Back to skill

Security audit

Evermemos Openclaw Plugin

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real EverOS memory plugin, but it needs Review because it automatically persists conversation content and uses unsafe install and memory-injection patterns.

Install only if you trust EverMind, the npm package, and the EverOS backend you configure. Prefer pinning the npm package to the reviewed version, avoid curl-to-shell setup, keep the backend on localhost or HTTPS, review changes to ~/.openclaw/openclaw.json, and avoid sensitive conversations until logging, retention, deletion, and memory-review controls are acceptable for your environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:130
Finding

Remote Installer Is Downloaded and Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation
/install.sh" printf '%s %s\n' '' 'uv-installer.sh' | sha256sum -c - sh ./uv-installer.sh rm ./uv-installer.sh ``` The actual release URL and checksum must come from a trusted, versioned publisher release. ]]>

T01 · Skill Instruction Hijacking

Error
Location
src/engine.js:218
Finding

Backend-Controlled Persistent Memory Is Injected at System-Message Priority

Content
View full analysis
", ...(when ? [` - time: ${when}`] : []), ...(intent ? [` - intent: ${intent}`] : []), ...(approach ? [` - approach: ${approach}`] : []), " ", ]; } function skillBlock(s) { if (!s) return []; const name = oneLiner(s.name || ""); const desc = oneLiner(s.description || ""); const content = s.content || ""; if (!name && !content) return []; return [ " ", ...(name ? [` - name: ${name}`] : []), ...(desc ? [` - description: ${desc}`] : []), ...(content ? [` - content: ${content}`] : []), " ", ]; } ``` The resulting prompt also contains behavioral instructions: ```js return [ "Note: Reference memory below. Build on past successes; avoid repeating failed approaches.", ...(nowLabel ? [`- Time: ${nowLabel}`] : []), "", ...memSection, "", "**Note**: for memory, please not read from o ...[truncated 2638 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/api.js:28
Finding

Sensitive Conversation and Memory Data Is Logged Without Redaction

Content
View full analysis
{ const p = { ...baseParams, memory_types: types }; log.info(`${TAG} GET /api/v1/memories/search ${label}`, JSON.stringify(p)); const r = await request(cfg, "GET", "/api/v1/memories/search", p); log.info(`${TAG} GET response ${label}`, JSON.stringify(r)); return r; }), ``` Each complete saved message payload is also logged: ```js // Send sequentially to preserve message order on the backend for (const payload of payloads) { log.info(`${TAG} POST /api/v1/memories`, JSON.stringify(payload)); const result = await request(cfg, "POST", "/api/v1/memories", payload); log.info(`${TAG} POST response`, JSON.stringify(result)); } ``` ### Technical Analysis The logged search parameters contain the current user query, `user_id`, `group_id`, retrieval settings, and memory types. The POST payload contains full user or assistant message content, sender identifiers, group identifiers, timestamps, and deterministic message IDs. Complete search responses can contain profiles, episodic memories, agent cases, and skills. No redaction, sensitivity classification, debug-level gate, or opt-in mechanism is applied. Persistent memory systems are especially likely to process private preferences, proprietary project information, personal data, credentials accidentally pasted into chat, and other sensitive material. Logs commonly have different access controls and retention policies from the primary memory database. This creates a second, less controlled copy of the same sensitive information. ### Attack Path 1. A user sends private or secret-bearing content in a normal conversation. 2. The plugin prepares the message for automatic persistence. 3. `saveMemo ...[truncated 850 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/config.js:5
Finding

Automatic Conversation Export Allows Arbitrary and Plaintext Backend URLs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:140
Finding

Preferred Installation Executes an Unpinned Registry Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (44)

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The README explicitly instructs curl -LsSf https://astral.sh/uv/install.sh | sh, which chains network retrieval directly into shell execution. This is dangerous because any compromise of the hosting domain, CDN, TLS interception point, or upstream script would result in arbitrary command execution on the user's machine.

Content

Scanner excerpt · README.md (reported line 70)May include surrounding context.

md
git clone https://github.com/EverMind-AI/EverMemOS.git
cd EverMemOS
docker compose up -d
curl -LsSf https://astral.sh/uv/install.sh | sh
uv sync
cp env.template .env
# edit .env

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The | sh construct chains network retrieval directly into shell execution, creating a high-risk remote code execution pathway. In this skill context, where users are being guided through installation, the likelihood of blind copy-paste is high, so a compromise of the remote script source would immediately compromise the host system.

Content

Scanner excerpt · README.zh.md (reported line 70)May include surrounding context.

md
git clone https://github.com/EverMind-AI/EverMemOS.git
cd EverMemOS
docker compose up -d
curl -LsSf https://astral.sh/uv/install.sh | sh
uv sync
cp env.template .env
# 编辑 .env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 72)May include surrounding context.

docker compose up -d curl -LsSf https://astral.sh/uv/install.sh | sh uv sync cp env.template .env

编辑 .env

uv run python src/run.py

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 73)May include surrounding context.

docker compose up -d curl -LsSf https://astral.sh/uv/install.sh | sh uv sync cp env.template .env

编辑 .env

uv run python src/run.py

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh.md (reported line 72)May include surrounding context.

docker compose up -d curl -LsSf https://astral.sh/uv/install.sh | sh uv sync cp env.template .env

编辑 .env

uv run python src/run.py

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh.md (reported line 73)May include surrounding context.

docker compose up -d curl -LsSf https://astral.sh/uv/install.sh | sh uv sync cp env.template .env

编辑 .env

uv run python src/run.py

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

docker compose up -d curl -LsSf https://astral.sh/uv/install.sh | sh uv sync cp env.template .env

编辑 .env

uv run python src/run.py

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

docker compose up -d curl -LsSf https://astral.sh/uv/install.sh | sh uv sync cp env.template .env

编辑 .env

uv run python src/run.py

text

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description says this skill installs and configures EverOS for OpenClaw memory. However, the provided code only acts as a plugin entry point: it loads plugin metadata, logs registration, and calls api.registerContextEngine to register the EverOS backend. That aligns with enabling/integrating a memory backend, but not with actually installing or configuring software. Because the primary described action is installation/setup while the observable behavior is plugin registration, this is a material description-versus-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says this skill installs and configures EverOS for OpenClaw memory. However, the supplied code does not perform installation, setup, enablement, or configuration tasks. Instead, it implements operational memory-service client functions: searching memories by type and saving chat messages as memory records through HTTP requests to backend API endpoints. This is a materially different primary purpose from installation/configuration. The code also handles and transmits user/assistant message content, user/group identifiers, and flush behavior to a remote service, which is a meaningful capability absent from the description and inconsistent with the empty declared permissions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says this skill installs/configures EverOS for OpenClaw memory. The supplied code does not install, configure, enable, or manage any plugin or memory system. Instead, it is a utility module that transforms message objects: it strips context markers from user text, caps message length, drops unsupported roles, flattens block content, and summarizes tool calls. That is a materially different primary purpose from installation/setup, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims this skill is for installing and configuring EverOS, triggered by phrases like 'install everos' or 'setup everos.' The supplied code does not perform installation or setup tasks such as downloading packages, modifying configuration files, enabling plugins, or provisioning services. Instead, it is the core runtime engine for an already-installed memory system: it bootstraps sessions, calls a backend /health endpoint, tracks session state, saves messages via saveMemories, retrieves contextual memories through an assembler, injects them as system messages, and manages subagent-related context. This is a materially different primary purpose from installation/configuration, so the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is about installing and configuring EverOS memory functionality for OpenClaw. The supplied code does not perform installation, configuration, plugin enablement, memory management, or any EverOS/OpenClaw setup actions. Instead, it implements a helper to flatten text content and a detector for a specific session-reset prompt based on edit distance. This is a materially different primary purpose and appears unrelated to the declared installation/setup behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill installs and configures EverOS, implying setup or system/plugin installation behavior. The supplied code does not perform installation, configuration, plugin enablement, or environment changes. Instead, it is purely prompt/memory-processing logic: it parses returned memory search data, selects/filter memories by type and score, formats timestamps, and generates an XML-like memory section plus guidance text for an LLM prompt. This is a materially different primary purpose from installation/configuration, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill installs and configures EverOS for OpenClaw memory, implying setup actions. The code shown instead is a runtime retrieval component: it calls searchMemories with query/user/group parameters, parses the response, counts memories, and builds a memory prompt string. It also has a separate path for subagent context assembly. There is no code for installation, plugin setup, enabling memory, modifying system configuration, or handling setup triggers. This is a material description-behavior mismatch because the primary purpose is memory retrieval/context assembly, not installation/configuration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description says this skill installs and configures EverOS for OpenClaw memory features. The supplied code does not install, configure, or enable anything; it only provides an in-memory tracker for subagent lifecycle state and cleanup, plus logging. While subagent tracking may be a supporting internal component of a memory system, this chunk’s primary behavior is materially different from the declared install/setup purpose, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The use of curl ... | sh creates an immediate command-execution chain from untrusted network content to the local shell, bypassing review and integrity checks. In the context of a skill that may automate shell actions, this materially increases the chance of remote code execution if the fetched script is malicious or tampered with.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

md
git clone https://github.com/EverMind-AI/EverMemOS.git
cd EverMemOS
docker compose up -d
curl -LsSf https://astral.sh/uv/install.sh | sh
uv sync
cp env.template .env
# edit .env

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.

md
| GET | `/health` | Health check |
| POST | `/api/v1/memories` | Save memory |
| GET | `/api/v1/memories/search` | Search memory |
| DELETE | `/api/v1/memories` | Delete memory |

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises automatic saving of conversation content after each turn but does not clearly warn users that their prompts and responses will be persisted and transmitted to a backend. In a memory plugin context, this can lead to unintended storage of sensitive personal, operational, or confidential data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to execute an unpinned package via npx, which fetches and runs the latest published installer code at execution time. If the package is compromised, typosquatted, or a malicious update is published, users could execute arbitrary code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The installer changes an existing OpenClaw configuration and disables the memory slot by setting plugins.slots.memory = "none", but the README does not present this as a prominent warning before execution. Silent or under-emphasized configuration changes can disrupt existing security controls, workflows, or expected memory behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 61)May include surrounding context.

Health check:

bash
curl http://localhost:1995/health

If you have not started the EverOS backend yet:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that each conversation turn is automatically saved to the backend, but it does not foreground the privacy and data-retention implications before users enable it. Because this plugin handles natural-language memory, it is likely to collect sensitive personal or organizational information, making silent persistence materially risky in this context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README recommends executing an unpinned package directly with npx, which fetches whatever version is current at execution time. This creates a supply-chain risk: a compromised publisher account, malicious new release, or dependency hijack could cause arbitrary code to run on the user's system during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The installation steps automatically modify OpenClaw configuration, enable this plugin, and disable the existing memory slot without a clear up-front warning. Unexpected configuration changes can break existing setups, alter security/privacy posture, or silently replace another memory mechanism with different trust assumptions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
bin/install.js:217

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
bin/install.js:17