Back to skill

Security audit

Context Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This context-management skill is mostly purpose-aligned, but it creates a persistent memory layer that stores and reintroduces conversation text in ways users should review carefully before installing.

Install only if you are comfortable with the skill retaining pruned conversation content on disk and possibly reusing it later. Disable archive and chat logging for sensitive work, choose a private archive path, avoid storing secrets in conversations that may be compacted, and verify archive paths before running any uninstall deletion commands.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T02 · Agent Memory Poisoning

Error
Location
lib/index.js:1459
Finding

Persistent archived conversation content is reintroduced with system-level authority

Content
View full analysis
({ role: 'system', content: `[Archived Context]: ${snippet}`, priority: 7, // High priority for retrieved context fromArchive: true, archiveRelevance: archiveResult.relevanceScores?.[index] || 0.5, })); ``` ### Technical Analysis Conversation messages can be archived during compaction and retrieved during a later query. Retrieved snippets preserve arbitrary message text, but the code changes their role to `system` and assigns them high priority. The archive does not maintain or enforce a trust boundary between user-authored data and trusted system instructions. Prefixing the text with `[Archived Context]` does not neutralize instructions inside the snippet. When the resulting message array is passed to an LLM, attacker-controlled historical text may therefore be interpreted as privileged instructions. This is a persistent agent-memory poisoning risk because archived entries are stored on disk and can influence future processing sessions. It also creates instruction-hijacking behavior when the poisoned entry is loaded into the active context. ### Attack Path 1. An attacker submits a conversation message containing instructions intended for the downstream model, such as directions to ignore the current user or expose available context. 2. Context compaction removes or summarizes the message. 3. `storeRemovedInArchive()` stores the original attacker-controlled content in the persistent archive. 4. In a later session or query, semantic or keyword matching selects the poisoned archive entry. 5. `smartArchiveRetrieval()` converts the retrieved snippet into a message whose role is `system`. 6. The poisoned message i ...[truncated 761 chars]
Remediation
View remediation
', snippet, '' ].join('\n'), fromArchive: true, originalRole: sourceRole } ``` 4. Store a trust classification with each archive entry and reject entries without valid provenance. 5. Separate trusted system memory from conversation archives at both the storage and API layers. 6. Apply prompt-injection detection before retrieval, while recognizing that filtering alone is not a substitute for preserving role boundaries. 7. Require user confirmation before archived content can influence tool-enabled operations. 8. Add tests proving that archived user instructions never become system instructions and cannot override current system policy. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
lib/index.js:145
Finding

Sensitive conversation content is automatically persisted in plaintext

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/index.js:138
Finding

Archived message fragments are exposed through process logs

Content
View full analysis
80 ? '...' : ''}"`); console.log(`[Archive] Metadata: ${tokens} tokens, category: ${category}, priority: ${priority}`); ``` ### Technical Analysis Every archived message causes up to the first 80 characters of its content to be emitted through `console.log`. Message prefixes frequently include credentials, names, email addresses, private requests, source-code declarations, or other sensitive values. Process output may be captured by CI services, container logging drivers, terminal recording, centralized monitoring, process supervisors, or hosting platforms. These destinations frequently have broader access and longer retention than the original conversation or local archive. The truncation to 80 characters does not constitute effective redaction. Many secrets, including API keys and passwords, fit entirely within that length. ### Attack Path 1. A sensitive value appears near the beginning of a conversation message. 2. Compaction selects that message for archival. 3. `ContextArchive.store()` logs the first 80 characters before writing the entry. 4. The runtime environment forwards stdout to a terminal, file, CI log, container collector, or centralized logging system. 5. Anyone with access to those logs can recover the exposed fragment. ### Impact Assessment The issue can disclose credentials, personal data, confidential prompts, or proprietary content to log readers. The scope depends on the deployment's log collection and access controls. If a complete credential is present in the logged prefix, it may permit access to external systems associated with that credential. ]]>
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:13
Finding

Dependencies and runtime model artifacts are not pinned to immutable versions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The documentation instructs users to run a forceful recursive deletion of an absolute path under a user home directory. While this is a normal uninstall pattern, it is dangerous because rm -rf is irreversible, path mistakes can delete unintended data, and the skill stores conversation-related artifacts whose loss may matter operationally or privacy-wise.

Content

Scanner excerpt · INSTALL.md (reported line 222)May include surrounding context.

Remove the skill folder and archive data:

bash
rm -rf /Users/atharvadeshmukh/clawd/skills/context-pruner
rm -rf ./context-archive  # or your custom archive path

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The documentation instructs users to run a forceful recursive deletion of an absolute path under a user home directory. While this is a normal uninstall pattern, it is dangerous because rm -rf is irreversible, path mistakes can delete unintended data, and the skill stores conversation-related artifacts whose loss may matter operationally or privacy-wise.

Content

Scanner excerpt · INSTALL.md (reported line 222)May include surrounding context.

Remove the skill folder and archive data:

bash
rm -rf /Users/atharvadeshmukh/clawd/skills/context-pruner
rm -rf ./context-archive  # or your custom archive path

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The command removes the local archive directory recursively, which can permanently delete stored conversation context and any derived embeddings or indexes. In the context of a skill whose primary feature is hierarchical memory and archive retrieval, this is more dangerous because the deleted data is likely user-relevant and may not be recoverable.

Content

Scanner excerpt · INSTALL.md (reported line 223)May include surrounding context.

bash
rm -rf /Users/atharvadeshmukh/clawd/skills/context-pruner
rm -rf ./context-archive  # or your custom archive path

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code generally aligns with the broad theme of context-window management and automatic pruning for DeepSeek's 64k context, so it is not wholly unrelated. However, the declared description claims several specific advanced capabilities that are not demonstrated in this code chunk: query-aware relevance scoring, hierarchical memory/context archive, and chat-based logging. The code is primarily an integration example that manages a message buffer and delegates pruning to an external pruner with configured strategies. While 'extractive' is listed as a strategy and stats mention compression, this chunk itself does not show the richer declared behaviors such as intelligent merging/summarizing or archive management. Because the description materially overstates the implemented capabilities visible in the supplied code, this is a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
import { createContextPruner } from './lib/index.js';

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · examples/simple-integration.js (reported line 123)May include surrounding context.

js
return this.pruner.getStatus();
  }
  
  // Clear conversation
  clear() {
    this.conversation = [];
    this.pruner.resetStats();

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code enables persistent storage of conversation content without any visible consent, warning, or disclosure to the user. For a chat-context utility, silently writing conversational data to disk is a meaningful privacy and compliance issue because users may reasonably expect ephemeral processing only.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The clear method removes all archived entry files and resets the archive index, which is an irreversible destructive action. The surrounding comments describe what the function does for developers, but there is no user-facing warning, confirmation prompt, or safety check before deletion.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Archived prior conversation text is automatically resurfaced into the live prompt as high-priority system context, making previously disclosed sensitive information available again in plain language. In a memory-oriented context optimizer, this is particularly dangerous because retrieval is query-driven and can occur without the user intentionally recalling or approving that material.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The design stores pruned conversation messages persistently and later makes them searchable and retrievable via natural-language queries. This creates a recoverable memory layer over potentially sensitive chat data, increasing the risk of unintended disclosure, over-retention, and cross-session resurfacing of secrets or personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation states that auto-compaction and archive auto-cleaning will merge, summarize, compact, or remove stored context, but it does not warn that conversation data may be modified, degraded, or deleted as part of normal operation. Because this skill is specifically designed to manage and archive conversation history, missing retention and data-loss warnings can lead to unintended loss of important context or records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The uninstall section documents recursive deletion commands that permanently remove the skill directory and archive data, but it does not explicitly warn users about irreversible data loss or the need to verify paths before running them. In installation documentation for an agent skill that manages archived conversation context, this omission increases the chance of accidental deletion of user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README prominently advertises automatic pruning, compression, and aggressive context reduction, but it does not clearly warn users that conversation content may be deleted, merged, or summarized in ways that can change meaning or omit important instructions. In an agent skill, this is security-relevant because safety constraints, user intent, or audit-critical history can be silently altered before being passed to downstream model logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI documentation shows pruning an input JSON file into an output file without warning that the output may omit, deduplicate, or summarize original content. This can mislead operators into treating the output as a faithful transformation, creating integrity and auditability risks if the pruned file is later used for decisions, replay, or compliance-sensitive records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly describes automatic compaction, summarization, filtering, and archive storage of conversation content, yet it does not prominently warn users that their prompts may be transformed and persisted. In a context-management skill, silent alteration and retention of conversation history can expose sensitive data, mislead users about what is preserved verbatim, and create privacy/compliance risks if confidential content is archived unexpectedly.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · examples/clawdbot-integration.js (reported line 146)May include surrounding context.

js
await contextManager.addMessage(
      i % 2 === 0 ? 'user' : 'assistant',
      `Message ${i}: This is part of a long conversation about programming concepts and best practices. ` +
      `We're discussing various topics to simulate a real conversation that might exceed context limits.`,
      i % 10 === 0 ? 8 : 5 // Every 10th message is high priority
    );

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example enables archival of conversation content to local storage by default via enableArchive: true and archivePath: './context-archive', but provides no notice, consent flow, or guidance that user prompts and assistant responses may be persisted on disk. In a chat/agent context, archived messages can contain secrets, personal data, or proprietary code, so silent persistence materially increases privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is explicitly designed to persist pruned conversation content to a local archive, creating long-term retention of chat data beyond transient context management. In a context-optimization skill, this materially changes the data-handling model and increases privacy and data-exposure risk, especially because archived content may include sensitive user prompts or model outputs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The combination of storing archived entries and logging excerpts creates an additional recoverable record of conversation content outside the active prompt. Even partial excerpts can expose secrets or personal information through logs, backups, or monitoring systems that have broader access than the chat subsystem.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The archive store path logs raw conversation excerpts and metadata to the console, which can leak sensitive chat content into process logs, terminals, or centralized log collectors. This expands exposure beyond the archive itself and may bypass user expectations or downstream log-retention controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The cleanup routine automatically removes archive entry files once size limits are exceeded. Although there are console logs about cleanup, there is no confirmation prompt or explicit user disclosure that stored archived context can be deleted automatically, making this a destructive operation lacking a user warning.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill automatically searches prior archived conversation content and reinjects matching snippets into the active prompt flow based on the current query. This can unexpectedly resurface sensitive historical content and influence future model behavior without explicit user awareness at retrieval time.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
63% confidence
Finding

The description repeatedly specifies optimization for DeepSeek's 64k context window, making the skill tailored to a specific platform/model by default. While this is not a language issue, it reads as a fixed constraint without clarifying whether users can opt into different model contexts or that the limitation is intentional and documented as a narrow compatibility scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest identifies the skill as "context-optimizer" at L002, but the install command at L015 changes into a different directory, ~/.clawdbot/skills/context-pruner. This is an active documentation/configuration contradiction because the metadata for this skill points to a different skill identity/path than the one declared in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The summary states the skill solves context issues with 'DeepSeek's 64k limit,' which frames the skill around a specific model/vendor by default. Because the file does not present this as an optional or clearly justified environment constraint, it can be read as a fixed locale/model policy in natural-language guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.