Back to skill

Security audit

Context Shrink

Security checks for vulnerabilities and agentic risk

Overview

This hook is a Review case because it can automatically rewrite and delete memory files and create broad Git commits without clear user control.

Install only if you are comfortable with an automatic hook managing your OpenClaw memory files and local Git history. Before enabling it, require explicit opt-in or dry-run behavior, path-limited Git staging, safe non-shell Git execution, validated backups or archive-before-delete, consistent trigger documentation, and no automatic push unless deliberately configured.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
handler.ts:139
Finding

Latent Shell Command Injection Through an Unvalidated Workspace Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
handler.ts:105
Finding

Non-Transactional and Lossy Deletion of Memory Files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
handler.ts:137
Finding

Automatic Git Commit Stages Unrelated Workspace Changes

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose sounds like benign context compression, but the documented behavior includes deleting files, rewriting MEMORY.md, and running git commands. This mismatch is dangerous because users may install or approve the skill expecting summarization only, while the hook can automatically perform destructive state changes and persist them via version control.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill overwrites MEMORY.md and deletes files automatically without prior confirmation, backup, or clear user-facing warning. Because this skill operates on accumulated user memory, silent destructive actions are especially dangerous and can erase important context or sensitive evidence with little chance of recovery.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill automatically deletes memory files and rewrites repository state by appending to MEMORY.md and then committing the changes. In a context-management skill, destructive deletion without an explicit safety boundary, dry-run mode, or user approval can cause irreversible loss of user data and unexpected repository mutation beyond simple 'compression'.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The handler invokes shell-based git commands through execSync, which expands the skill's privileges from memory compression into arbitrary repository mutation. Even if the command strings are mostly fixed, this behavior can create unintended commits, alter audit history, and increases risk if workspaceDir is influenced by untrusted context or points to an unexpected location.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented trigger threshold conflicts with the stated skill metadata: the manifest says compression should occur only above 85%, while this hook documentation says cleanup starts above 60%. This mismatch is dangerous because it changes when destructive behavior activates, making data deletion/compression occur much earlier than users or reviewers would expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents automatic deletion of memory files and git push behavior without prominent warning or consent for modification and remote transmission. In this context, that is dangerous because the hook runs on routine events and may silently alter or exfiltrate sensitive conversational history to a repository.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The hook description expands beyond passive context shrinking into deletion of memory files and automatic git commit/push. That is materially broader than the declared purpose and introduces destructive local changes plus potential remote data transmission, which can surprise users and bypass expected consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states the hook executes silently and only logs output, reducing user awareness of destructive cleanup and repository operations. Silent execution makes the behavior more dangerous in this skill context because it can delete memory and transmit data without timely human review or intervention.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation indicates behavior requiring environment and likely broader execution capabilities, but it declares no explicit tool scope or permissions. In a hook that can run automatically, undeclared capability use is dangerous because it hides the true trust boundary and can enable filesystem, environment, or command access without clear user consent or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation describes cleanup and compression behavior without a clear warning that stored data may be modified, deleted, and committed automatically. In an auto-triggered hook, lack of disclosure is dangerous because users may expose important notes or lose data without realizing the skill performs destructive and persistent actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file's comments, status messages, and user-facing strings are written in Chinese, and the skill does not indicate that language selection is configurable or intentionally region-specific. This can violate a language/locale policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The docstring claims the handler listens for both message:sent and command:reset events, but the code first returns unless type is 'message' with action 'sent' or 'received', and then immediately returns unless type is 'command' with action 'reset'. Because both conditions cannot be true in one event, the implementation contradicts the documented trigger behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

When no workspace is provided, the code falls back to process.env.HOME to locate and operate on a default workspace. Accessing environment-derived global paths is broader than the manifest's narrow purpose of compressing session memories and can redirect operations beyond the immediate session context.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill reads historical memory files, extracts selected lines, and appends them into MEMORY.md in plain text, potentially concentrating sensitive information into a more visible, durable file. In a memory-management context this is particularly risky because the deleted source material may contain credentials, personal data, or prior confidential prompts that are then preserved in summarized form.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill runs git add and git commit automatically with no warning or consent, causing silent side effects outside the core compression task. In an agent setting, automatic shell-triggered repository actions can surprise users, capture unintended files, and complicate recovery or forensic review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes the skill as automatically compressing session memories when context usage exceeds 60%, but it does not specify what event or platform condition actually invokes the hook, nor any exclusions or negative cases. For a manifest file, this broad automatic behavior can lead to unclear or unintended activation because the trigger scope is not explicitly defined.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language description is written in Chinese and the document continues primarily in Chinese, with no indication that users may choose another language or that the skill is intentionally region-specific. This can violate language/locale policy when a skill effectively constrains interaction language without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description at L04 and feature list at L17 say the hook runs when context usage exceeds or reaches 85%, but the prose at L13 says it triggers at a 60% threshold. This is an active contradiction in the skill's own documentation about core behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file presents key operational details in Chinese while other parts are in English, which imposes a language assumption without explicitly offering a user choice or documenting a locale-specific requirement. This can violate language/locale policy when users are not given opt-in or an alternative language path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill manifest context says the skill should auto-compress session memories when context usage exceeds 85%, but package.json describes the behavior as triggering when usage exceeds 60%. This is a direct description-level mismatch about when the skill acts, which changes the intended scope of behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
handler.ts:145