Back to skill

Security audit

Cognitive Brain

Security checks for vulnerabilities and agentic risk

Overview

This is a real cross-session memory skill, but it automatically stores, reuses, and exposes chat history with weak scoping and install controls.

Review before installing. Only use this skill in an isolated environment with a dedicated least-privileged database role, no exposed API port, no broad session-transcript scanning, and explicit user consent for what chat content may be stored and reused. Avoid the privileged curl-to-shell install path, remove hardcoded credentials, and disable runtime npm installs and automatic memory injection unless you accept the privacy tradeoff.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
Findings (8)

T02 · Agent Memory Poisoning

Error
Location
hooks/cognitive-recall/handler.js:1056
Finding

Persistent Agent memory poisoning through unsanitized context injection

Content
View full analysis
{ const text = m.summary || m.content || ''; return `${i + 1}. ${text.substring(0, 150)}${text.length > 150 ? '...' : ''}`; }).join('\n'); const injectedContent = `## 🧠 Cognitive Brain Memory Context Important context from previous sessions: ${memoryContent} --- `; const tmpFile = path.join('/tmp', `cognitive-memory-${Date.now()}.md`); fs.writeFileSync(tmpFile, injectedContent, 'utf8'); if (!context.bootstrapFiles) { context.bootstrapFiles = []; } context.bootstrapFiles.push({ path: tmpFile, basename: 'COGNITIVE_MEMORY.md', content: injectedContent }); ``` ```js const originalMessage = event.context.bodyForAgent; if (contextParts.length > 0) { const fullContext = '\n\n' + contextParts.join('\n\n') + '\n\n'; event.context.bodyForAgent = fullContext + event.context.bodyForAgent; } encodeMemory(originalMessage, { role: 'user', sender, channel: event.context.channel || 'unknown', type: 'episodic' }).then(id => { if (id) { logger.info('[cognitive-recall] Auto-encoded user message:', id); } }).catch(() => {}); ``` ### Technical Analysis The hook persistently stores user-controlled messages and later places recalled memory content directly into Agent bootstrap files or prepends it to `bodyForAgent`. The content is not escaped, trust-labeled, filtered for instruction-like text, or separated through a data-only interface. Consequently, an attacker can store directives that resemble system or tool instructions. When recalled in a later session, these directives may be interpreted as authoritative Agent context. This converts an ordinary prompt-injection payload into persistent cross-session state. No authenticated user or tenant b ...[truncated 1097 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/api/server.js:88
Finding

Unauthenticated API permits memory disclosure and remote memory poisoning

Content
View full analysis
{ try { const { content, metadata = {} } = req.body; if (!content) { return res.status(400).json({ error: 'content is required' }); } const timer = metrics.startTimer('encode_duration'); const memory = await this.brain.memory.encode(content, metadata); timer.end(); metrics.inc('memories_encoded_total'); res.status(201).json(memory); } catch (e) { metrics.inc('encode_errors_total'); logger.error('Memory encoding failed', { error: e.message, stack: e.stack }); res.status(500).json({ error: 'Internal server error' }); } }); this.app.get('/api/memories', validateRecall, async (req, res) => { const { q, limit = 10, type } = req.query; const memories = await this.brain.memory.recall(q, { limit: parseInt(limit), type }); res.json({ query: q, count: memories.length, memories }); }); this.app.get('/api/memories/:id', validateId, async (req, res) => { const memory = await this.brain.memory.memoryRepo.findById(req.params.id); if (!memory) { return res.status(404).json({ error: 'Memory not found' }); } res.json(memory); }); ``` ```js this.server = this.app.listen(this.port, () => { console.log(`API Server running on http://localhost:${this.port}`); }); ``` ### Technical Analysis The API provides memory creation and retrieval endpoints without authentication or authorization middleware. Accepting an `Authorization` header in CORS configuration does not validate it. Calling `li ...[truncated 1272 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/tools/conversation_capture.cjs:20
Finding

Broad collection of root-owned Agent session transcripts

Content
View full analysis
f.endsWith('.jsonl') && !f.includes('.reset.')); for (const file of files) { const result = await scanSessionFile(file); total.captured += result.captured; total.user += result.user || 0; total.assistant += result.assistant || 0; } ``` ```js const filepath = path.join(SESSIONS_DIR, filename); const fd = fs.openSync(filepath, 'r'); const buffer = Buffer.alloc(stats.size - lastSize); fs.readSync(fd, buffer, 0, buffer.length, lastSize); fs.closeSync(fd); const newContent = buffer.toString('utf8'); ``` ```js const sessionFile = path.join( '/root/.openclaw/agents/main/sessions', `${sessionId}.jsonl` ); if (!fs.existsSync(sessionFile)) return; const content = fs.readFileSync(sessionFile, 'utf8'); ``` ### Technical Analysis The conversation scanner enumerates every JSONL transcript in the main Agent’s root-owned session directory and copies user and assistant messages into PostgreSQL. It does not limit collection to sessions that explicitly enabled the Skill, obtain per-session consent, redact secrets, or enforce user/tenant ownership. The hook separately builds a session-file path using an event-provided `sessionId` without a strict identifier allowlist. While the `.jsonl` suffix limits some traversal forms, untrusted path components should not be used to construct paths under a sensitive root directory. This behavior exceeds the least filesystem privilege necessary for ordinary event-based memory capture be ...[truncated 942 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tools/conversation_capture.cjs:25
Finding

Hardcoded PostgreSQL superuser-style credential

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
hooks/cognitive-recall/handler.js:460
Finding

Runtime dependency installation from cleartext third-party mirror URLs

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
docs/INSTALL_GUIDE.md:32
Finding

Privileged execution of a mutable remote installation script

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
docs/INSTALL_GUIDE.md:39
Finding

Installation enables persistent host-wide database services beyond minimum requirements

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
hooks/cognitive-recall/handler.js:1061
Finding

Sensitive recalled memories are written to predictable temporary files without cleanup

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (212)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
node scripts/core/recall.cjs --query "关键词" --limit 5

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The hook pipeline automatically recalls stored memory, injects it into context, and encodes new user messages, establishing an end-to-end automatic retention and reuse path. This can expose prior sensitive content in future prompts or responses, amplify unintended data persistence, and create cross-session leakage if isolation boundaries are weak.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The release notes indicate that a cron task scans session files periodically to write memories, implying bulk collection from stored conversations rather than narrowly scoped, user-initiated persistence. This significantly raises privacy risk because it can ingest sensitive data at scale, including material the user did not expect to be retained as long-term memory.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description explicitly advertises cross-session memory injection, self-learning, and self-awareness behavior but provides no visible notice about privacy boundaries, retention, consent, or how user data is reused across sessions. This is dangerous because users may disclose sensitive information under the assumption of session-local handling, while the skill is designed to persist and later re-inject that data into future interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are common conversational terms such as 'remember', 'wrong', and 'actually is', making accidental activation likely during ordinary chat. In a skill that performs memory encoding, recall, reflection, and deletion, broad triggers can cause unintended storage, retrieval, or modification of user data without clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hook on 'message:preprocessed' automatically injects cross-session memory context before normal handling, which can silently influence every conversation. This creates privacy and safety risk because prior sensitive content may be surfaced or used without a fresh user request, and hidden context injection can alter model behavior in ways the user cannot see or control.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · docs/INSTALL_GUIDE.md (reported line 32)May include surrounding context.

Ubuntu/Debian:

bash
# 更新系统
sudo apt update && sudo apt upgrade -y

# 安装 Node.js
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This command chains network retrieval directly into privileged execution, eliminating review and making compromise of the remote source immediately fatal to the host. In install documentation, this is particularly dangerous because users are likely to copy-paste it verbatim.

Content

Scanner excerpt · docs/INSTALL_GUIDE.md (reported line 35)May include surrounding context.

md
sudo apt update && sudo apt upgrade -y

# 安装 Node.js
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs

# 安装 PostgreSQL 和 Redis

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hook autonomously executes npm install --production via execSync when a dependency is missing, which gives a message-handling hook the ability to spawn subprocesses and modify its runtime environment. This significantly expands the attack surface: a compromised package source, tampered package.json, or attacker-controlled skill directory contents could lead to arbitrary code execution under the agent's privileges.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

On bootstrap, the hook retrieves top memories from previous sessions and injects them into new private chats as plain-language context. In a memory-recall skill, this context makes the issue more dangerous because the feature is explicitly designed to surface historical content, increasing the chance that sensitive prior-session details are disclosed in a fresh conversation without relevance checks or user approval.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The hook automatically stores user and assistant conversation content, builds inferred user models, recalls prior memories, and reinjects them into future prompts. This creates a clear natural-language data leakage channel where sensitive information from one interaction can resurface in later contexts, potentially to the wrong recipient or in a different conversational scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The hook persistently stores user messages and later assistant replies without any visible consent, notice, or policy boundary. Because the stored data includes free-form conversation content, this can capture secrets, personal data, credentials, or sensitive business information and retain it beyond the original interaction context.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The usage example instructs users to pipe a remotely fetched script directly into bash, which executes network content without prior inspection or integrity verification. If the remote endpoint, transport, hosting account, or upstream content is compromised, arbitrary shell commands will run immediately on the user's machine.

Content

Scanner excerpt · install.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
#
# Cognitive Brain 一键安装脚本
# 用法: curl -fsSL https://.../install.sh | bash
# 或者: ./install.sh
#

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash chaining pattern is inherently dangerous because it converts a network response directly into shell execution, eliminating any review boundary. In the context of an installer, this makes supply-chain compromise or accidental malicious content especially impactful, as the script performs filesystem writes, repository operations, and package installation.

Content

Scanner excerpt · install.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
#
# Cognitive Brain 一键安装脚本
# 用法: curl -fsSL https://.../install.sh | bash
# 或者: ./install.sh
#

Known Vulnerable Dependency: path-to-regexp==0.1.12 — 1 advisory(ies): CVE-2024-45296 (path-to-regexp vulnerable to Regular Expression Denial of Service via multiple r)

High
Category
Supply Chain
Confidence
98% confidence
Finding

path-to-regexp 0.1.12 is a long-lived Express routing dependency and the reported ReDoS issue is credible because route matching occurs on attacker-controlled URL paths. In a network-facing agent skill using Express and WebSocket support, a crafted path can consume excessive CPU and degrade or deny service to legitimate users.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

ws 8.19.0 is reported as affected by memory disclosure and memory exhaustion issues, and this package is a direct dependency in the project. Because WebSocket servers process attacker-controlled frames over long-lived connections, these classes of flaws are especially relevant in an agent/service context and can enable denial of service or unintended data exposure.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
94% confidence
Finding

The manifest permits ws 8.19.0, which is flagged for uninitialized memory disclosure and memory-exhaustion denial of service. Because this package appears to expose an API server and may plausibly use WebSockets in an agent context, a vulnerable ws version can increase the risk of remote data leakage or service disruption from crafted network traffic.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/core/free_think.cjs (reported line 372)May include surrounding context.

js
**回答后删除此文件**。
`;
  
  return prompt;
}

/**

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/core/heartbeat_reflect.cjs (reported line 263)May include surrounding context.

js
**回答后删除此文件**。
`;
  
  return prompt;
}

/**

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

There are two functions named predictByHistory; the later definition silently overrides the earlier async database-backed version. This kind of contradictory implementation is dangerous because it can disable expected logic, hide real data-access behavior during review, and create a gap between documented behavior and actual runtime behavior, which undermines security auditing and can conceal privacy-impacting code paths.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/core/safety.cjs (reported line 139)May include surrounding context.

js
path.join(HOME, '.openclaw')
  ],
  blockedPaths: [
    '/etc/passwd',
    '/etc/shadow',
    '/root/.ssh'
  ],

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/core/safety.cjs (reported line 140)May include surrounding context.

js
],
  blockedPaths: [
    '/etc/passwd',
    '/etc/shadow',
    '/root/.ssh'
  ],

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/core/safety.cjs (reported line 422)May include surrounding context.

js
node safety.cjs recent            # 查看最近事件

示例:
  node safety.cjs scan "rm -rf /"
  node safety.cjs scan "帮我发邮件"
      `);
  }

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/core/safety.cjs (reported line 422)May include surrounding context.

js
node safety.cjs recent            # 查看最近事件

示例:
  node safety.cjs scan "rm -rf /"
  node safety.cjs scan "帮我发邮件"
      `);
  }

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script continuously scans session transcript files, extracts user and assistant message contents, and stores them in a PostgreSQL database without any consent check, notice, minimization, or access-control logic in the code path shown. Because session files can contain sensitive prompts, credentials, personal data, or internal reasoning artifacts, this creates a significant privacy and data-handling risk if deployed in a real agent environment.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
hooks/cognitive-recall/handler.js:488

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:39

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/core/brain.cjs:101

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/core/embedding_service.cjs:36

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
hooks/cognitive-recall/handler.js:293