SecureSkill scanned self-improvement by pskoett on 2026-04-21 using scanner version 0.1.0. Verdict: CAUTION. Risk score: 5/10. 7 findings across 10 analysis layers. Platform: OpenClaw.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is debb84b8-70aa-48c9-a365-296ba4a49aa8.
This skill is mainly a structured note-taking and memory workflow for AI agents. It does not appear to steal data or contact outside servers, but it does use powerful features: startup hooks, prompt-context injection, and instructions to write lasting guidance into files that affect future sessions. That makes it more sensitive than a simple documentation-only skill. If you want this kind of persistent self-improvement behavior, it looks reasonably transparent, but you should install it knowingly rather than casually.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Writes to
Runs
Permissions Requested
Network Calls
File Writes
Code Execution
7 behaviors were flagged for review. Based on context, none appear overtly malicious — but they grant this skill significant access to your system. This includes writing to agent configuration files (CLAUDE.md, AGENTS.md, SOUL.md, TOOLS.md), permanently changing your agent's behavior across all future sessions. While this appears to be within scope of the skill's purpose, review the behaviors below before installing.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
The package does not contain outbound network code, hidden downloads, or credential exfiltration paths, which keeps it well below a block decision.
Risk rises because it uses privileged mechanisms: lifecycle hooks, bootstrap context injection, and instructions to write persistent agent guidance into workspace files.
The shell scripts are comparatively low risk; two only print reminders, and the extraction helper includes path validation before writing files.
Inter-session features are documented but not automated. That is a moderate concern because transcript-sharing tools can expose sensitive context if used carelessly.
Overall this looks like a transparent productivity/knowledge-management skill, but one that should be installed only if you are comfortable with persistent prompt influence and hook-based automation.
What to do
Verify all outbound network endpoints match the skill's stated purpose
Audit all imported dependencies for known vulnerabilities before installing
This skill modifies agent config files that persist across all future sessions
Scan ID
debb84b8
Scanner
v0.1.0
Date
Apr 21, 2026
Risk Score
5
Skill Version
3.0.16
Skill License
unspecified