Back to skill

Security audit

Aura for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local document-indexing and persistent-memory tool, but it needs Review because it can persist agent memory, index broad local folders, and relies on unpinned external code with limited safeguards.

Install only if you want an agent to maintain durable local memory and compile selected folders into searchable archives. Use a virtual environment, pin and review the auralith-aura dependency, avoid indexing secrets or highly sensitive folders unless intended, periodically inspect or delete ~/.aura/memory/, and require explicit confirmation in your workflow before persistent fact writes, broad directory compilation, or pruning.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party Dependency Executes Outside the Audited Codebase

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-26; duplicated in README.md, lines 84-88
Vulnerability Type: Supply-chain risk caused by an unpinned dependency
Risk Level: Medium

Complete Code Snippet

bash
pip install auralith-aura

For full document support:

bash
pip install 'auralith-aura[all]'

Technical Analysis

The installation instructions retrieve the latest available version of auralith-aura and its transitive dependencies without an exact version constraint or integrity hash. The bundled scripts then delegate their substantive operations to modules supplied by that package:

  • aura.compiler processes user-selected directories.
  • aura.rag parses and searches .aura archives.
  • aura.memory reads and writes persistent agent memory.

Because this external package is outside the audited project, the bundled source cannot independently guarantee that dependency versions will continue to honor the documented claims of local-only processing, no telemetry, and no external requests. The issue does not prove that the current package is malicious; it establishes that installation and subsequent execution are not reproducible or cryptographically bound to an audited release.

Attack Path

  1. An attacker compromises a future package release, a maintainer account, or a transitive dependency.
  2. A user follows the documented unpinned pip install command.
  3. The package manager selects the compromised or unexpectedly changed release.
  4. Package-controlled installation or runtime code executes with the user's privileges.
  5. The Skill imports the package and supplies it with user-selected documents, archives, and persistent memory.
  6. Malicious dependency code could read, alter, destroy, or transmit data accessible to the current user.

Impact Assessment

Exploitation would execute code with the privileges of the account running pip or the Skill. T ...[truncated 365 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact, reviewed version, for example auralith-aura==X.Y.Z.
  2. Publish a lock file that fixes every transitive dependency version.
  3. Provide verified package hashes and install with pip --require-hashes.
  4. Prefer installation in an isolated virtual environment under an unprivileged account.
  5. Audit the selected dependency release and its transitive dependency graph before publishing the Skill.
  6. Document clearly that local-processing guarantees depend on the behavior of the externally installed package.
  7. Add automated dependency scanning, provenance verification, and controlled update review to the release process.

T02 · Agent Memory Poisoning

Warning
Location
scripts/memory.py:60
Finding

Caller-Controlled Persistent Memory Supports Forged Provenance

Content
View full analysis

Vulnerability Details

File Location: scripts/memory.py, lines 60-65 and 96-102
Vulnerability Type: Persistent agent-memory poisoning and provenance spoofing
Risk Level: Medium

Complete Code Snippet

python
write_parser.add_argument('namespace', choices=['pad', 'episodic', 'fact'],
                         help='Memory namespace')
write_parser.add_argument('content', type=str, help='Content to remember')
write_parser.add_argument('--source', type=str, default='agent',
                         help='Source of the memory (default: agent)')
write_parser.add_argument('--tags', type=str, nargs='*', default=[],
                         help='Optional tags for classification')
python
if args.action == 'write':
    entry = memory.write(
        namespace=args.namespace,
        content=args.content,
        source=args.source,
        tags=args.tags
    )
    print(f"✅ Written to /{args.namespace}: {entry.entry_id}")

Technical Analysis

The write command accepts arbitrary memory content and permits the caller to select the persistent fact namespace. It also accepts any string through --source and passes that string directly to memory.write() without authentication, validation, or an allowlist.

Consequently, a caller can label attacker-controlled content with trusted-looking provenance such as system, user, or another authoritative identity. The Skill documentation states that facts persist across sessions and that stored provenance is used to indicate the origin of an entry. Allowing the same caller who supplies the content to assert its provenance defeats that trust property.

The wrapper also has no confirmation step for durable facts, no trust-level metadata distinct from the displayable source, and no filtering that separates factual content from instruction-like text. If later agent behavior treats retrieved memories as trusted context, a poisoned entry may c ...[truncated 1575 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove caller control over provenance and derive source from authenticated host-agent context.
  2. If a source argument must remain available, enforce a strict allowlist and map untrusted CLI writes to a value such as external-unverified.
  3. Require explicit user confirmation before writing to the persistent fact namespace.
  4. Store immutable trust metadata separately from caller-controlled labels and tags.
  5. Mark all retrieved memory as untrusted data and prevent it from overriding system instructions or authorization policy.
  6. Detect or quarantine instruction-like content before promoting entries to durable facts.
  7. Record an append-only audit trail containing the actual invoking identity, session, timestamp, and promotion history.
  8. Provide review, correction, expiration, and deletion controls for individual entries rather than relying only on shard-level pruning.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

You: How does the auth middleware handle token refresh? Agent: Based on src/middleware/auth.ts (lines 45-89), the auth middleware intercepts expired JWTs by checking the exp claim. When expired, it calls refreshTokenService.rotate() which issues a new access token and sets it via the X-Refreshed-Token response header. The original request is then replayed with the new token.

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README prominently encourages indefinite persistence of facts, preferences, decisions, transcripts, and compiled documents, but does not warn users that this may include sensitive personal, legal, or confidential data retained across sessions. In an agent skill context, users may reasonably treat examples as safe defaults, so omitting retention/privacy cautions increases the risk of over-collection and long-term storage of sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The examples explicitly tell the agent to ingest an entire legal folder and remember user attributes like timezone, which normalizes collection of potentially sensitive or regulated data without any cautionary guidance. Because this is a skill README guiding operational use, these examples can directly lead users to store confidential documents and personal data indefinitely or more broadly than intended.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The examples explicitly encourage storing and later reusing sensitive operational details such as production regions, API key rotation practices, and user preferences across sessions. Even if no secret value is stored, persistent retention of operational security details expands the blast radius of compromise, enables profiling, and normalizes cross-session handling of potentially sensitive data without clear minimization or consent controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to act on broad trigger phrases like "learn," "compile," "index," or "remember" when pointed at a directory, which can cause the skill to activate in situations the user did not intend as a storage or indexing operation. In a skill that can ingest large local directories and persist their contents, ambiguous activation increases the chance of over-collection of sensitive local data and unintended persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The autonomous invocation note says the agent decides when to compile documents and manage memory during normal operation, but it does not define strict activation criteria, approval requirements, or limits on what may be persisted. That lack of boundaries is risky because the skill handles durable memory and filesystem content, so an agent could store sensitive user data across sessions without sufficiently informed consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/memory.py (reported line 5)May include surrounding context.

python
"""Aura Memory Management Script for OpenClaw Integration.

Provides memory lifecycle commands for AI agents:
  - Write to memory tiers (/pad, /episodic, /fact)
  - List compiled memory shards  
  - Prune old/unwanted memories
  - Show storage usage

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The prune command performs deletion via memory.prune_shards for either a date range or a specific shard ID, but there is no confirmation prompt or explicit warning at execution time. Although the module docstring mentions pruning old memories, the destructive action itself is not accompanied by a visible safety disclosure when invoked.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module docstring lists the provided lifecycle commands and usage examples, but it does not mention the implemented query command even though the code exposes a search capability at L84-L90 and executes it at L127-L141. Because the documentation presents itself as the script's command inventory, this is an intent/documentation mismatch rather than a mere low-level omission.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.