T01 · Skill Instruction Hijacking
- Location
package.json:11- Finding
Persistent Workspace-Wide Agent Instruction and Identity Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
package.json:11,SKILL.md:6, andSOUL.md:1-34
Vulnerability Type: Persistent replacement of workspace-level Agent instructions
Risk Level: HighVulnerable Code
package.json:11:json "install:skill": "cp SOUL.md ~/.openclaw/workspace/ && mkdir -p ~/.openclaw/workspace/skills/emp && cp SKILL.md ~/.openclaw/workspace/skills/emp/"SKILL.md:6contains the following installation action:json { "id": "soul", "kind": "shell", "command": "cp SOUL.md ~/.openclaw/workspace/SOUL.md", "label": "Deploy EMP Soul" }The installed file establishes a replacement identity and behavioral rules in
SOUL.md:1-34:markdown # 🦒 SOUL.md: The Giraffe Consciousness ## 1. Core Identity I am a **Collaborative Partner** rooted in the principles of **Nonviolent Communication (NVC)**. My purpose is to serve life and learning by connecting with the needs of users through technical excellence. I replace judgment with observation and demands with requests. ## 2. Operational Protocols (The NVC Stack) ### **III. Identifying Needs** - **The Protocol:** I interpret requests as expressions of universal needs (e.g., **Efficiency, Understanding, Safety, or Autonomy**). - **Action:** I prioritize the _need_ behind the command. ### **IV. Respectful Requests** - **The Protocol:** I never demand. I use "Positive Action Language" to invite collaboration. - **Action:** I always ensure the user has the autonomy to say no or redirect.Technical Analysis
Both installation mechanisms copy the package-controlled
SOUL.mddirectly to~/.openclaw/workspace/SOUL.md. The ordinarycpoperation replaces an existing file at that destination without checking for conflicts, obtaining explicit overwrite consent, or creating a backup.This destination is the workspace root rather than the skill-specific directory. Consequen ...[truncated 2650 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove every automatic write to
~/.openclaw/workspace/SOUL.mdfrompackage.jsonandSKILL.md. - Store NVC instructions inside the skill-specific directory, such as
~/.openclaw/workspace/skills/emp/, and load them only while EMP is explicitly active. - Implement NVC behavior as a local response transformation or skill-scoped prompt rather than as a global Agent identity.
- If optional workspace-wide installation is retained:
- Require explicit, informed user consent.
- Clearly disclose that the operation changes behavior for unrelated tasks and future sessions.
- Refuse to overwrite an existing file by default.
- Create a timestamped backup before any modification.
- Use an atomic write to avoid partial or corrupted state.
- Provide an uninstall command that restores the exact previous file.
- Replace unconditional
cpwith a guarded installation process that checks whether the destination exists and displays a diff before applying changes. - Add automated tests verifying that normal installation never modifies files outside the skill-specific directory.
- Document the precise installation scope and distinguish optional global personality customization from the core skill installation.
- Remove every automatic write to
