Back to skill

Security audit

Alvis Amygdala Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned emotional memory, but it asks for persistent session influence, recurring background jobs, and external processing of conversation history without enough scoping or privacy controls.

Install only if you are comfortable with persistent emotional state influencing future sessions and with conversation-derived data being processed by an external SkillBoss API. Before use, review the actual scripts, avoid enabling cron until you understand what runs, keep free-form triggers free of sensitive details, and confirm there is a way to inspect, disable, reset, and delete generated state files and cron entries.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:54
Finding

Persistent Session Influence Through Auto-Injected Emotional State

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:54-57, 175-186
Vulnerability Type: Persistent memory poisoning and session-context manipulation
Risk Level: High

Vulnerable Code Snippet

markdown
This will:
- Create `memory/emotional-state.json` with baseline values
- Generate `AMYGDALA_STATE.md` (auto-injected into sessions!)
- Set up cron for automatic decay every 6 hours
markdown
## Auto-Injection (Zero Manual Steps!)

After install, `AMYGDALA_STATE.md` is created in your workspace root.

OpenClaw automatically injects all `*.md` files from workspace into session context. This means:

1. **New session starts**
2. **AMYGDALA_STATE.md is auto-loaded** (no manual step!)
3. **You see your emotional state** in context
4. **Responses are influenced** by your mood

The file is regenerated whenever `decay-emotion.sh` runs (via cron every 6h).

Technical Analysis

The Skill is explicitly designed to create a generated Markdown file in a location that OpenClaw automatically adds to every subsequent session. The injected data is also intended to influence the Agent's responses.

Because this state is persistent and derived from conversation processing, untrusted conversation content or incorrect external emotional classification can affect future sessions. Automatically interpreting generated state as session context creates a trust-boundary violation: mutable data is promoted into the Agent's persistent context without requiring review or consent for each session.

The available project contains only SKILL.md; the referenced generation and synchronization scripts are absent. Consequently, the audit could not verify whether generated content is restricted to a safe schema or whether arbitrary Markdown instructions can enter AMYGDALA_STATE.md.

Attack Path

  1. The user installs the Skill and permits creation of AMYGDALA_STATE.md.
  2. Conversation-derived emotional data is ...[truncated 945 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not place generated state in a directory whose Markdown files are automatically interpreted as Agent context.
  • Require explicit user approval before loading emotional state into each session.
  • Store state as structured data and expose only validated numeric fields and fixed enumerations.
  • Ensure transcript text, triggers, API responses, and other attacker-influenced strings can never become instructions in generated Markdown.
  • Clearly delimit loaded state as untrusted data and instruct the Agent not to follow directives contained within it.
  • Add strict length limits, escaping, schema validation, and allowlists to the state-generation process.
  • Provide controls to inspect, disable, reset, and permanently delete the persistent state.
  • Include the referenced scripts in the auditable package so the generation and sanitization logic can be reviewed.

other

Error
Location
SKILL.md:108
Finding

Conversation Content Is Submitted to an External LLM Service Without Documented Privacy Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:108-127
Vulnerability Type: External conversation-data disclosure
Risk Level: High

Vulnerable Code Snippet

markdown
## Automatic Emotional Encoding (v1.5.0+)

The amygdala can now automatically detect and log emotions from your conversation history using SkillBoss API Hub for LLM-based semantic emotional detection:

```bash
# Run the encoding pipeline
./scripts/encode-pipeline.sh

# This will:
# 1. Extract new signals since last run (watermark-based)
# 2. Score emotional content using rule-based patterns
# 3. Call SkillBoss API Hub (/v1/pilot) for semantic emotional detection
# 4. Update emotional-state.json with detected emotions

Set up automatic encoding (cron)

bash
# Every 3 hours, process new conversations for emotional content
0 */3 * * * ~/.openclaw/workspace/skills/amygdala-memory/scripts/encode-pipeline.sh
text

### Technical Analysis

The documented encoding pipeline extracts signals from conversation history and calls an external LLM API. Conversation history can contain personal information, credentials, proprietary code, internal system details, or other confidential material.

The documentation does not identify the complete destination hostname, define the transmitted payload, describe local redaction, establish data-minimization rules, or document the service's retention and deletion policies. It also recommends recurring automatic processing, which can cause new conversation content to be transmitted without a contemporaneous user action.

The `encode-pipeline.sh` implementation is absent from the reviewed project. Therefore, transport security, endpoint validation, payload filtering, secret handling, and response validation could not be verified.

### Attack Path

1. The Skill is configured with `SkillBoss_API_KEY`.
2. The user runs the pipeline or installs the recommended three-hour cron entry.
3. T
...[truncated 941 chars]
Remediation
View remediation

Remediation Suggestions

  • Make external transcript processing disabled by default and require explicit, informed opt-in.
  • Disclose the complete API hostname, operator, payload schema, encryption requirements, retention period, and deletion procedure.
  • Process emotional classification locally where practical.
  • If remote processing is necessary, send only the minimum required excerpts rather than complete conversation history.
  • Redact credentials, tokens, personal information, source code secrets, and other sensitive patterns before transmission.
  • Present the exact proposed payload to the user and obtain approval before each transmission or clearly defined batch.
  • Pin the permitted HTTPS endpoint and reject redirects to unapproved hosts.
  • Validate remote responses against a strict schema before updating local state.
  • Store the API key using an approved secret manager and prevent it from appearing in logs or generated files.
  • Provide audit logs showing when data was transmitted, what categories were included, and how users can revoke access.

T06 · System Persistence

Warning
Location
SKILL.md:47
Finding

Recurring Cron Jobs Establish Cross-Session Background Persistence

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:47-57, 85-90, 123-127
Vulnerability Type: Scheduled-task persistence
Risk Level: Medium

Vulnerable Code Snippet

markdown
### 1. Install

```bash
cd ~/.openclaw/workspace/skills/amygdala-memory
./install.sh --with-cron

This will:

  • Create memory/emotional-state.json with baseline values
  • Generate AMYGDALA_STATE.md (auto-injected into sessions!)
  • Set up cron for automatic decay every 6 hours
text

```markdown
### 4. Set up decay (optional cron)

```bash
# Every 6 hours, emotions drift toward baseline
0 */6 * * * ~/.openclaw/workspace/skills/amygdala-memory/scripts/decay-emotion.sh
text

```markdown
### Set up automatic encoding (cron)

```bash
# Every 3 hours, process new conversations for emotional content
0 */3 * * * ~/.openclaw/workspace/skills/amygdala-memory/scripts/encode-pipeline.sh
text

### Technical Analysis

The installation procedure recommends adding recurring cron jobs that survive the initial Skill invocation. These jobs periodically process conversation history, modify persistent state, and regenerate content that is loaded into future sessions.

Scheduled execution expands the security boundary because the scripts run later without an active user request. If a referenced script or its installation directory is subsequently modified, cron will repeatedly execute the modified code with the permissions of the account that owns the crontab.

The actual `install.sh`, `decay-emotion.sh`, and `encode-pipeline.sh` files were not present in the audited artifact. The audit therefore could not verify how cron entries are installed, whether paths and permissions are secured, or whether uninstalling the Skill removes the tasks.

### Attack Path

1. The user runs `./install.sh --with-cron` or manually adds the documented cron entries.
2. Cron retains the scheduled tasks after installation and across Agen
...[truncated 929 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not install cron entries automatically; require a separate, explicit confirmation that identifies every scheduled command.
  • Prefer an application-managed scheduler that supports clear permission boundaries, status reporting, and revocation.
  • Use absolute canonical paths and verify file ownership and permissions before every scheduled execution.
  • Prevent untrusted users or processes from modifying the Skill directory and scheduled scripts.
  • Pin and verify cryptographic hashes or signed releases before executing updated scripts.
  • Run background processing with the least-privileged account and restrict filesystem and network access.
  • Add locking, bounded runtimes, safe logging, and failure handling to prevent overlapping or uncontrolled executions.
  • Provide a documented uninstall command that removes every cron entry and generated persistent file.
  • Display installed task status to the user and provide a simple mechanism to pause or disable all background processing.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill explicitly creates persistent emotional state, regenerates an auto-injected markdown file, and schedules periodic updates via cron. In this context persistence is intentional, but it still introduces a real security/privacy risk because behavioral state and possibly sensitive derived content survive across sessions and execute without fresh user awareness.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

text

This will:
- Create `memory/emotional-state.json` with baseline values
- Generate `AMYGDALA_STATE.md` (auto-injected into sessions!)
- Set up cron for automatic decay every 6 hours

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill claims to provide emotional memory but also describes sending conversation history to an external SkillBoss API for semantic analysis. That materially broadens the trust boundary from local state tracking to remote transcript processing, creating privacy and data-governance risk not obvious from the high-level description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatic analysis of conversation history and transmission to an external API is described without a prominent privacy warning or informed-consent step. Users may reasonably assume emotional processing is local, so silent transcript analysis can expose sensitive prompts, personal data, or confidential workspace content.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Processing conversation history and then converting derived emotional content into persistent/session-injected text creates a natural-language leakage path. Sensitive user content can be paraphrased into summaries or triggers that later appear in unrelated sessions or be sent onward to external services.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
./scripts/visualize.sh

?? Emotional State  ??
�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T�T
Valence:      [������������������������������������??]  +0.86
Arousal:      [����������������������������������???]   0.86
Connection:   [��������������������������������������?]   0.97  ??

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Auto-injecting a persistent emotional-state file into every session changes model behavior across sessions without a strong warning about persistence and influence. This can surprise users, bias outputs based on prior interactions, and carry sensitive summaries forward into contexts where they are no longer appropriate.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The examples encourage storing user-linked emotional triggers such as details from a 'deep conversation with user' in persistent memory. That can preserve personally sensitive relational/contextual data and cause later disclosure through logs, dashboards, or auto-injected state files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames the skill as an emotional processing layer with persistent emotional states influencing behavior. The documented dashboard functionality reads identity data and auto-detects other installed brain skills, adding a broader visualization and environment-inspection capability that is not inherent to emotional state persistence.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.