Back to skill

Security audit

Context Restore

Security checks for vulnerabilities and agentic risk

Overview

The skill has a real context-restore purpose, but its background cron monitoring and unverified notification hook create review-worthy persistence and execution risk.

Install only after reviewing and disabling the cron and auto-restore paths unless you explicitly want background monitoring. Treat restored context as sensitive, avoid external notification hooks unless you control and audit the script, and do not use the documented `crontab -` pipeline without preserving your existing scheduled jobs.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
scripts/restore_context.py:2160
Finding

Recurring Cron-Based Context Monitor Establishes Cross-Session Persistence

Content
View full analysis
str: """ Generate a shell script for cron integration. Creates a ready-to-use cron entry script that can be added to crontab for automated context monitoring. """ script = f'''#!/bin/bash # Context Restore Auto-Monitor # Generated by restore_context.py Phase 3 # # Add to crontab for automatic context monitoring: # */5 * * * * /home/athur/.openclaw/workspace/skills/context-restore/scripts/auto_context_monitor.sh >> /var/log/context_monitor.log 2>&1 SCRIPT_DIR="/home/athur/.openclaw/workspace/skills/context-restore/scripts" CONTEXT_FILE="/home/athur/.openclaw/workspace/compressed_context/latest_compressed.json" LOG_FILE="/home/athur/.openclaw/workspace/logs/context_monitor.log" mkdir -p "$(dirname "$LOG_FILE")" echo "[$(date '+%Y-%m-%d %H:%M:%S')] Running context check..." python3 "$SCRIPT_DIR/restore_context.py" --auto --quiet --level normal ''' return script def install_cron_job( script_path: str = None, interval_minutes: int = 5 ) -> bool: if script_path is None: script_path = os.path.join(SCRIPT_DIR, 'auto_context_monitor.sh') script_content = generate_cron_script() try: with open(script_path, 'w', encoding='utf-8') as f: f.write(script_content) os.chmod(script_path, 0o755) interval = f"*/{interval_minutes}" if interval_minutes < 60 else f"0 */{interval_minutes // 60}" cron_entry = f"{interval} * * * * {script_path}" print(f"{EMOJI['success']} Cron script created: {script_path}") print(f"{EMOJI['info']} To install, run:") print(f' echo "{cron_entry}" ...[truncated 2737 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/restore_context.py:2142
Finding

Automatic Execution of an Unverified Notification Script Outside the Skill Package

Content
View full analysis
bool: """ Send notification about context changes. """ if os.path.exists(NOTIFICATION_SCRIPT): try: import subprocess cmd = [ 'python3', NOTIFICATION_SCRIPT, '--file', context_file, '--auto' if auto_mode else '--confirm' ] subprocess.run(cmd, capture_output=True, timeout=10) return True except (subprocess.SubprocessError, OSError): pass print(f"{EMOJI['bell']} Context change notification sent") return True ``` ### Technical Analysis When auto-restoration detects a context change, the Skill checks for a Python file at a path outside the audited Skill package and executes it solely because the path exists. The external script is not included in the audited project. No validation is performed for: - File ownership or permissions. - Whether the path is a symbolic link. - Whether the resolved path remains under a trusted directory. - File integrity or an expected cryptographic digest. - Whether the external hook was explicitly enabled by the user. The subprocess call uses an argument list rather than `shell=True`, so the `context_file` value does not directly create shell-command injection. The security issue is executable substitution: an attacker who can place or replace the expected notification script can cause arbitrary Python code to run under the Agent user's account. The subprocess return code is not checked. The function reports success after any completed invocation, even if the external script ...[truncated 1472 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
docs/USAGE.md:346
Finding

Documented Cron Installation Command Replaces the Entire Existing User Crontab

Content
View full analysis
> ~/.context_restore.log 2>&1" | crontab - # Method 2: Edit crontab crontab -e ``` ### Technical Analysis `crontab -` does not append a new entry to the current user's crontab. It installs the complete crontab supplied through standard input. Because the pipeline supplies only one line, following this documented command replaces all existing scheduled tasks with the Context Restore entry. This differs from the nearby `echo ... >> ~/.crontab; crontab ~/.crontab` instructions, although those instructions have separate duplication and stale-file risks. The destructive `crontab -` example is presented as a direct installation method without warning, backup, confirmation, or preservation of existing entries. ### Attack Path 1. A user already has scheduled jobs for backups, monitoring, synchronization, maintenance, or other applications. 2. The user follows the documented “add directly to crontab” command. 3. The shell passes only the Context Restore entry to `crontab -`. 4. Cron replaces the user's complete existing crontab with that single entry. 5. Existing scheduled jobs stop running, while the Skill's persistent monitor remains active. ### Impact Assessment The command can cause denial of service and loss of automation within the current user's account. Potential consequences include: - Missed backups and retention operations. - Disabled monitoring or alerting. - Failure of maintenance and synchronization tasks. - Loss of unrelated application schedules. - Replacement of security-related scheduled jobs. - Continued execution of the Context Restore monitor as the sole retained entry. The command does not directly e ...[truncated 176 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (112)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Cron installation, notifications, hash-cache persistence, and automated triggers go well beyond a user-invoked context reader and create unattended execution pathways. In practice, that means the skill can persist behavior and continue acting after initial invocation, which raises both security and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Cron installation, notifications, hash-cache persistence, and automated triggers go well beyond a user-invoked context reader and create unattended execution pathways. In practice, that means the skill can persist behavior and continue acting after initial invocation, which raises both security and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Cron installation, notifications, hash-cache persistence, and automated triggers go well beyond a user-invoked context reader and create unattended execution pathways. In practice, that means the skill can persist behavior and continue acting after initial invocation, which raises both security and privacy risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Cron installation, notifications, hash-cache persistence, and automated triggers go well beyond a user-invoked context reader and create unattended execution pathways. In practice, that means the skill can persist behavior and continue acting after initial invocation, which raises both security and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Documenting automatic notification and Telegram integration without warning that context-derived content may be sent to external services is a significant privacy risk. Historical context often contains sensitive operational details, and external transmission changes the threat model from local processing to possible disclosure to third parties.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include broad everyday language like 'continue', 'resume', and '接着', which can cause accidental activation during normal conversation. Because activation leads to reading and summarizing historical context, false triggers can expose prior-session information when the user did not intend a context restore action.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The proposed auto-trigger logic combines ambiguous everyday phrases with an unconditional trigger when a new session begins and compressed context exists. That design can restore and reveal prior context without a sufficiently explicit user request, increasing the chance of cross-session data exposure, especially in shared devices, multi-user channels, or mistaken session boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Cron script generation and cron job installation materially expand the skill from on-demand context restoration into persistence and background execution. For a skill advertised as restoring context when users ask to continue, this is dangerous because it introduces system modification and autonomous behavior that can monitor files or trigger actions without the user's immediate awareness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Installing cron jobs is an unjustified system-level capability for a context-restore feature and creates persistence on the host. Even if intended for convenience, it allows the skill to modify scheduled tasks and repeatedly execute logic that may access or process sensitive conversation context, increasing the blast radius if abused or misconfigured.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · docs/USAGE.md (reported line 346)May include surrounding context.

示例:**

text
✅ Cron script created: /home/athur/.openclaw/workspace/skills/context-restore/scripts/auto_context_monitor.sh
ℹ️  To install, run:
  echo "*/5 * * * * /home/athur/.openclaw/workspace/skills/context-restore/scripts/auto_context_monitor.sh >> /var/log/context_monitor.log 2>&1" >> ~/.crontab
  crontab ~/.crontab

2. 手动安装 Cron

bash
# 方法1:直接添加到 crontab
echo "*/5 * * * * /home/athur/.openclaw/workspace/skills/context-restore/scripts/restore_context.py --auto --quiet >> ~/.context_restore.log 2>&1" | crontab -

# 方法2:编辑 crontab
crontab -e
# 添加:
# */5 * * * * /home/athur/.openclaw/workspace/skills/context-restore/scripts/restore_context.py --auto --quiet >> ~/.context_restore.log 2>&1

3. Cron 输出配置

bash
# 输出到日志文件
python restore_context.py --auto --quiet >> /var/log/context_restore.log 2>&1

# 每天轮转日志
0 0 * * * mv /var/log/context_restore.log /var/log/context_restore_$(date +\%

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · docs/USAGE.md (reported line 492)May include surrounding context.

ls -la /home/athur/.openclaw/workspace/tmp/context_hashes/

手动清除缓存(强制重新检测)

rm /home/athur/.openclaw/workspace/tmp/context_hashes/latest_hash.json python restore_context.py --check-only

text

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Invoking an external notification script is not necessary for simple context restoration and introduces a high-risk capability boundary crossing from data processing to code execution. Because this path is reachable during automatic context-change handling, it can execute without an interactive review step, magnifying the risk of abuse if the local environment is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill can generate executable shell scripts and provide installation instructions for cron-based monitoring, effectively enabling persistence and unattended re-execution. That is far beyond a context-restore helper and is dangerous because it normalizes ongoing background execution that can repeatedly process or reveal user context without fresh consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document advertises automatic monitoring, cron integration, and external notifications without accompanying warnings about background execution, file watching, persistence, or possible transmission of context-derived information. Because this skill handles compressed conversation context that may contain sensitive project and task data, users may enable these features without understanding the privacy and system-modification implications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example trigger uses very broad natural language ('继续之前的工作' / 'continue previous work'), which can cause the skill to activate in situations where a user is speaking conversationally rather than explicitly requesting file-based context restoration. In a skill that reads stored context files and may expose prior operations, projects, or tasks, accidental invocation increases the risk of unintended disclosure of sensitive historical data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The automatic restore/monitoring description omits warnings that the feature may repeatedly read context files, run in the background, and surface sensitive prior conversation content without a fresh user review. In the context of a restoration skill, this makes accidental exposure more likely, especially on shared systems or when notifications and unattended execution are enabled.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says the skill "automatically reads compressed context files and restores your work state in seconds," but it does not clearly distinguish automatic restoration from explicit user-invoked restoration. In a skill that handles prior conversation state, this ambiguity can cause restoration to happen when users do not expect it, increasing the risk of unintentional exposure of stored context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The article promotes restoration of compressed context files and detailed history views but omits any warning that restored output may contain sensitive prior conversation content, project details, tasks, file names, or recent operations. Because the skill's core purpose is replaying historical context, the missing privacy warning makes accidental disclosure more likely and leaves users without guidance on safe usage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language triggers shown here are broad phrases like "continue previous work" and "what was I doing?" that can easily appear in ordinary conversation. In a context-restore skill, ambiguous triggers raise the chance of unintended activation and accidental disclosure of prior session data, project details, or recent operations to the current conversation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill that restores conversation context by reading compressed context files and extracting key information. This promotion document repeatedly states the skill can '自动保存/恢复' and 'automatically saves and restores' context, which adds a save capability not present in the stated skill purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Using a broad natural-language trigger like '继续之前的工作' can collide with normal conversation and unintentionally activate the skill. In a context-restore skill, accidental activation may cause retrieval and display of prior session context, potentially exposing sensitive project details, tasks, or recent operations to the wrong moment or audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The feature list explicitly advertises '智能上下文保存和恢复', while the skill’s stated purpose is to restore context from existing compressed files. This is not merely incomplete wording; it asserts an additional capability that conflicts with the restore-focused intent described for the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Describing a 'natural language trigger mechanism' without boundaries or exclusions increases the chance of prompt-trigger collisions. Because this skill restores stored context, unintended invocation can surface historical information and confuse agent state, creating privacy and integrity risks beyond a normal documentation ambiguity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Repeating the broad phrase in promotional copy reinforces an unsafe invocation model where ordinary user language doubles as a command. In this skill's context, that is more dangerous because activation leads to reading compressed context files and summarizing prior work, which can leak sensitive session content if triggered unintentionally.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

These sections market the skill as one that 'Auto-save and restore' or 'automatically saves and restores' conversation context. That contradicts the declared behavior for context-restore, which is limited to reading saved context and helping resume prior work.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.