Back to skill

Security audit

Smart Memory

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local memory skill, but it asks for broad control over memory routing and exposes sensitive transcript and memory data through under-protected local services and installation paths.

Install only if you are comfortable reviewing and operating a local memory service that stores transcripts and can affect future prompts. Avoid the curl-to-bash installer, keep the server bound to loopback, add authentication before any remote or shared use, do not disable built-in memory tools unless you understand the rollback path, and treat stored/retrieved memories as untrusted data.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (8)

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:1
Finding

Mutable Remote Installer Is Piped Directly into a Shell

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:47
Finding

Installer Executes Unpinned Repository and Dependency Lifecycle Code

Content
View full analysis
/dev/null 2>&1; then cd /tmp rm -rf smart-memory-temp 2>/dev/null || true git clone --depth 1 "$REPO_URL.git" smart-memory-temp cp -r smart-memory-temp/* "$TARGET_DIR/" rm -rf smart-memory-temp else cd /tmp rm -rf smart-memory-master 2>/dev/null || true curl -L "$REPO_URL/archive/refs/heads/master.tar.gz" | tar xz cp -r smart-memory-master/* "$TARGET_DIR/" rm -rf smart-memory-master fi cd "$TARGET_DIR/smart-memory" npm install --silent ``` ```json "scripts": { "postinstall": "node postinstall.js" } ``` ```javascript runCommand(venvPython, ['-m', 'pip', 'install', '--upgrade', 'pip'], 'Upgrading pip'); runCommand( venvPython, [ '-m', 'pip', 'install', 'torch', 'torchvision', 'torchaudio', '--index-url', 'https://download.pytorch.org/whl/cpu', ], 'Installing CPU-only PyTorch' ); runCommand( venvPython, ['-m', 'pip', 'install', '-r', requirementsPath], 'Installing cognitive requirements' ); ``` ```text pydantic>=2,<3 numpy>=1.26 pytest>=8,<10 sentence-transformers>=3,<4 einops>=0.8.0 qdrant-client>=1.9 fastapi>=0.115,<1 uvicorn>=0.30,<1 ``` ### Technical Analysis The installer retrieves the latest state of a mutable repository branch and immediately invokes `npm install`. The package defines a `postinstall` lifecycle hook that creates a Python environment, upgrades pip, and installs multiple packages from remote indexes. Most Python dependencies use broad version ranges rather than exact versions, ...[truncated 1298 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
skills/smart-memory-openclaw/SKILL.md:34
Finding

Setup Instructions Disable Competing Built-In Memory Tools

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
prompt_engine/prompt_renderer.py:146
Finding

Attacker-Controlled Persistent Memory Is Injected into Privileged Prompt Context

Content
View full analysis
", "", "[AGENT IDENTITY]", identity_text or "N/A", "", "[TEMPORAL STATE]", temporal_text or "N/A", "", ] if core_lines: parts.extend(["[CORE MEMORY]", "", "\n".join(core_lines), ""]) parts.extend(["[WORKING CONTEXT]", working_context, "", "", ""]) if insight_lines: parts.extend([ "[BACKGROUND INSIGHTS]", "The following insights were generated during background reflection cycles.", "", "\n".join(insight_lines), "", ]) if retrieved_lines: parts.extend(["[RETRIEVED MEMORY]", "", "\n".join(retrieved_lines), ""]) ``` ```javascript const contextBlock = formatActiveContextBlock({ status: resolvedHotMemory.agent_state?.status || compose?.interaction_state || "idle", activeProjects: resolvedHotMemory.active_projects || [], workingQuestions: resolvedHotMemory.working_questions || [], topOfMind: resolvedHotMemory.top_of_mind || [], pendingInsights: insights, }); const baseSystemPrompt = String(params.baseSystemPrompt || "").trim(); const mergedPrompt = [ baseSystemPrompt, "", contextBlock, "", `Prompt Guidance: ${PENDING_INSIGHT_PROMPT_GUIDANCE}`, ] .filter(Boolean) .join("\n"); ``` ```javascript const insightLines = (Array.isArray(input.pendingInsights) ? input.pendingInsights : []) .map((insight) => String(insight.content || "").trim()) .filter(Boolean) .map((line) => `- ${line}`); ``` ### Technical Analysis Memory and insight content can originate from user messages, explicit commits, transcript derivation, and session summaries. That content is rendered verbatim into `[CORE MEMORY]`, `[WO ...[truncated 1789 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
server.py:94
Finding

Memory and Transcript API Exposes Unauthenticated Read and Mutation Endpoints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smart-memory-openclaw/retry-queue.js:115
Finding

Failed Memory Commits Are Persisted in an Unprotected Plaintext Retry File

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools/session-prime.py:47
Finding

Session Startup Utility Builds a Shell Command from Filesystem Paths

Content
View full analysis
/tmp/smart-memory-server.log 2>&1 &" subprocess.Popen(cmd, shell=True) ``` ### Technical Analysis The utility interpolates the resolved `base` path into a shell command without quoting and executes it with `shell=True`. Shell metacharacters contained in the filesystem path are interpreted as shell syntax rather than as part of a path. The path is derived from the current directory, parent directory, `./skills`, or the user's home workspace. An attacker who can influence one of those path names and provide the expected `smart-memory` files can cause arbitrary shell syntax to execute when the health check fails and the startup path is selected. Sourcing the activation script is unnecessary because the utility can invoke the virtual environment's Python executable directly. ### Attack Path 1. An attacker creates or induces use of a directory whose resolved name contains shell metacharacters. 2. The directory contains the expected `.venv/bin/activate` and `server.py` paths. 3. The target memory server is unavailable, causing `ensure_server_running` to attempt startup. 4. The unquoted path is interpolated into `cmd`. 5. `subprocess.Popen(..., shell=True)` passes the command to the shell. 6. The shell interprets the embedded metacharacters and executes attacker-selected commands. ### Impact Assessment Successful exploitation executes arbitrary commands with the privileges of ...[truncated 255 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/smart-memory-openclaw/http-client.js:52
Finding

Configurable Plaintext Server Endpoints Can Receive Sensitive Conversation Data

Content
View full analysis
controller.abort(), this.timeoutMs); const headers = {}; const init = { method, signal: controller.signal, headers, }; if (payload !== undefined) { headers["content-type"] = "application/json"; init.body = JSON.stringify(payload); } try { const response = await this.fetchImpl(buildUrl(this.baseUrl, endpoint), init); ... } finally { clearTimeout(timeout); } } ``` ### Technical Analysis The default endpoint is loopback, and the audit found no hard-coded third-party exfiltration destination. However, bot ...[truncated 1644 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (148)

Known Vulnerable Dependency: torch==2.5.1+cpu — 16 advisory(ies): CVE-2025-2953 (PyTorch susceptible to local Denial of Service); CVE-2025-32434 (PyTorch: `torch.load` with `weights_only=True` leads to remote code execution); CVE-2025-3730 (PyTorch Improper Resource Shutdown or Release vulnerability) +13 more

Critical
Category
Supply Chain
Confidence
94% confidence
Finding

The manifest pins torch==2.5.1+cpu, and the supplied analysis indicates this exact version is affected by multiple advisories, including severe issues such as unsafe deserialization/RCE and denial of service. In a memory/embedding skill handling local transcripts and model artifacts, vulnerable PyTorch builds are more dangerous because loading untrusted model files or tensors can become a code-execution path.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 117)May include surrounding context.

md
- `GET /lanes/{lane_name}`
- `POST /lanes/{lane_name}/{memory_id}`
- `DELETE /lanes/{lane_name}/{memory_id}`
- `GET /eval/suite/{suite_name}`
- `GET /eval/case/{case_id}`

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description materially understates and mischaracterizes behavior, describing a local memory component while static analysis indicates broader cognition, orchestration, embedding, scheduling, retrieval mutation, and server/process management features. This is dangerous because reviewers and users may approve or invoke the skill under false assumptions, granting it access to sensitive transcripts and local resources without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
examples/session-start/nodejs-agent.js:49

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
smart-memory/index.js:158

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
smart-memory/postinstall.js:14

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
smart-memory/index.js:11