Back to skill

Security audit

Agent Memory Setup v2 (Gemini Embeddings 2)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, user-directed memory setup guide and script with disclosed cloud embedding behavior, though users should review its optional third-party plugin and documentation mismatch before use.

Before installing, confirm you are comfortable with memory file contents being sent to Google Gemini if semantic search is enabled, use this only in the intended agent workspace, and separately review or pin the optional third-party Lossless Claw plugin before installing it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:74
Finding

Unpinned Third-Party Plugin Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 74-76
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

markdown
**Lossless Claw** (`@martian-engineering/lossless-claw`) — compacts old context into
expandable summaries to prevent amnesia. Install separately:
`openclaw plugins install @martian-engineering/lossless-claw`

Technical Analysis

The documented installation command does not specify an exact package version, trusted artifact digest, or signature. Consequently, users following this instruction may install whichever package version is current at installation time rather than the version represented during this audit.

This creates a supply-chain risk: compromise of the package publisher, registry account, publication process, or a later malicious release could cause the OpenClaw plugin manager to install code that has not been reviewed. The plugin is explicitly optional and is not installed by scripts/setup_memory_v2.sh, so exploitation requires a user or administrator to follow the separate installation instruction.

Attack Path

  1. An attacker compromises the package publisher account, registry publication channel, or upstream release process.
  2. The attacker publishes a malicious version under @martian-engineering/lossless-claw.
  3. A user follows the unpinned command in SKILL.md.
  4. The plugin manager resolves and installs the attacker-controlled release.
  5. OpenClaw loads the plugin, allowing its code to execute within the permissions and environment of the OpenClaw process.

Impact Assessment

Successful exploitation could grant malicious plugin code the same privileges as the OpenClaw process. Depending on that process's configuration, the plugin could access or modify agent memory, alter agent behavior, read environment-accessible credentials, or communicate with external systems. The exact scope is limited by the operat ...[truncated 274 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the plugin to an exact, reviewed version rather than resolving the latest available release.
  • Use an integrity digest, cryptographic signature, or lockfile where supported by the OpenClaw plugin manager.
  • Document the authoritative package registry and source repository so users can verify package provenance.
  • Review the plugin's source and release artifacts before installation and before intentional upgrades.
  • Run OpenClaw with least privilege, restrict unnecessary network access, and expose only required credentials and files.
  • Keep the plugin explicitly optional and warn users that third-party plugin code executes with the OpenClaw process's permissions.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill’s declared behavior materially overstates what it actually sets up: it claims a 3-tier HOT/WARM/COLD memory system and Gemini-based memory configuration, but the content only provides manual instructions and appears inconsistent about the COLD tier. In security terms, this can mislead operators into believing semantic memory, plugin configuration, and privacy expectations are already handled, causing accidental exposure of memory contents to a cloud provider or leaving agents in a misconfigured state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough that the skill may activate in loosely related conversations about memory, onboarding, or semantic search. Unintended activation can cause users or agents to apply setup guidance in the wrong workspace, enable external-memory features without informed consent, or disclose configuration steps involving API-key handling when not appropriate.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The inline documentation at the top of the script claims it initializes a 3-tier memory structure for an OpenClaw agent. However, the implementation only creates hot and warm directories and associated files, so the comment directly overstates what the code does.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest explicitly states the skill creates a 3-tier memory directory structure consisting of HOT/WARM/COLD. In the code, only memory/hot and memory/warm are created and reported, with no corresponding creation of a cold directory or cold memory file, so the actual setup behavior does not match the described functionality.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.