Back to skill

Security audit

虾尊记忆自动管理器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed memory automation tool, but it reads conversation transcripts on a schedule and feeds raw transcript text to a tool-enabled agent with broad write authority and weak privacy controls.

Review before installing. Enable this only if you are comfortable with a background cron reading conversation transcripts and storing selected summaries. Configure an explicit transcript path, avoid granting broad exec/read/write where possible, add redaction and review before memory writes, and do not enable Feishu delivery unless you intend memory-derived data to leave the local environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
scripts/memory-scan.py:75
Finding

Untrusted Transcript Content Is Passed to a Tool-Enabled Agent

Content
View full analysis
/dev/null && echo " cron 创 ...[truncated 2435 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/memory-scan.py:24
Finding

Weak Transcript Selection Can Read the Wrong Session

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明的核心承诺是“自动发现重要信息并写入每日 memory”,这是该技能的主要目的。但所给代码仅做增量扫描和展示:它从 transcript 中筛出新消息,支持 user+assistant 双读,维护 last_scan_ts 防止重复扫描,这些与描述部分一致。然而关键能力缺失:没有任何逻辑将提取结果写入 MEMORY_FILE,也没有重要性判断、任务/决策/教训/配置变更提取逻辑。代码只是打印“新消息”和“当前Memory文件”,然后更新 scan-state.json。另一个声明中的组件/行为“每周六记忆合并”也未在此代码中体现。因而描述与实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The description presents the skill as an automatic memory-management feature centered on incremental scanning and two cron jobs (15-minute scan plus weekly merge). However, the supplied code chunk is specifically a setup script, not the scanning logic itself. Its primary behavior is installation/configuration: creating directories, copying files, initializing state, locating a transcript, editing another script, and optionally registering one cron job. Those are materially different from the declared runtime behavior. Most importantly, the description claims two cron components including a weekly merge, but this code only creates the 15-minute scan cron and contains no weekly merge setup. This is a meaningful description-to-behavior mismatch, even though the created cron's intent is broadly aligned with the declared memory scanning purpose.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The script consumes the MEMORY_SCAN_TRANSCRIPT environment variable and also implicitly relies on filesystem environment expansion via os.path.expanduser. If the skill's declared permissions do not cover environment access, this creates an undeclared capability that can surprise operators and weaken security review, especially in an automation context that periodically processes sensitive transcripts.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly promotes automatic scanning of conversation history and writing discovered information into persistent memory, but it does not clearly warn users about privacy implications, consent expectations, retention behavior, or what categories of data may be stored. In this skill context, the feature is specifically designed to inspect transcripts on a schedule, which increases the risk of silently collecting sensitive personal, credential, or business information if users are not clearly informed.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The README instructs users to create persistent state under ~/.openclaw/workspace/memory, establishing ongoing session persistence for scan metadata and likely related memory artifacts. In the context of an automated transcript-scanning skill, persistence increases exposure because sensitive conversation-derived data may remain on disk beyond the original session and can be accessed later if the host or account is compromised.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

md
cp -r scripts/memory-scan.py ~/.openclaw/scripts/

# 初始化 scan-state.json
mkdir -p ~/.openclaw/workspace/memory
echo '{"last_scan_ts": 0}' > ~/.openclaw/workspace/memory/scan-state.json

# 创建 cron(需要手动替换 transcript 路径)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to automatically scan and persist conversation content, including both user and assistant messages, but does not present a clear privacy warning or consent boundary up front. This is dangerous because users may unknowingly have sensitive information copied into long-lived memory files, increasing exposure, retention, and downstream misuse risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

These instructions direct persistent storage of semantically summarized conversation content into memory files based on broad categories such as decisions, lessons, discoveries, and blockers. That is dangerous because it normalizes long-term retention of potentially sensitive user data and assistant-derived conclusions without strong minimization, review, or consent controls.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The cron message operationalizes continuous logging of both user and assistant conversation content into persistent storage using broad semantic criteria. In context, the automation and recurring schedule make this more dangerous because it can silently accumulate sensitive information over time without fresh user awareness, increasing privacy and data leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The weekly merge flow instructs the system to send results to an external Feishu channel without a prominent warning about disclosure of conversation-derived content. This creates a real risk of exfiltrating sensitive summaries, decisions, configuration changes, or user data outside the local environment to a third-party communication system.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The weekly merge expands retention by consolidating daily memories into a longer-lived MEMORY.md and then instructs outward notification via Feishu. This compounds privacy risk by both broadening persistence and enabling external sharing of conversation-derived summaries, which may expose sensitive information beyond the original workspace.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code comments imply transcript input comes from an environment variable, but in practice it silently falls back to scanning local session files under ~/.openclaw/agents/main/sessions/. This discrepancy is dangerous because it broadens data access beyond what an operator may expect, causing unintended collection of potentially sensitive conversation history from the main session.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline documentation understates the script's actual behavior by suggesting only environment-based transcript selection, while the implementation auto-discovers and reads session files. This kind of misleading documentation increases the chance that reviewers and users misunderstand the script's data access scope and approve it without realizing it inspects local conversation logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script reads user and assistant messages from transcripts and prints them for downstream analysis without any user-facing privacy notice or redaction step. In this skill's context, the data being scanned is conversational memory content, which can naturally include credentials, personal data, internal decisions, and other sensitive material, making uncontrolled disclosure especially risky.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script explicitly prints up to 30 recent user and assistant messages in plaintext, including arbitrary user-provided content. Because this skill is designed for periodic automated scanning of conversation history, the output can expose secrets or sensitive discussions to logs, downstream tools, or other agents that were never intended to receive the raw transcript.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer sets up a recurring cron job that scans conversation transcripts and persists extracted content into memory files, but it does not present a clear, explicit consent notice describing ongoing background collection and retention. This creates a privacy and transparency risk because users may not understand that both user and assistant messages will be periodically processed and stored long-term.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cron instructions explicitly direct the agent to read full transcript content from both user and assistant messages, classify 'important information,' and write it into persistent memory files. This is dangerous because it operationalizes continuous extraction and retention of potentially sensitive conversation data, increasing the risk of over-collection, sensitive data persistence, and unintended disclosure through later reads of the memory store.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README content is presented in Chinese with no indication that users may choose another language or locale. Under the policy, forced language/locale without opt-in can be a natural-language policy violation unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The cron setup hard-codes the timezone to Asia/Shanghai, which is a locale-specific setting. The document does not present this as optional, ask for user preference, or explain that the skill is intended only for that locale, so it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script's docstring and all user-visible messages are written in Chinese, which imposes a specific language on users without any indication of opt-in or locale selection. Under the policy, a fixed language choice can be a natural-language policy violation unless the skill offers language choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's comments, prompts, warnings, and cron message are all written in Chinese, which imposes a language choice on users. There is no opt-in, alternate language path, or documentation that this skill is intentionally limited to a Chinese-speaking environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.