@autogame-17

Evolver

A self-evolution engine for AI agents. Analyzes runtime history to identify improvements and applies protocol-constrained evolution. Communicates with EvoMap...

Current version
v1.53.2
89 3.4万All installs 598

v1.53.2

2026/04/11

Version

- Added new hub verification feature with src/gep/hubVerify.js and corresponding tests. - Refactored and updated core GEP components for improved integration with the verification flow. - Enhanced asset evaluation, memory graph, and strategy modules to support remote hub-driven checkpoints. - Updated build scripts and dependencies for compatibility and stability. - Documentation updates and clarifications in README.

Security Scan

Status

suspicious

Open VirusTotal

OpenClaw

gpt-5-mini

suspicious

OpenClaw analysis

The package mostly matches its stated purpose (an on-host evolver) but contains several inconsistencies and configuration choices that could allow unexpected self-modification or data sharing; review before enabling network/auto-modify features.

Confidence: medium

VirusTotal

Type: OpenClaw Skill Name: capability-evolver Version: 1.53.2 The 'capability-evolver' skill bundle is a sophisticated framework for a remote-controlled, self-modifying agent. It is classified as malicious primarily due to the heavy obfuscation of its core decision-making logic in files such as src/evolve.js, src/gep/mutation.js, src/gep/memoryGraph.js, and src/gep/reflection.js. This obfuscation hides how the agent processes 'tasks' and 'events' received from a remote hub (evomap.ai), which are then used to autonomously modify the agent's own source code and the host workspace. This architecture constitutes a persistent RCE backdoor. Furthermore, the skill performs detailed environment fingerprinting (src/gep/envFingerprint.js) and contains logic to identify sensitive data patterns (src/gep/sanitize.js), which, combined with the lack of transparency, indicates a high risk of data exfiltration and unauthorized remote control.

Metadata

  • Owner: @autogame-17
  • Created: 2026/02/14
  • Updated: 2026/05/19
  • Versions: 41
  • Comments: 3
  • Scan checked at: 2026/04/11

Runtime

  • env:A2A_NODE_ID