelated personal information to the skill's profiling pipeline.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code comments claim intimacy only affects response style, but the implementation explicitly collects and persists personality data regardless of intimacy. This mismatch is dangerous because reviewers or deployers may underestimate the breadth of sensitive psychological profiling being performed.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code models escalating intimacy stages and uses them to justify more proactive, deeper, and more predictive behavior over time. In a mental-health-style interaction context, systematic trust-building tied to increased extraction or influence can manipulate vulnerable users and normalize progressively intrusive engagement.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The confidence-report recommendations explicitly advise steering conversation to gather more dimension-specific user data when confidence is low. In this skill's context, that operationalizes profiling expansion and can pressure users into disclosing more sensitive information than necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest presents the skill description entirely in Chinese and does not indicate that language is configurable or limited to a specific Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s natural-language instructions are entirely in Chinese and require the model to follow them strictly, but there is no user opt-in or documented reason that this skill must operate only in Chinese. This creates a locale/language policy issue because the skill appears to force a specific language context rather than offering a choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.