Back to skill

Security audit

QMD Memory

Security checks for vulnerabilities and agentic risk

Overview

The skill’s memory-search purpose is coherent, but setup installs mutable global third-party code and indexes local OpenClaw workspace data with limited upfront control.

Review this before installing if you are sensitive to local workspace indexing, background services, or supply-chain risk. Run setup only as a normal user, avoid sudo, confirm you are comfortable with QMD being installed globally and downloading about 2GB of models, and inspect or disable any QMD daemon or scheduled refresh behavior you do not want.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:16
Finding

Unpinned Global npm Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.sh, lines 16-20
Vulnerability Type: Unpinned third-party package installation with npm lifecycle-script execution
Risk Level: Medium

Vulnerable Code

bash
# Check if QMD is installed
if ! command -v qmd &> /dev/null; then
    echo "📦 Installing QMD..."
    npm install -g @tobilu/qmd
    echo "✅ QMD installed"

Technical Analysis

The setup process globally installs @tobilu/qmd without specifying an exact version or verifying package integrity. As a result, npm resolves a mutable package release at installation time rather than a version reviewed alongside this skill.

npm packages may execute lifecycle scripts during installation. If the package, a transitive dependency, or its publishing account is compromised, running this setup script could execute attacker-controlled code with the privileges of the user invoking the skill. The global installation scope also modifies user- or system-level tooling outside the project directory.

This is a supply-chain weakness; the audited repository does not itself contain evidence that the current QMD package is malicious.

Attack Path

  1. An attacker compromises the @tobilu/qmd publication process, its registry account, or a dependency resolved by the package.
  2. The attacker publishes a malicious version that is selected by npm's unpinned resolution.
  3. A user without an existing qmd executable runs the skill's setup command.
  4. npm install -g @tobilu/qmd downloads the mutable release and its dependency tree.
  5. Malicious package code or lifecycle scripts execute with the invoking user's privileges.
  6. The installed program may subsequently access files indexed by the skill, including workspace memory and agent configuration documents.

Impact Assessment

Successful exploitation can provide arbitrary code execution under the account running the setup command. This may ...[truncated 312 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin QMD to a reviewed exact version, for example:
    bash
    npm install -g --ignore-scripts @tobilu/qmd@<reviewed-exact-version>
    
    Use --ignore-scripts only after confirming QMD does not legitimately require lifecycle scripts.
  2. Verify the selected package artifact against a trusted integrity hash or approved lockfile before installation.
  3. Prefer a project-local dependency installed from a committed lockfile with npm ci rather than modifying global tooling.
  4. Review and pin transitive dependencies through a reproducible dependency manifest.
  5. Execute installation without root privileges and document that users must not invoke setup through sudo.
  6. Consider requiring explicit user confirmation before downloading and installing executable third-party code.
  7. Regularly audit the pinned dependency and update it only after reviewing release provenance, lifecycle scripts, and security advisories.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README markets the skill as low-cost and easy to use, but it does not clearly warn users that first use auto-downloads roughly 2GB of models and that nightly automatic index updates can modify local state. This can lead users to install and run the skill without informed consent about network activity, disk usage, background processing, and changes to local indexed data, which is a meaningful safety and transparency issue for an agent skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly advertises that setup installs QMD, configures collections, and sets up cron jobs, but it does not present these system-modifying actions as clear upfront warnings requiring explicit user awareness or consent. This is dangerous because users may run setup expecting a simple local enhancement while unintentionally altering indexed data sources and persistence behavior on their machine, including scheduled background tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill notes auto-downloaded models and lists their sizes, but it does not frame this as a clear operational warning before setup, despite a multi-gigabyte download and storage impact. This can surprise users on constrained systems, cause failed installs, or consume significant disk/bandwidth without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.