Back to skill

Security audit

BenOS Memory Core

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed BenOS memory reader for fixed runtime files, with privacy and scoping caveats but no evidence of hidden execution, exfiltration, or destructive behavior.

Install only if you want agents using this skill to read BenOS runtime memory, including prior-session text. Treat the runtime files as potentially sensitive, and prefer trusted callers or wrapper controls if you need per-agent authorization or redaction.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
index.js:24
Finding

Unrestricted Disclosure of Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: index.js, lines 24-40
Vulnerability Type: Missing authorization for access to persistent session data
Risk Level: Medium

js
async hydrate(ctx) {
  try {
    const state = fs.existsSync(statePath)
      ? JSON.parse(fs.readFileSync(statePath, 'utf8'))
      : {};

    const last = fs.existsSync(lastPath)
      ? fs.readFileSync(lastPath, 'utf8')
      : "";

    return {
      ok: true,
      hydration: {
        lastSession: last,
        state
      }
    };

Technical Analysis

The exported hydrate(ctx) method reads and returns the complete contents of the persistent state.json and last-session.md files. Although the method accepts a context object, it does not inspect ctx, authenticate the caller, verify authorization scopes, request consent, or restrict the returned fields.

These files are intended to contain runtime state, prior-session text, notes, decisions, open loops, and session references. Consequently, any component that can invoke this native skill method receives all stored information rather than a minimal, purpose-specific subset.

The file paths are fixed beneath the current user's home directory, so this issue does not provide arbitrary-file-read capability by itself. It also does not elevate operating-system privileges. The vulnerability is an access-control failure within the agent environment: callers with permission to invoke the skill may cross the intended confidentiality boundary around persistent agent memory.

Attack Path

  1. An untrusted, compromised, or insufficiently privileged agent component obtains the ability to invoke the native skill.
  2. The component calls the exported hydrate() method without needing to provide credentials or an authorized scope in ctx.
  3. The method reads ~/.openclaw/workspace/benos/runtime/state.json and ~/.openclaw/workspace/benos/runtime/last-session.md using the ...[truncated 971 chars]
Remediation
View remediation

Remediation Suggestions

  1. Enforce caller authentication and authorization through ctx before reading either file. Reject calls lacking a trusted identity and an explicit memory-read scope.
  2. Define granular permissions, such as separate scopes for current state, historical session text, notes, and decisions.
  3. Return only fields required for the caller's declared operation instead of returning the complete files.
  4. Redact secrets, credentials, tokens, personal data, and other sensitive values before constructing the response.
  5. Consider denying access to last-session.md by default and requiring explicit user consent for historical-session retrieval.
  6. Validate the size and schema of stored data before parsing or returning it, and impose response-size limits.
  7. Add privacy-preserving audit logs recording the caller identity, requested scope, timestamp, and result without recording sensitive memory contents.
  8. Add tests confirming that anonymous callers, unauthorized roles, and callers with insufficient scopes cannot retrieve persistent memory.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes capabilities to read and write runtime state and references filesystem locations, but it does not declare any explicit tool scope or permissions boundary. In an agent environment, undeclared access to environment/filesystem-related capabilities increases the chance of overbroad authority, unintended state tampering, or misuse by downstream components that assume the skill is read-only or narrowly scoped.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill explicitly says files may be edited directly for manual repairs or migration, but the description does not prominently warn that this can modify active runtime state. That omission can cause operators or agents to treat the skill as a harmless memory interface, increasing the risk of accidental corruption, persistence of bad state, or unsafe manual edits during live sessions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.