Back to skill

Security audit

Memory Cache

Security checks for vulnerabilities and agentic risk

Overview

This Redis cache skill is mostly coherent, but its key-scanning command can list Redis keys outside the advertised namespace.

Review before installing if the Redis database is shared or contains sensitive key names. Use a dedicated Redis database or ACL-restricted Redis user limited to mema:* keys, and prefer pinned dependency versions or a lockfile. Do not rely on the scan command's documentation as a namespace guarantee in this version.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/cache_manager.py:130
Finding

Redis Key Enumeration Bypasses the Enforced Namespace

Content
View full analysis
list[str]: if not pattern.startswith(KEY_PREFIX) and "*" not in pattern: pattern = f"{KEY_PREFIX}*" if pattern == "*" else f"{KEY_PREFIX}*{pattern}*" r = _client() try: return list(r.scan_iter(match=pattern, count=count)) except redis.RedisError as e: raise CacheError(str(e)) ``` ### Technical Analysis The function intends to constrain key enumeration to the `mema:` namespace. However, prefix normalization only occurs when the supplied pattern both lacks the `mema:` prefix and contains no `*` wildcard. Consequently, any pattern containing `*` bypasses namespace enforcement. This includes the default pattern `"*"`, as well as attacker-controlled values such as `other:*` or `session:*`. These patterns are passed directly to Redis through `scan_iter(match=pattern)`, allowing the caller to enumerate key names outside the namespace assigned to this Skill. This behavior contradicts the documented requirement to strictly enforce the `mema:` prefix. Although the affected command does not directly retrieve the values of non-`mema:` keys, Redis key names can disclose application structure, tenant identifiers, session identifiers, service names, or other sensitive metadata. Materializing the complete iterator as a list also increases memory-consumption risk when a broad pattern matches a large database. ### Attack Path 1. The attacker or untrusted caller obtains permission to invoke the cache manager against a Redis database shared with other applications. 2. The caller runs one of the following commands: ```bash python3 scripts/cache_manager.py scan '*' ``` or: ```bash python3 scripts/cache_manager.py scan 'other:*' ``` 3. `scan_keys()` detects ...[truncated 1093 chars]
Remediation
View remediation
1000: raise KeyValidationError("Count must be between 1 and 1000") if pattern == "*": pattern = f"{KEY_PREFIX}*" elif not pattern.startswith(KEY_PREFIX): raise KeyValidationError(f"Scan pattern must start with {KEY_PREFIX}") r = _client() try: return r.scan_iter(match=pattern, count=count) except redis.RedisError as e: raise CacheError(str(e)) ``` Additional hardening measures: 1. Reject every caller-supplied scan pattern that does not begin with the literal `mema:` prefix. 2. Convert the default `"*"` pattern explicitly to `mema:*`. 3. Stream results from `scan_iter()` instead of converting the entire iterator to a list. 4. Place this Skill in a dedicated Redis logical database or, preferably, a separate Redis instance. 5. Configure a Redis ACL user restricted to the required `mema:*` key pattern and necessary commands. 6. Add tests covering `"*"`, `other:*`, `*:suffix`, empty patterns, and valid `mema:*` patterns. ]]>

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unbounded and Unverified Dependency Installation

Content
View full analysis
=5.0.0 python-dotenv>=1.0.0 ``` `scripts/cache.sh`: ```bash source "$VENV_DIR/bin/activate" pip install -q --upgrade pip pip install -q -r "$REQ_FILE" ``` The Skill metadata also declares an installation command that uses the same unpinned requirements: ```yaml metadata: {"openclaw":{"requires":{"bins":["python3"],"env":["REDIS_URL"]},"install":[{"id":"pip-dependencies","kind":"exec","command":"pip install -r requirements.txt"}]}} ``` ### Technical Analysis Both dependencies use open-ended minimum-version constraints. No exact versions, upper bounds, lock file, or package hashes are provided. The wrapper additionally upgrades `pip` to whichever release is current at execution time. As a result, two installations performed at different times may execute different package and installer code even when the Skill source remains unchanged. This weakens the value of source review because future transitive dependencies or package releases are not represented by the audited artifact. This configuration does not by itself prove that a current dependency is malicious. The security risk arises if an allowed future release, transitive dependency, package-index response, or installer release is compromised or introduces a vulnerability. ### Attack Path 1. An operator invokes `scripts/cache.sh`, or the Skill installation mechanism runs `pip install -r requirements.txt`. 2. The installer resolves the newest available releases satisfying `redis>=5.0.0` and `python-dotenv>=1.0.0`. 3. Because versions and hashes are not fixed, artifacts that were not part of this audit may be selected. 4. If an allowed package release, transitive dependency, configured package index, or installer ...[truncated 725 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The del_key function performs irreversible deletion of cache entries via r.delete(key) without any confirmation prompt or explicit user-facing warning at the point of execution. Although the CLI subcommand is named del, the code provides no additional disclosure or safeguard for this destructive action.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specification redis>=5.0.0 is unpinned, so installs may resolve to different versions over time, reducing reproducibility and making it harder to ensure vulnerable releases are excluded. In a security-sensitive skill, this increases supply-chain uncertainty and may unintentionally permit installation of a version affected by known advisories.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
redis>=5.0.0
python-dotenv>=1.0.0

Unverifiable Dependency: redis has 4 known advisory(ies) (CVE-2023-28858 (redis-py Race Condition vulnerability); CVE-2023-28859 (redis-py Race Condition due to incomplete fix); CVE-2023-28858 (redis-py before 4.5.3, as used in ChatGPT and other products, leaves a connectio) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

redis has known security advisories, and because the manifest does not pin a version, it is impossible to verify whether deployed environments will receive a fixed or vulnerable release. This elevates risk beyond a generic unpinned dependency because the package has a documented vulnerability history relevant to connection handling and race conditions.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specification python-dotenv>=1.0.0 is unpinned, which allows future installs to pull different releases without review. This weakens build integrity and can expose the skill to dependency regressions or vulnerable versions if a bad release is published or selected.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
redis>=5.0.0
python-dotenv>=1.0.0

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

python-dotenv has known advisories, and the unpinned requirement means the actual installed version cannot be verified as safe. If the skill uses dotenv file writing or parsing features in attacker-influenced paths, vulnerable versions could contribute to file overwrite or unsafe file handling issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code performs network/package installation operations via pip, which can modify the local environment and fetch remote content. Although there is a minimal status message, it does not clearly warn the user that dependencies will be downloaded and installed when the virtual environment is missing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.