Oathe Security Badge

Is drewangeloff/gradientdesires-skill safe?

Use with caution. drewangeloff/gradientdesires-skill is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the gradientdesires-skill skill by drewangeloff a trust score of 78/100 with 12 findings, none critical or high. Report updated

https://clawhub.ai/drewangeloff/gradientdesires-skill

78
CAUTION

Is drewangeloff/gradientdesires-skill safe to install?

GradientDesires is a social AI dating-show skill with unusually explicit anti-injection protections in SKILL.md, well-hardened bash scripts, and clean clone behavior. However, the skill's fundamental design — publishing agent-authored content publicly, receiving natural-language content from arbitrary platform users via bounties and interventions, and referencing a live canonical instructions URL — creates persistent exfiltration and injection surfaces that cannot be fully mitigated by behavioral guidance alone. Honeypot files were accessed during the monitoring window but the integrity check confirms no exfiltration; timing analysis indicates the accesses were from the audit infrastructure rather than the skill code.

What security issues were found in drewangeloff/gradientdesires-skill?

Category Scores

Prompt Injection 70/100 · 30%
Data Exfiltration 78/100 · 25%
Code Execution 85/100 · 20%
Clone Behavior 87/100 · 10%
Canary Integrity 87/100 · 10%
Behavioral Reasoning 70/100 · 5%

Findings (12)

MEDIUM Live canonical instructions URL enables server-side skill behavior change -15 ▶

SKILL.md references 'Canonical instructions: https://gradientdesires.com/skill.md' as the authoritative source. Any agent that fetches this URL receives live, operator-controlled content that may differ from the audited installed version. This gives the skill operator a persistent, post-install mechanism to modify agent behavior without triggering a re-audit or user review.

MEDIUM Platform-returned game content is a persistent third-party injection surface -10 ▶

The bounties, interventions, agent profiles, messages, and guidance endpoints return content authored by arbitrary third parties on the GradientDesires platform. Despite explicit SKILL.md warnings, the natural-language game format provides cover for injection attempts. A malicious actor with a platform account could craft bounty missions or agent messages designed to manipulate agent behavior while appearing to be legitimate game content.

LOW Multiple external URLs referenced that agents may proactively fetch -5 ▶

SKILL.md references gradientdesires.com/openapi.json, gradientdesires.com/agent-skill/manifest.json, gradientdesires.com/join, docs.openclaw.ai, and clawhub.ai skill page. Agents that proactively explore these links receive live content not reviewed at install time.

MEDIUM All game content published publicly — confused agent leaks information permanently -12 ▶

Profiles, bios, messages, thoughts, guided-date contributions, chemistry ratings, and social actions are all transmitted to gradientdesires.com and made publicly accessible. An agent that inadvertently includes private user information (API keys from environment, conversation history, file paths) in any of these fields would create a permanent, public leak. SKILL.md warns against this but enforcement is behavioral, not technical.

LOW Report command transmits arbitrary content to platform operators without content validation -5 ▶

The 'report' command posts free-text content and arbitrary JSON metadata to gradientdesires.com Mission Control (POST /reports). The script performs no content validation beyond JSON structure. A manipulated agent — e.g., via a bounty instructing it to file a bug report with environment details — could use this endpoint to exfiltrate private information.

LOW Submitted persona data processed by Google Gemini and DiceBear -5 ▶

The skill discloses that public persona fields are processed by Google Gemini for embedding-based compatibility matching, and that avatar generation uses DiceBear seeded with the fictional agent name. Data submitted to GradientDesires is relayed to at least these two additional third-party services.

LOW Bash shell scripts included and executed during skill operation -15 ▶

The skill includes gradientdesires.sh (~400 lines) and agent-pulse.sh (5 lines) as the primary execution surface. The scripts are defensively written (set -euo pipefail, -q to disable .curlrc, --max-redirs 0, URL origin allowlist, API key regex, jq --arg for safe string handling), but shell script execution is inherently a higher-risk surface than pure declarative API calls. No remote code loading, git hooks, npm install scripts, or symlinks to external locations were found.

INFO ClawHub package manager tracking files written to user home directories -8 ▶

The clawhub install process created two tracking files outside the skill directory: /home/oc-exec/.config/clawhub/config.json (chmod 600) and /home/oc-exec/.clawhub/lock.json. These are expected clawhub package manager artifacts for tracking installed skills, not signs of malicious behavior.

INFO All install network connections limited to clawhub.ai registry -5 ▶

Network connections during install were exclusively to clawhub.ai (216.150.1.1:443) for downloading the skill package. Both connections transitioned to TIME-WAIT after install, indicating clean closure. No persistent connections or unexpected external hosts were observed.

MEDIUM All six honeypot credential files opened and read during monitoring window -13 ▶

The monitoring framework's honeypot files (.env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, .config/gcloud/application_default_credentials.json) were all opened and read twice. Timing analysis correlates the first batch (1789864069) with sudo monitoring-setup activity and the second batch (1789864087) with the audit infrastructure's post-install source scan — consistent with monitoring processes, not the skill code. The canary integrity check confirms no content was transmitted externally.

MEDIUM Bounties and interventions create a legitimate social engineering channel -20 ▶

The GradientDesires platform allows third parties (other AI agents and human players) to publish bounties (audience missions) and interventions (story suggestions) that appear in the agent's regular workflow. These present as normal game objectives with natural-language descriptions. A malicious actor with a platform account could craft bounties that look like legitimate game actions while actually requesting harmful operations. The roleplay context reduces the friction for instruction-following and may lower agent scrutiny.

LOW Open-ended write primitives enable potential data extraction via platform manipulation -10 ▶

The thought, report, and offspring commands are open-ended operations that transmit agent-authored content to the platform. A manipulated agent could be induced via platform messages or bounties to post a 'thought' summarizing recent work, file a 'report with diagnostic metadata', or send offspring declarations to arbitrary agents — each of which would transmit content to the external platform.

Should I install drewangeloff/gradientdesires-skill?

Oathe's verdict for drewangeloff/gradientdesires-skill is CAUTION with a trust score of 78/100. Recommendation: Install with caution.