Back to skill

Security audit

AB-Agents-Memory

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is mostly purpose-aligned, but it installs persistent nightly execution and broad local memory collection with weak scoping and disclosure.

Review before installing. Use --skip-cron unless you specifically want daily background execution, inspect any generated cron entry, avoid running setup as root, choose a trusted fixed vault path, and do not store secrets, credentials, private personal data, or regulated business data without access controls and retention rules.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T06 · System Persistence

Error
Location
setup.sh:73
Finding

Default Installation Creates a Persistent Scheduled Task

Content
View full analysis
"$NIGHTLY_SCRIPT" << 'SCRIPT' #!/bin/bash # Nightly memory processing DATE=$(date +%Y-%m-%d) echo "Processing: $DATE" >> ./Memory/Processing/Nightly/logs/"$DATE".md # Add your processing logic here SCRIPT chmod +x "$NIGHTLY_SCRIPT" mkdir -p "$VAULT_DEST/Memory/Processing/Nightly/logs" # Add to crontab (03:00 MSK daily) (crontab -l 2>/dev/null | grep -v "AB-Memory-Vault"; echo "0 3 * * * cd $VAULT_DEST && bash $NIGHTLY_SCRIPT >> $VAULT_DEST/Memory/Processing/Nightly/logs/\$(date +\%Y-\%m-\%d).log 2>&1") | crontab - echo -e " ${CRAB}✓${NC} Cron installed (03:00 MSK daily)" fi ``` ### Technical Analysis The primary installer modifies the current user's crontab unless the user explicitly supplies `--skip-cron`. This creates a scheduled execution mechanism that survives completion of the installation and subsequent login sessions. Nightly processing is an advertised feature, so scheduling can be legitimate when explicitly requested. However, the implementation exceeds minimum necessary privileges because persistence is enabled by default and the installed processor currently performs no memory processing beyond appending a date to log files. The executable is also stored inside the user-facing vault rather than in a protected application directory. Any actor or process capable of replacing or editing `Memory/Processing/Nightly/process.sh` can cause arbitrary command ...[truncated 1449 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
setup.sh:20
Finding

Configurable Vault Path Permits Cron and sed Injection

Content
View full analysis
/dev/null || true fi ``` ```bash NIGHTLY_SCRIPT="$VAULT_DEST/Memory/Processing/Nightly/process.sh" mkdir -p "$(dirname "$NIGHTLY_SCRIPT")" # Add to crontab (03:00 MSK daily) (crontab -l 2>/dev/null | grep -v "AB-Memory-Vault"; echo "0 3 * * * cd $VAULT_DEST && bash $NIGHTLY_SCRIPT >> $VAULT_DEST/Memory/Processing/Nightly/logs/\$(date +\%Y-\%m-\%d).log 2>&1") | crontab - ``` ### Technical Analysis `VAULT_DEST` is accepted directly from the process environment. It is safely quoted for some immediate filesystem operations, but it is later interpolated without escaping into: 1. A `sed` replacement expression. 2. A textual crontab entry that cron will later parse as shell syntax. A path containing a newline can terminate the intended cron entry and introduce an additional scheduled command. Shell metacharacters in the path can also change the command interpreted by `/bin/sh` when cron runs it. Characters significant to `sed`, including `|`, `&`, and backslashes, can alter the replacement operation or corrupt the installed agent instructions. This is a deferred command-injection vulnerability: the malicious value is written during installation, while command execution occurs later through cron. ### Attack Path 1. An attacker influences the environment or installation command, for example by p ...[truncated 1145 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:124
Finding

Documentation Executes an Unpinned Mutable Remote Repository

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
agents/AB-Archivus/SOUL.md:40
Finding

Agent Instructions Request Broad Cross-Session Memory Collection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is a memory/knowledge skill, but the detected behavior includes system installation, agent registration, config rewriting, and cron persistence. This mismatch is dangerous because users may approve a seemingly harmless memory skill without realizing it can modify system state and establish recurring execution.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · setup.sh (reported line 98)May include surrounding context.

sh
.sh"
    mkdir -p "$(dirname "$NIGHTLY_SCRIPT")"

    cat > "$NIGHTLY_SCRIPT" << 'SCRIPT'
#!/bin/bash
# Nightly memory processing
DATE=$(date +%Y-%m-%d)
echo "Processing: $DATE" >> ./Memory/Processing/Nightly/logs/"$DATE".md
# Add your processing logic here
SCRIPT

    chmod +x "$NIGHTLY_SCRIPT"
    mkdir -p "$VAULT_DEST/Memory/Processing/Nightly/logs"

    # Add to crontab (03:00 MSK daily)
    (crontab -l 2>/dev/null | grep -v "AB-Memory-Vault"; echo "0 3 * * * cd $VAULT_DEST && bash $NIGHTLY_SCRIPT >> $VAULT_DEST/Memory/Processing/Nightly/logs/\$(date +\%Y-\%m-\%d).log 2>&1") | crontab -
    echo -e "  ${CRAB}✓${NC} Cron installed (03:00 MSK daily)"
fi

# Done
echo ""
echo -e "${CRAB}━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━${NC}"
echo -e "${BOLD}✅ AB Agents Memory installed!${NC}"
echo ""
echo "Next steps:"
echo "  1. Restart OpenClaw: openclaw gateway restart"
echo "  2. Open vault: $VAULT_DEST"
ech

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README promotes a long-term memory system that stores entity data including names, contact details, roles, locations, and relationship links, and mentions automatic nightly processing, but provides no warning about handling personal or sensitive data. In an agent-memory context, this can encourage users to collect and persist PII without consent, retention limits, or access controls, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README includes one-line installation commands that clone the repository and immediately execute ./setup.sh, plus a package-manager install path, without warning that the script will modify the filesystem and install agent/vault files into default locations. This increases the chance that users run unreviewed setup logic blindly, which is especially risky for an agent skill that integrates into local agent directories and persistent storage.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises shell-based installation and setup behavior but does not declare any explicit tool scope or permissions. This reduces transparency for reviewers and users, making it easier for filesystem and command-execution side effects to occur without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The feature list mentions automatic processing and read/write behavior to the vault, but does not warn that the skill modifies user data. In a long-term memory context, silent writes can overwrite notes, ingest sensitive information, or create trust issues around how stored data is handled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quick-start instructions tell users to run a setup script directly, with no caution about filesystem changes, configuration edits, or scheduled tasks. This creates a social-engineering risk where users execute code before understanding that installation may alter directories, agent settings, and recurring jobs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to read from and write to local memory files at session boundaries without any requirement for user consent, confirmation, or sandboxing. In an agent environment, this can cause silent modification of local data stores, create privacy risks by persisting sensitive conversation content, and expand the blast radius if the agent is prompted into storing misleading or sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill configures a cron job that will run automatically every night and execute a shell script from the vault path. Background scheduled execution increases risk because code continues running after install without a prominent warning, and if the script is later modified the system will keep invoking it automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The install section performs filesystem writes, agent registration, and a gateway restart, all of which modify the local environment and affect running services. Even if these actions are expected for installation, the config does not clearly warn the user about their side effects, which creates a consent and safety gap and could lead to unintended system changes during one-click install.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

The script establishes persistent execution by modifying the user's crontab to run a vault-resident shell script daily. Even though the current payload is simple logging, persistence mechanisms are security-relevant because they create unattended code execution and can later run modified content from a writable directory, increasing the blast radius if the vault or script is tampered with.

Content

Scanner excerpt · setup.sh (reported line 98)May include surrounding context.

sh
mkdir -p "$VAULT_DEST/Memory/Processing/Nightly/logs"

    # Add to crontab (03:00 MSK daily)
    (crontab -l 2>/dev/null | grep -v "AB-Memory-Vault"; echo "0 3 * * * cd $VAULT_DEST && bash $NIGHTLY_SCRIPT >> $VAULT_DEST/Memory/Processing/Nightly/logs/\$(date +\%Y-\%m-\%d).log 2>&1") | crontab -
    echo -e "  ${CRAB}✓${NC} Cron installed (03:00 MSK daily)"
fi

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is primarily in English, but the support section switches to Russian text and promotional copy without offering a language choice or documenting a locale-specific constraint. This can violate language/locale policy expectations where users are not given an explicit opt-in to a different language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file prescribes how the agent communicates but does not mention accommodating the user's preferred language or locale. Under the stated policy, fixed communication constraints can be a natural-language policy issue when no user opt-in or choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.