Back to skill

Security audit

Team Shared Memory

Security checks for vulnerabilities and agentic risk

Overview

This is a local shared-memory sync skill that can overwrite shared memory files, but that behavior is disclosed and fits its stated purpose.

Install only if you want project/reference memories shared across OpenClaw agents or workspaces. Avoid putting secrets, regulated data, or private notes in shared memory folders, and keep backups of important memory files because sync conflicts can overwrite content.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.