Back to skill

Security audit

Auto Memory

Security checks for vulnerabilities and agentic risk

Overview

The skill generally matches its memory-storage purpose, but it needs review because it can permanently publish data, persist local API credentials, and restore unverified public memory chains into agent state.

Review before installing. Only upload data you are willing to make permanent and publicly retrievable by CID, avoid secrets or personal data, prefer setting the API key through a safer secret mechanism, and do not restore or continue a memory chain from a CID unless you trust its source. Avoid the optional npx Auto-Respawn command unless the package version and target script are pinned and audited.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/automemory-recall-chain.sh:57
Finding

Untrusted public memory chains can poison persistent agent context

Content
View full analysis
&2 exit 1 fi ``` Content is then retrieved from public storage and accepted when it is valid JSON: ```bash # Download via authenticated API (handles decompression server-side). EXPERIENCE=$(curl -sS --fail \ "$AD_DOWNLOAD_URL/downloads/$CID" \ -H "Authorization: Bearer $AUTO_DRIVE_API_KEY" \ -H "X-Auth-Provider: apikey" 2>/dev/null \ || true) # Fall back to public gateway if the API fails. # Memories are uploaded with --compress (ZLIB), and the gateway returns raw bytes, # so we must decompress client-side. Pipe curl directly into the decompressor to # avoid bash variables stripping null bytes from the binary stream. if [[ -z "$EXPERIENCE" ]] || ! echo "$EXPERIENCE" | jq empty 2>/dev/null; then GATEWAY_URL="https://gateway.autonomys.xyz/file/$CID" # Try as JSON first (uncompressed files are safe in bash variables) EXPERIENCE=$(curl -sS --fail "$GATEWAY_URL" 2>/dev/null || true) if [[ -n "$EXPERIENCE" ]] && echo "$EXPERIENCE" | jq empty 2>/dev/null; then echo "[$COUNT] Fetched $CID via gateway" >&2 else # ZLIB compressed — pipe curl directly into decompressor (no intermediate variable) EXPERIENCE="" if command -v python3 &>/dev/null; then EXPERIENCE=$(curl -sS --fail "$GATEWAY_URL" 2>/dev/null \ | python3 -c "import sys,zlib;sys.stdout.buffer. ...[truncated 4805 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-auto-memory.sh:43
Finding

API keys are exposed through visible prompts and command-line arguments

Content
View full analysis
&2 exit 1 fi ``` ### Technical Analysis Bash `read` echoes user input unless the `-s` option is used. The API key is therefore displayed as it is pasted into the terminal. It may be exposed to nearby observers, terminal recording software, shared support sessions, or captured terminal output. Accepting the key as `$1` creates a second disclosure channel. Users commonly invoke such a command as: ```bash scripts/update-api-key.sh actual-secret-key ``` The secret may then remain in shell history. Depending on the operating system and timing, process command-line inspection may also reveal it to other local processes or users. The later storage implementation applies restrictive permissions (`700` to the configuration directory and `600` to credential files), which is appropriate, but those controls do not protect the key during entry or command invocation. ### Attack Path #### Visible prompt path 1. The user runs the setup or update script in an observed or recorded terminal. 2. The user pastes the API key. 3. Because `read` lacks `-s`, the key is rendered visibly. 4. A local observer, recording system, screenshot, or support log captures the key. 5. The captured k ...[truncated 973 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:232
Finding

Optional integration executes an unpinned package through npx

Content
View full analysis
--cid ``` ``` ### Technical Analysis The instruction invokes `tsx` through `npx` without an exact version, integrity value, lockfile, or requirement that a previously audited local installation be used. When the package is unavailable locally, `npx` may retrieve executable package content from the configured npm registry at invocation time. This makes the effective code dependent on remote package resolution after the Skill has been reviewed. Package compromise, registry account takeover, malicious registry configuration, or an unexpected future release could result in execution of code that was not part of this audit. The referenced `auto-respawn.ts` file is not included in the audited project, so its behavior and wallet handling cannot be verified from this artifact. The command is optional and documented rather than automatically run by the included scripts, which limits immediate exposure but does not eliminate the supply-chain risk for users who follow the instruction. ### Attack Path 1. A user follows the documented Auto-Respawn integration instructions. 2. The environment does not already contain a pinned local `tsx` executable. 3. `npx` resolves and downloads a package from the configured registry. 4. A compromised, substituted, or unexpectedly changed package executes with the user's local privileges. 5. The process runs in the context of the workspace and the wallet-oriented ...[truncated 702 chars]
Remediation
View remediation
--cid ``` 4. Include `auto-respawn.ts` in the audited distribution, or reference a specific immutable commit and provide integrity verification. 5. Audit package lifecycle scripts and disable unnecessary lifecycle execution during installation. 6. Document the wallet permissions and files accessed by the integration. 7. Require explicit user confirmation before executing wallet-related integration commands. 8. Do not run the command with elevated privileges. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on durable agent-memory storage and recovery on the Autonomys Network. However, this code chunk does not save memories, upload data, retrieve memory history, or reconstruct state from a CID. Its main behavior is administrative setup: checking for required tools, validating CID format with a regex, verifying an API key via the Auto Drive accounts endpoint, and writing that key into local OpenClaw config files. While these helpers may support a larger memory feature, this chunk’s actual purpose is credential/configuration management, which is materially different from the declared end-user functionality. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises a high-level memory persistence and recovery capability: saving agent decisions/identity/context as a durable chain and reconstructing history from a CID. This code does not save anything, manage memory chains, or reconstruct history. It only validates a CID and output path, then downloads content from an Auto Drive API or public gateway, optionally with auth headers, and writes the result to stdout or a local file. While downloading a CID could be a supporting part of a larger memory-recovery system, this chunk alone is materially narrower and different in purpose from the declared description, so it is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code only performs authenticated file upload to Auto Drive and outputs a CID. While this may be a building block for storage on the Autonomys ecosystem, it does not implement the core declared behavior of an 'indestructible agent memory' system: there is no memory model, no chaining of records, no persistence semantics beyond generic upload, and no retrieval or reconstruction of history from a CID. The description therefore materially overstates and misrepresents the functionality actually present in this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises durable memory storage and recovery functionality on the Autonomys Network. However, this code chunk does not implement memory saving, loading, chaining, CID-based reconstruction, or agent history recovery. Its primary purpose is environment setup: directing the user to create an API key, opening a browser, reading the key from stdin, verifying it, and saving it to local configuration files. Those are materially different capabilities from the declared memory functionality, so this chunk is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about durable agent-memory storage and recovery on a network. The supplied code chunk does not implement memory persistence, chain storage, history reconstruction, or CID handling. Instead, it is a utility script for updating an Auto Drive API key by accepting user input or environment input, verifying the key, and saving it. Credential management is a materially different primary purpose from the declared memory functionality, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a persistence capability: permanently saving agent memory and reconstructing history from a CID after loss. The supplied code does not implement memory storage or retrieval. Instead, it performs environment and account verification: checks for curl/jq/file, verifies AUTO_DRIVE_API_KEY, validates the key via a helper, and prints upload limits and remaining credits. This is a materially different primary purpose from the declared functionality, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
scripts/automemory-recall-chain.sh [cid] [--limit N] [--output-dir DIR]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
scripts/automemory-recall-chain.sh [cid] [--limit N] [--output-dir DIR]

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The script is designed to persist an API key in predictable local files under ~/.openclaw, creating a credential-at-rest risk if the host is compromised, backups are exposed, or other tooling later reads the file insecurely. Although permissions are tightened, long-term plaintext secret storage materially increases the blast radius compared with using an OS keychain or ephemeral environment injection.

Content

Scanner excerpt · scripts/_lib.sh (reported line 10)May include surrounding context.

sh
AD_BASE_URL="https://mainnet.auto-drive.autonomys.xyz/api"
AD_DOWNLOAD_URL="https://public.auto-drive.autonomys.xyz/api"
AM_OPENCLAW_DIR="${OPENCLAW_DIR:-$HOME/.openclaw}"
AM_ENV_FILE="$AM_OPENCLAW_DIR/.env"
AM_CONFIG_FILE="$AM_OPENCLAW_DIR/openclaw.json"

GREEN='\033[0;32m'

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This section intentionally manages a .env file containing AUTO_DRIVE_API_KEY, which means credentials are being written to a file that may later be sourced by shells or accessed by other software. In the context of an agent skill that preserves long-lived memory state, persistent credential storage is more sensitive because compromise could allow unauthorized API use over time.

Content

Scanner excerpt · scripts/_lib.sh (reported line 128)May include surrounding context.

sh
fi
  echo -e "${GREEN}✓ Saved to $AM_CONFIG_FILE${NC}"

  # --- .env ------------------------------------------------------------------
  # Remove any existing AUTO_DRIVE_API_KEY lines first to prevent duplicates,
  # then append exactly one entry.
  if [[ -f "$AM_ENV_FILE" ]]; then

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The code appends the API key directly into a .env file in plaintext, which is a real credential exposure concern despite the attempt to quote special characters safely. Any local compromise, accidental file disclosure, insecure backup, or downstream process that reads the .env can leak the key and permit unauthorized access to the associated Auto Drive account.

Content

Scanner excerpt · scripts/_lib.sh (reported line 138)May include surrounding context.

sh
sed '/^AUTO_DRIVE_API_KEY=/d' "$AM_ENV_FILE" > "$sedtmp" && mv "$sedtmp" "$AM_ENV_FILE"
  fi
  # Single-quote the value so characters like #, $, and backticks are
  # preserved literally when the .env file is later sourced by bash.
  local safe_key="${key//\'/\'\\\'\'}"
  echo "AUTO_DRIVE_API_KEY='${safe_key}'" >> "$AM_ENV_FILE"
  chmod 600 "$AM_ENV_FILE"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/automemory-recall-chain.sh (reported line 158)May include surrounding context.

sh
if [[ -n "$EXPERIENCE" ]] && echo "$EXPERIENCE" | jq empty 2>/dev/null; then
      echo "[$COUNT] Fetched $CID via gateway" >&2
    else
      # ZLIB compressed — pipe curl directly into decompressor (no intermediate variable)
      EXPERIENCE=""
      if command -v python3 &>/dev/null; then
        EXPERIENCE=$(curl -sS --fail "$GATEWAY_URL" 2>/dev/null \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/automemory-recall-chain.sh (reported line 165)May include surrounding context.

sh
| python3 -c "import sys,zlib;sys.stdout.buffer.write(zlib.decompress(sys.stdin.buffer.read()))" 2>/dev/null || true)
      fi
      if [[ -z "$EXPERIENCE" ]] && command -v perl &>/dev/null; then
        EXPERIENCE=$(curl -sS --fail "$GATEWAY_URL" 2>/dev/null \
          | perl -MCompress::Zlib -e 'undef $/;my $d=uncompress(<STDIN>);print $d if defined $d' 2>/dev/null || true)
      fi
      if [[ -n "$EXPERIENCE" ]]; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill explicitly requests Write capability and describes persisting state locally via environment files, state files, and automatic updates to MEMORY.md. Session persistence is expected for a memory skill, but it still creates security risk because it can modify workspace files and local configuration, potentially persisting sensitive identifiers or altering project state in ways the user does not fully anticipate.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
license: Apache-2.0
description: Indestructible agent memory — permanently stored, never lost. Save decisions, identity, and context as a memory chain on the Autonomys Network. Rebuild your full history from a single CID, even after total state loss.
compatibility: Requires curl, jq, and the file utility, plus outbound HTTPS to the Autonomys Auto Drive API (ai3.storage) and public gateway. Stored data is permanent and public — do not store secrets. Works with OpenClaw and Hermes agents on macOS and Linux.
allowed-tools: Bash(curl:*) Bash(jq:*) Bash(file:*) Read Write
metadata:
  openclaw:
    emoji: "🧬"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger guidance includes broad activation language such as 'Any time the user wants data stored permanently and immutably' and nearby everyday phrases, which can cause an agent to invoke this skill in normal conversation without sufficiently explicit consent. In this context, accidental activation is more dangerous because the skill's core action is irreversible publication of data to a permanent public network.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill instructs users to run npx tsx auto-respawn.ts ... without pinning an exact package version or otherwise constraining what will be executed. Unpinned npx usage can fetch and run unexpected code from the registry or a changed dependency tree, creating a supply-chain execution risk on the local machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation promotes permanent, irreversible storage of agent data and memories but does not warn users about privacy, secrecy, or compliance risks. In the context of an agent memory skill, users may store prompts, personal data, credentials, or sensitive operational context that cannot be deleted once uploaded, making accidental disclosure effectively permanent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explicitly encourages storing arbitrary agent memories, decisions, and even full file snapshots on permanent decentralized storage, but it does not prominently warn that such data may be sensitive, irreversible, and publicly recoverable by anyone with the CID. In this skill context, the risk is heightened because the feature is framed as "indestructible" memory and "resurrection," which can lead operators to persist secrets, identities, or private context that cannot later be deleted.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/_lib.sh (reported line 98)May include surrounding context.

sh
local key="$1"

  mkdir -p "$AM_OPENCLAW_DIR"
  chmod 700 "$AM_OPENCLAW_DIR"

  # Collect temp files for cleanup
  _AM_TMPS=()

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/_lib.sh (reported line 116)May include surrounding context.

sh
jq -n --arg key "$key" \
      '{"skills": {"entries": {"auto-memory": {"enabled": true, "apiKey": $key}}}}' \
      > "$newtmp" && mv "$newtmp" "$AM_CONFIG_FILE"
    chmod 600 "$AM_CONFIG_FILE"
  else
    local jsontmp
    jsontmp=$(mktemp)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/_lib.sh (reported line 124)May include surrounding context.

sh
jq -n --arg key "$key" \
      '{"skills": {"entries": {"auto-memory": {"enabled": true, "apiKey": $key}}}}' \
      > "$newtmp" && mv "$newtmp" "$AM_CONFIG_FILE"
    chmod 600 "$AM_CONFIG_FILE"
  else
    local jsontmp
    jsontmp=$(mktemp)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/_lib.sh (reported line 141)May include surrounding context.

sh
jq -n --arg key "$key" \
      '{"skills": {"entries": {"auto-memory": {"enabled": true, "apiKey": $key}}}}' \
      > "$newtmp" && mv "$newtmp" "$AM_CONFIG_FILE"
    chmod 600 "$AM_CONFIG_FILE"
  else
    local jsontmp
    jsontmp=$(mktemp)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/automemory-recall-chain.sh (reported line 220)May include surrounding context.

sh
jq -n --arg key "$key" \
      '{"skills": {"entries": {"auto-memory": {"enabled": true, "apiKey": $key}}}}' \
      > "$newtmp" && mv "$newtmp" "$AM_CONFIG_FILE"
    chmod 600 "$AM_CONFIG_FILE"
  else
    local jsontmp
    jsontmp=$(mktemp)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/automemory-save-memory.sh (reported line 147)May include surrounding context.

sh
jq -n --arg key "$key" \
      '{"skills": {"entries": {"auto-memory": {"enabled": true, "apiKey": $key}}}}' \
      > "$newtmp" && mv "$newtmp" "$AM_CONFIG_FILE"
    chmod 600 "$AM_CONFIG_FILE"
  else
    local jsontmp
    jsontmp=$(mktemp)

Static analysis

No suspicious patterns detected.