T01 · Skill Instruction Hijacking
- Location
scripts/memory-scan.py:75- Finding
Untrusted Transcript Content Is Passed to a Tool-Enabled Agent
- Content
View full analysis
/dev/null && echo " cron 创 ...[truncated 2435 chars]- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed memory automation tool, but it reads conversation transcripts on a schedule and feeds raw transcript text to a tool-enabled agent with broad write authority and weak privacy controls.
Review before installing. Enable this only if you are comfortable with a background cron reading conversation transcripts and storing selected summaries. Configure an explicit transcript path, avoid granting broad exec/read/write where possible, add redaction and review before memory writes, and do not enable Feishu delivery unless you intend memory-derived data to leave the local environment.
scripts/memory-scan.py:75Untrusted Transcript Content Is Passed to a Tool-Enabled Agent
scripts/memory-scan.py:24Weak Transcript Selection Can Read the Wrong Session
声明的核心承诺是“自动发现重要信息并写入每日 memory”,这是该技能的主要目的。但所给代码仅做增量扫描和展示:它从 transcript 中筛出新消息,支持 user+assistant 双读,维护 last_scan_ts 防止重复扫描,这些与描述部分一致。然而关键能力缺失:没有任何逻辑将提取结果写入 MEMORY_FILE,也没有重要性判断、任务/决策/教训/配置变更提取逻辑。代码只是打印“新消息”和“当前Memory文件”,然后更新 scan-state.json。另一个声明中的组件/行为“每周六记忆合并”也未在此代码中体现。因而描述与实际行为存在实质性不匹配。
The description presents the skill as an automatic memory-management feature centered on incremental scanning and two cron jobs (15-minute scan plus weekly merge). However, the supplied code chunk is specifically a setup script, not the scanning logic itself. Its primary behavior is installation/configuration: creating directories, copying files, initializing state, locating a transcript, editing another script, and optionally registering one cron job. Those are materially different from the declared runtime behavior. Most importantly, the description claims two cron components including a weekly merge, but this code only creates the 15-minute scan cron and contains no weekly merge setup. This is a meaningful description-to-behavior mismatch, even though the created cron's intent is broadly aligned with the declared memory scanning purpose.
The script consumes the MEMORY_SCAN_TRANSCRIPT environment variable and also implicitly relies on filesystem environment expansion via os.path.expanduser. If the skill's declared permissions do not cover environment access, this creates an undeclared capability that can surprise operators and weaken security review, especially in an automation context that periodically processes sensitive transcripts.
The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The README explicitly promotes automatic scanning of conversation history and writing discovered information into persistent memory, but it does not clearly warn users about privacy implications, consent expectations, retention behavior, or what categories of data may be stored. In this skill context, the feature is specifically designed to inspect transcripts on a schedule, which increases the risk of silently collecting sensitive personal, credential, or business information if users are not clearly informed.
The README instructs users to create persistent state under ~/.openclaw/workspace/memory, establishing ongoing session persistence for scan metadata and likely related memory artifacts. In the context of an automated transcript-scanning skill, persistence increases exposure because sensitive conversation-derived data may remain on disk beyond the original session and can be accessed later if the host or account is compromised.
cp -r scripts/memory-scan.py ~/.openclaw/scripts/
# 初始化 scan-state.json
mkdir -p ~/.openclaw/workspace/memory
echo '{"last_scan_ts": 0}' > ~/.openclaw/workspace/memory/scan-state.json
# 创建 cron(需要手动替换 transcript 路径)
The skill is designed to automatically scan and persist conversation content, including both user and assistant messages, but does not present a clear privacy warning or consent boundary up front. This is dangerous because users may unknowingly have sensitive information copied into long-lived memory files, increasing exposure, retention, and downstream misuse risk.
These instructions direct persistent storage of semantically summarized conversation content into memory files based on broad categories such as decisions, lessons, discoveries, and blockers. That is dangerous because it normalizes long-term retention of potentially sensitive user data and assistant-derived conclusions without strong minimization, review, or consent controls.
The cron message operationalizes continuous logging of both user and assistant conversation content into persistent storage using broad semantic criteria. In context, the automation and recurring schedule make this more dangerous because it can silently accumulate sensitive information over time without fresh user awareness, increasing privacy and data leakage risk.
The weekly merge flow instructs the system to send results to an external Feishu channel without a prominent warning about disclosure of conversation-derived content. This creates a real risk of exfiltrating sensitive summaries, decisions, configuration changes, or user data outside the local environment to a third-party communication system.
The weekly merge expands retention by consolidating daily memories into a longer-lived MEMORY.md and then instructs outward notification via Feishu. This compounds privacy risk by both broadening persistence and enabling external sharing of conversation-derived summaries, which may expose sensitive information beyond the original workspace.
The code comments imply transcript input comes from an environment variable, but in practice it silently falls back to scanning local session files under ~/.openclaw/agents/main/sessions/. This discrepancy is dangerous because it broadens data access beyond what an operator may expect, causing unintended collection of potentially sensitive conversation history from the main session.
The inline documentation understates the script's actual behavior by suggesting only environment-based transcript selection, while the implementation auto-discovers and reads session files. This kind of misleading documentation increases the chance that reviewers and users misunderstand the script's data access scope and approve it without realizing it inspects local conversation logs.
The script reads user and assistant messages from transcripts and prints them for downstream analysis without any user-facing privacy notice or redaction step. In this skill's context, the data being scanned is conversational memory content, which can naturally include credentials, personal data, internal decisions, and other sensitive material, making uncontrolled disclosure especially risky.
The script explicitly prints up to 30 recent user and assistant messages in plaintext, including arbitrary user-provided content. Because this skill is designed for periodic automated scanning of conversation history, the output can expose secrets or sensitive discussions to logs, downstream tools, or other agents that were never intended to receive the raw transcript.
The installer sets up a recurring cron job that scans conversation transcripts and persists extracted content into memory files, but it does not present a clear, explicit consent notice describing ongoing background collection and retention. This creates a privacy and transparency risk because users may not understand that both user and assistant messages will be periodically processed and stored long-term.
The cron instructions explicitly direct the agent to read full transcript content from both user and assistant messages, classify 'important information,' and write it into persistent memory files. This is dangerous because it operationalizes continuous extraction and retention of potentially sensitive conversation data, increasing the risk of over-collection, sensitive data persistence, and unintended disclosure through later reads of the memory store.
The README content is presented in Chinese with no indication that users may choose another language or locale. Under the policy, forced language/locale without opt-in can be a natural-language policy violation unless clearly documented and justified.
The cron setup hard-codes the timezone to Asia/Shanghai, which is a locale-specific setting. The document does not present this as optional, ask for user preference, or explain that the skill is intended only for that locale, so it may violate language/locale policy expectations.
The script's docstring and all user-visible messages are written in Chinese, which imposes a specific language on users without any indication of opt-in or locale selection. Under the policy, a fixed language choice can be a natural-language policy violation unless the skill offers language choice or clearly documents a justified regional constraint.
The script's comments, prompts, warnings, and cron message are all written in Chinese, which imposes a language choice on users. There is no opt-in, alternate language path, or documentation that this skill is intentionally limited to a Chinese-speaking environment.
No suspicious patterns detected.