ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      ramsbaby

      Safety Report

      Self-Evolving Agent ๐Ÿง 

      @ramsbaby

      AI ๋น„์„œ๊ฐ€ ์ž๊ธฐ ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•ด์„œ AGENTS.md ๊ฐœ์„ ์•ˆ์„ ์ œ์•ˆํ•˜๋Š” ์ž๋™ํ™”. v5.0: ์‹œ๋งจํ‹ฑ ์ž„๋ฒ ๋”ฉ(Ollama nomic-embed-text, FP ~8%), ์‹ค์‹œ๊ฐ„ ์ŠคํŠธ๋ฆฌ๋ฐ ๋ชจ๋‹ˆํ„ฐ(<30์ดˆ ์•Œ๋ฆผ), ํ”Œ๋ฆฟ ๋ถ„์„(๋‹ค์ค‘ ์ธ์Šคํ„ด์Šค). v4.3: ๋Œ€ํ™”ํ˜• ์Šน์ธ, ๋ฉ€ํ‹ฐํฌ๋งท ๋ฆฌํฌํŠธ, Gi...

      21Downloads
      2Installs
      0Stars
      1Versions

      Security Analysis

      medium confidence
      Suspicious0.16 risk

      The skillโ€™s purpose is coherent, but it reads highly sensitive local agent history and its local-only/privacy claims conflict with documented optional external API and delivery features.

      May 10, 202696 files5 concerns
      Purpose & Capabilitynote

      The core purposeโ€”analyzing OpenClaw logs and proposing AGENTS.md improvementsโ€”is coherent and repeatedly described as human-reviewed, but it necessarily has high-impact visibility into agent behavior and future-agent rules.

      Instruction Scopenote

      The artifacts state that AGENTS.md changes require explicit approval, but the skill is designed to generate rule changes that can affect future agent behavior, so proposals should be reviewed carefully.

      Install Mechanismnote

      There is no platform install spec, but _meta.json documents user-run installation steps that clone an unpinned GitHub repository, install Ollama, start a background service, and register a cron job.

      Credentialsconcern

      The skillโ€™s broad reads of session transcripts, MEMORY.md, logs, and multi-agent fleet data are purpose-aligned, but the privacy/network documentation is inconsistent about what may leave the machine through LLM APIs or delivery channels.

      Persistence & Privilegenote

      Weekly cron scheduling and a real-time streaming monitor are disclosed and aligned with the skillโ€™s purpose, but they create persistent automation the user should intentionally enable and know how to remove.

      Guidance

      Install only if you are comfortable with a local automation reading OpenClaw session history, memory, logs, and fleet data. If you want local-only operation, use Ollama or provider "none", disable external delivery/webhooks, and verify the cron/monitor settings. Read SECURITY.md critically because some local-only and network-access claims conflict with the documented optional integrations.

      Latest Release

      v5.0.0

      6-stage pipeline: semantic embeddings (Ollama), streaming monitor, fleet analysis. 141 tests. $0/week. Human approval gate.

      More by @ramsbaby

      OpenClaw Self-Healing System

      2 stars

      MemoryBox

      @Ramsbaby ยท 0 stars

      self-improving-agent

      @pskoett ยท 1,456 stars

      Gog

      @steipete ยท 672 stars

      Tavily Web Search

      @arun-8687 ยท 620 stars

      Find Skills

      @JimLiuxinghai ยท 529 stars

      Published by @ramsbaby on ClawHub

      Zappushยฉ 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]