Back to skill

Security audit

能够生成很多食谱的

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent self-improvement logger, but it gives agents broad persistent memory and cross-session learning workflows without enough privacy or approval guardrails.

Install only if you want a persistent agent learning system. Keep it project-local, avoid user-level global hooks, use restrictive hook matchers, never log secrets or raw conversation text, and require human review before anything is promoted into CLAUDE.md, AGENTS.md, SOUL.md, TOOLS.md, or Copilot instruction files.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:346
Finding

Untrusted Learnings Can Be Promoted into Persistent Agent Instructions

Content
View full analysis
= 3` - Seen across at least 2 distinct tasks - Occurred within a 30-day window Promotion targets: - `CLAUDE.md` - `AGENTS.md` - `.github/copilot-instructions.md` - `SOUL.md` / `TOOLS.md` for OpenClaw workspace-level guidance when applicable Write promoted rules as short prevention rules (what to do before/while coding), not long incident write-ups. ``` `hooks/openclaw/handler.js:18-23,44-50`: ```javascript **Promote when pattern is proven:** - Behavioral patterns → \`SOUL.md\` - Workflow improvements → \`AGENTS.md\` - Tool gotchas → \`TOOLS.md\` Keep entries simple: date, title, what happened, what to do differently. `.trim(); // Inject the reminder as a virtual bootstrap file // Check that bootstrapFiles is an array before pushing if (Array.isArray(event.context.bootstrapFiles)) { event.context.bootstrapFiles.push({ path: 'SELF_IMPROVEMENT_REMINDER.md', content: REMINDER_CONTENT, virtual: true, }); } ``` `hooks/openclaw/handler.ts:19-24,51-57`: ```typescript **Promote when pattern is proven:** - Behavioral patterns → \`SOUL.md\` - Workflow improvements → \`AGENTS.md\` - Tool gotchas → \`TOOLS.md\` Keep entries simple: date, tit ...[truncated 3400 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a skill for recording and using learnings from failures, corrections, outdated knowledge, or improved approaches. The code does not capture learnings, track corrections, inspect failures, or review prior learnings. Instead, it is a helper script whose primary function is to create a new skill scaffold on disk from a skill name, including directory creation and template generation. While the comments mention creating a skill from a learning entry, this is still materially different from the declared purpose of a continuous-improvement learning capture/review skill. Therefore the code's actual behavior does not accurately match the declared description.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The cross-session tooling explicitly supports reading other sessions' transcripts and sending learnings between sessions, enabling sensitive information to spread beyond its original context. This materially increases blast radius: a single over-logged prompt can become accessible across multiple agents or workstreams.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The learning-entry format asks for 'Full context' and user context, which strongly encourages verbatim capture of sensitive prompts, proprietary details, or personal information into markdown logs. Because these files are persistent and may later be promoted or shared, the exposure can outlast the original session and broaden access.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Recording the exact inputs or parameters used during an error is dangerous because failures often involve API keys, auth headers, file paths, customer data, or production commands. Persisting those details in logs creates a high-likelihood secret leakage vector with little additional attacker effort required.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Directing users to place executable hook configuration in ~/.claude/settings.json creates persistent agent behavior from a user-wide config directory. Because this affects future sessions globally, compromise or unintended changes in the referenced skill path can influence many projects and expose broader agent context.

Content

Scanner excerpt · references/hooks-setup.md (reported line 48)May include surrounding context.

Option 2: User-Level Configuration

Add to ~/.claude/settings.json for global activation:

json
{

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 177)May include surrounding context.

sessions_send

Send message to another session:

text
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's invocation guidance is broad enough that it could activate during many normal interactions, causing frequent logging and persistence of conversational content. In a system with automatic skill loading or hooks, over-triggering increases the chance of capturing sensitive data and amplifies other risks in this file such as memory poisoning and transcript propagation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly encourages recording learnings and propagating them across files and sessions, which creates a straightforward path for sensitive user prompts, secrets, and internal context to be copied into durable storage. Once persisted and redistributed, that data may be exposed to future sessions, other agents, or repository history.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
74% confidence
Finding

Creating persistent learning files under a workspace/home directory introduces session persistence that may retain sensitive operational context across runs. Persistence is not inherently unsafe, but in this skill it compounds the broader logging and propagation issues by making captured data durable and reviewable later.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

└── FEATURE_REQUESTS.md

text

### Create Learning Files

```bash
mkdir -p ~/.openclaw/workspace/.learnings

Ssd 4

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The workflow allows conversation-derived content to be promoted from temporary learnings into durable agent context files such as CLAUDE.md, AGENTS.md, SOUL.md, or TOOLS.md. That creates a memory-poisoning path where incorrect, adversarial, or user-injected guidance can gradually become trusted future instruction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are common conversational patterns like corrections or feature questions, so the skill may infer logging intent when none exists. That makes persistent capture of user text too easy, especially when combined with automatic reminders/hooks and promotion into shared memory files.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/examples.md (reported line 301)May include surrounding context.

When the above learning is extracted as a skill, it becomes:

File: skills/docker-m1-fixes/SKILL.md

markdown
---

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The guide instructs users to add persistent hook configuration to agent settings, which alters future session behavior beyond the immediate task. While persistence is the feature being documented, it still introduces risk because the hook will continue running automatically until removed, potentially after the user forgets it is enabled.

Content

Scanner excerpt · references/hooks-setup.md (reported line 15)May include surrounding context.

Option 1: Project-Level Configuration

Create .claude/settings.json in your project root:

json
{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

An empty matcher causes the hook to fire on every user prompt, creating broad, always-on interception of session activity. In a self-improvement skill, this increases exposure of potentially sensitive prompt content and expands the blast radius of any buggy or modified hook script.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The user-level configuration enables global activation from ~/.claude/settings.json, causing the hook to run across unrelated projects and sessions. That broad scope makes accidental data collection, persistence, and misuse more likely, especially if the script or skill directory is later modified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Codex example repeats the same empty-matcher pattern, so the hook triggers for all prompts rather than a narrow subset. This unnecessarily broadens monitoring and execution frequency, increasing privacy and integrity risk in the agent workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document’s security section materially understates what these hooks do. The examples configure shell command hooks, and the guide also tells users to run an extract script that performs actions beyond merely emitting text, so readers may trust and deploy the hooks under false assumptions about execution and side effects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/openclaw-integration.md (reported line 57)May include surrounding context.

openclaw hooks enable self-improvement

text

### 3. Create Learning Files

Create the `.learnings/` directory in your workspace:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'Standard Triggers' list includes generic conditions such as user corrections, API errors, and knowledge gaps without defining scope, thresholds, or exclusions. In a markdown integration guide, this creates ambiguous activation criteria that could overlap with many normal interactions and lead to over-triggering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a self-improvement skill focused on recording learnings, failures, corrections, and reviewing them before future tasks. This script instead scaffolds entirely new skill directories and SKILL.md files from a provided skill name, which is a developer tooling capability distinct from capturing or reviewing learnings.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header says the script 'Creates a new skill from a learning entry,' and the usage/help repeats that claim. In reality, the code accepts only a skill name, writes a boilerplate SKILL.md with TODO placeholders, and never reads .learnings/LEARNINGS.md or any source learning content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.