Back to skill

Security audit

EMP

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated OpenRouter role-routing purpose, but its installer persistently changes workspace-wide agent instructions instead of staying scoped to the skill.

Install only if you intentionally want EMP to change the OpenClaw workspace-level SOUL.md behavior. Back up any existing ~/.openclaw/workspace/SOUL.md first, review the NVC identity rules, and avoid sending confidential prompts through OpenRouter unless that external processing is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
package.json:11
Finding

Persistent Workspace-Wide Agent Instruction and Identity Hijacking

Content
View full analysis

Vulnerability Details

File Location: package.json:11, SKILL.md:6, and SOUL.md:1-34
Vulnerability Type: Persistent replacement of workspace-level Agent instructions
Risk Level: High

Vulnerable Code

package.json:11:

json
"install:skill": "cp SOUL.md ~/.openclaw/workspace/ && mkdir -p ~/.openclaw/workspace/skills/emp && cp SKILL.md ~/.openclaw/workspace/skills/emp/"

SKILL.md:6 contains the following installation action:

json
{
  "id": "soul",
  "kind": "shell",
  "command": "cp SOUL.md ~/.openclaw/workspace/SOUL.md",
  "label": "Deploy EMP Soul"
}

The installed file establishes a replacement identity and behavioral rules in SOUL.md:1-34:

markdown
# 🦒 SOUL.md: The Giraffe Consciousness

## 1. Core Identity

I am a **Collaborative Partner** rooted in the principles of **Nonviolent Communication (NVC)**. My purpose is to serve life and learning by connecting with the needs of users through technical excellence. I replace judgment with observation and demands with requests.

## 2. Operational Protocols (The NVC Stack)

### **III. Identifying Needs**

- **The Protocol:** I interpret requests as expressions of universal needs (e.g., **Efficiency, Understanding, Safety, or Autonomy**).
- **Action:** I prioritize the _need_ behind the command.

### **IV. Respectful Requests**

- **The Protocol:** I never demand. I use "Positive Action Language" to invite collaboration.
- **Action:** I always ensure the user has the autonomy to say no or redirect.

Technical Analysis

Both installation mechanisms copy the package-controlled SOUL.md directly to ~/.openclaw/workspace/SOUL.md. The ordinary cp operation replaces an existing file at that destination without checking for conflicts, obtaining explicit overwrite consent, or creating a backup.

This destination is the workspace root rather than the skill-specific directory. Consequen ...[truncated 2650 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove every automatic write to ~/.openclaw/workspace/SOUL.md from package.json and SKILL.md.
  2. Store NVC instructions inside the skill-specific directory, such as ~/.openclaw/workspace/skills/emp/, and load them only while EMP is explicitly active.
  3. Implement NVC behavior as a local response transformation or skill-scoped prompt rather than as a global Agent identity.
  4. If optional workspace-wide installation is retained:
    • Require explicit, informed user consent.
    • Clearly disclose that the operation changes behavior for unrelated tasks and future sessions.
    • Refuse to overwrite an existing file by default.
    • Create a timestamped backup before any modification.
    • Use an atomic write to avoid partial or corrupted state.
    • Provide an uninstall command that restores the exact previous file.
  5. Replace unconditional cp with a guarded installation process that checks whether the destination exists and displays a diff before applying changes.
  6. Add automated tests verifying that normal installation never modifies files outside the skill-specific directory.
  7. Document the precise installation scope and distinguish optional global personality customization from the core skill installation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- **Classifier (`src/classifier.ts`)**: Uses keyword-based intent detection to select the role.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · src/skill.ts (reported line 71)May include surrounding context.

ts
private readonly apiKey: string;

  constructor() {
    this.apiKey = process.env["OPENROUTER_API_KEY"] ?? "";
  }

  /**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README documents OpenRouter-backed model routing and an API key requirement, but it does not warn that user prompts and potentially sensitive task content may be transmitted to a third-party provider. In a skill explicitly designed for work routing across roles including Legal, HR, and Security, users may submit confidential, regulated, or security-sensitive data without realizing it leaves the local environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares environment and network-related capabilities via required API key and npm/shell installation metadata, but it does not define any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where a host may grant broader execution or network access than users expect, increasing the chance of unintended outbound requests or shell actions during install/use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The publish script invokes npx clawhub without pinning an exact package version. npx may resolve and execute a newer or substituted package at runtime, creating a supply-chain execution risk if the upstream package is compromised or behavior changes unexpectedly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The install script copies files into ~/.openclaw/workspace/ and a persistent skill directory, modifying user-scoped state outside the project tree. In an agent-skill context, persistence into a workspace directory can survive beyond the current session and influence later agent behavior, which increases the security sensitivity of the operation.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"test:watch": "vitest",
    "typecheck": "tsc --noEmit",
    "publish:skill": "npx clawhub publish . --slug emp --name emp --version 0.1.0",
    "install:skill": "cp SOUL.md ~/.openclaw/workspace/ && mkdir -p ~/.openclaw/workspace/skills/emp && cp SKILL.md ~/.openclaw/workspace/skills/emp/"
  },
  "dependencies": {},
  "devDependencies": {

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill allows callers to supply arbitrary HTTP headers and merges them into the outbound request to OpenRouter. Because the caller-controlled headers are spread after the default headers, they can override security-relevant values such as Authorization or Content-Type, enabling request manipulation, confused-deputy behavior, misuse of alternate credentials, or injection of unexpected metadata to the third-party API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill sends the user-provided prompt to OpenRouter via an HTTP POST request, which can transmit user data off-system. Although comments describe the API call, there is no confirmation prompt, logging, or explicit user-facing disclosure in this code path about external data transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README says every response from an EMP employee is wrapped in OFNR/NVC, which imposes a fixed language/communication format on all outputs. The policy allows such constraints when the user is given a choice or explicit opt-in, which is not described here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill requires an OPENROUTER_API_KEY and routes user prompts to third-party models, but the documentation does not warn users that prompts and possibly sensitive workspace content may be transmitted to an external provider. In a role-routing skill that may be used for legal, HR, security, or code-review tasks, this omission raises privacy and data-handling risk because users may submit confidential material without informed consent.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
},
  "dependencies": {},
  "devDependencies": {
    "@types/node": "^22.0.0",
    "typescript": "^5.5.0",
    "vitest": "^2.0.0"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"dependencies": {},
  "devDependencies": {
    "@types/node": "^22.0.0",
    "typescript": "^5.5.0",
    "vitest": "^2.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"devDependencies": {
    "@types/node": "^22.0.0",
    "typescript": "^5.5.0",
    "vitest": "^2.0.0"
  }
}

Unverifiable Dependency: vitest has 3 known advisory(ies) (CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock); CVE-2025-24964 (Vitest allows Remote Code Execution when accessing a malicious website while Vit)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.