Back to skill

Security audit

Supermemory Free

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly backs up knowledge to Supermemory, but its optional auto-capture feature can repeatedly upload sensitive session memory with weak filtering and unsafe cron setup.

Install only if you are comfortable sending selected OpenClaw memory-log content to Supermemory.ai. Do not enable the cron job unless you have reviewed the memory directory contents and accept ongoing unattended uploads; prefer dry-run/manual storage. Treat the .env sourcing and weak redaction as risks, and avoid using this with secrets, credentials, private customer data, or regulated information in session memory.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
auto_capture.py:52
Finding

Automatic Capture Can Upload Credentials and Sensitive Session Data Without Effective Redaction

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
install_cron.sh:53
Finding

Installer Creates Persistent Unattended Session-Memory Collection Through Cron

Content
View full analysis
> $LOG_FILE 2>&1 # $CRON_MARKER" ``` ```bash install_cron() { check_python check_api_key # Create log dir mkdir -p "$(dirname "$LOG_FILE")" # Remove existing entry (if any) crontab -l 2>/dev/null | grep -v "$CRON_MARKER" | crontab - || true # Add new entry (crontab -l 2>/dev/null; echo "$CRON_CMD") | crontab - info "Cron job installed: $CRON_SCHEDULE (daily at 2:00 AM UTC)" echo "" echo " Command: $PYTHON $SKILL_DIR/auto_capture.py --days 3" echo " Log: $LOG_FILE" echo "" echo "Verify with: crontab -l | grep $CRON_MARKER" echo "" echo "Test run (dry): $PYTHON $SKILL_DIR/auto_capture.py --dry-run" echo "Test run (live): $PYTHON $SKILL_DIR/auto_capture.py" } ``` ### Technical Analysis The installer adds an entry to the current user's crontab that survives the Skill invocation and runs every day. The scheduled process scans three days of session-memory files and performs live cloud uploads without requiring contemporaneous confirmation. The cron feature is disclosed in `README.md`, `SKILL.md`, and `_meta.json`, is installed through an explicit command, and has a removal operation. It is therefore not hidden persistence. Nevertheless, it creates cross-session execution and materially expands the exposure window of the sensitive-data issue. Persistent scheduling is not required for the Skill's manual cloud store and search functionality and exceeds the minimum privilege necessary for those operations. The normal setup instructions encourage running the installer, while the re ...[truncated 1284 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
install_cron.sh:10
Finding

Unsafe Cron Command Construction and Shell-Sourcing of .env Enable Scheduled Command Execution

Content
View full analysis
> $LOG_FILE 2>&1 # $CRON_MARKER" ``` ```bash # Remove existing entry (if any) crontab -l 2>/dev/null | grep -v "$CRON_MARKER" | crontab - || true # Add new entry (crontab -l 2>/dev/null; echo "$CRON_CMD") | crontab - ``` ### Technical Analysis The script constructs a cron command by directly interpolating `PYTHON`, `WORKSPACE_DIR`, `SKILL_DIR`, and `LOG_FILE` into shell syntax without shell-quoting them. `PYTHON` is directly influenced by the invoking environment. A value containing spaces or shell metacharacters can alter the scheduled command instead of identifying only a Python executable. Paths are also unquoted in the generated cron command. A workspace path containing whitespace or shell-significant characters can break parsing or introduce additional shell operations. The generated command uses: ```bash source .env ``` This does not merely read the required API key. It executes the complete `.env` file as shell code on every scheduled run. Environment files are often treated as passive key-value configuration and may not be protected or reviewed as executable scripts. Any command substitution, shell operator, function definition, or command present in that file will run with the cron user's permissions. The exploitation precondition is the ability to influence the `PYTHON` environment value, a generated path, or the workspa ...[truncated 1880 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Installing and removing system cron jobs, sourcing workspace .env, and writing logs are materially different from a simple backup/retrieval utility. In context, these hidden operational behaviors increase persistence and automation risk, especially because they can continue scanning and uploading session-derived content after initial setup.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Installing and removing system cron jobs, sourcing workspace .env, and writing logs are materially different from a simple backup/retrieval utility. In context, these hidden operational behaviors increase persistence and automation risk, especially because they can continue scanning and uploading session-derived content after initial setup.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Installing and removing system cron jobs, sourcing workspace .env, and writing logs are materially different from a simple backup/retrieval utility. In context, these hidden operational behaviors increase persistence and automation risk, especially because they can continue scanning and uploading session-derived content after initial setup.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Installing and removing system cron jobs, sourcing workspace .env, and writing logs are materially different from a simple backup/retrieval utility. In context, these hidden operational behaviors increase persistence and automation risk, especially because they can continue scanning and uploading session-derived content after initial setup.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

md
| `SKILL.md` | This file |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script automatically scans session memory logs and uploads selected content to an external cloud service without an explicit runtime warning or confirmation about sensitive data transfer. Because memory logs can contain user prompts, environment details, file paths, internal notes, and possibly secrets, silent automatic transmission materially increases privacy and data-leak risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code comment says it handles only credential locations, but the actual matcher \bapi[\s_-]?key\b.{5,} can match lines containing real API key values and then upload the full line to the cloud. The skip rules only block some formats like token= and do not reliably prevent secrets embedded in prose, markdown bullets, or api key: ... lines from being exfiltrated.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The code reads .env files directly to locate SUPERMEMORY_OPENCLAW_API_KEY, which constitutes credential access from local secret storage. In a skill that already processes memory logs and performs network uploads, this combination is more dangerous because the component has both access to secrets and a ready exfiltration path.

Content

Scanner excerpt · auto_capture.py (reported line 198)May include surrounding context.

python
Path("/mnt/openclaw/openclaw/.openclaw/workspace"),
    ]
    for d in search_dirs:
        env_path = Path(d) / ".env"
        if env_path.exists():
            for line in env_path.read_text().splitlines():
                line = line.strip()

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · auto_capture.py (reported line 207)May include surrounding context.

python
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"

# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install_cron.sh (reported line 18)May include surrounding context.

sh
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"

# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · search.py (reported line 25)May include surrounding context.

python
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"

# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · search.py (reported line 47)May include surrounding context.

python
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"

# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · store.py (reported line 25)May include surrounding context.

python
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"

# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · store.py (reported line 47)May include surrounding context.

python
# Cron schedule: 2:00 AM UTC daily
CRON_SCHEDULE="0 2 * * *"
CRON_CMD="$CRON_SCHEDULE cd $WORKSPACE_DIR && source .env && $PYTHON $SKILL_DIR/auto_capture.py --days 3 >> $LOG_FILE 2>&1 # $CRON_MARKER"

# ── Colors ──────────────────────────────────────────────────────────────────
GREEN='\033[0;32m'

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install_cron.sh (reported line 41)May include surrounding context.

sh
os.path.expanduser("~/.openclaw/workspace"),
    ]
    for d in search_dirs:
        env_path = os.path.join(d, ".env")
        if os.path.isfile(env_path):
            with open(env_path) as f:
                for line in f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install_cron.sh (reported line 42)May include surrounding context.

sh
os.path.expanduser("~/.openclaw/workspace"),
    ]
    for d in search_dirs:
        env_path = os.path.join(d, ".env")
        if os.path.isfile(env_path):
            with open(env_path) as f:
                for line in f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install_cron.sh (reported line 47)May include surrounding context.

sh
os.path.expanduser("~/.openclaw/workspace"),
    ]
    for d in search_dirs:
        env_path = os.path.join(d, ".env")
        if os.path.isfile(env_path):
            with open(env_path) as f:
                for line in f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · search.py (reported line 36)May include surrounding context.

python
os.path.expanduser("~/.openclaw/workspace"),
    ]
    for d in search_dirs:
        env_path = os.path.join(d, ".env")
        if os.path.isfile(env_path):
            with open(env_path) as f:
                for line in f:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · store.py (reported line 36)May include surrounding context.

python
os.path.expanduser("~/.openclaw/workspace"),
    ]
    for d in search_dirs:
        env_path = os.path.join(d, ".env")
        if os.path.isfile(env_path):
            with open(env_path) as f:
                for line in f:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README expands the skill from manual cloud backup/search into automatic cron-based extraction of OpenClaw session logs, which is materially broader than the stated backup/retrieval scope. That creates a hidden data-flow from potentially sensitive local conversations and artifacts to a third-party cloud service, increasing the risk of over-collection and unintended exfiltration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatically harvesting session logs is not clearly necessary for a skill whose core purpose is manual cloud backup and retrieval. In this context, the unjustified background collection is dangerous because session logs often contain prompts, outputs, file paths, API keys, and other sensitive operational data that users would not expect to be uploaded.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes automatic extraction of session logs to cloud backup without any warning about privacy or data sensitivity. This is dangerous because users may enable the cron job without understanding that confidential conversations, credentials, proprietary code, or personal data could be continuously sent to an external service.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and instructs use of capabilities including environment-variable access, file read/write, network access, shell execution, and cron installation, but it does not declare any explicit tool scope or permissions boundaries. In a skill that uploads memory content to a third-party cloud service and installs scheduled jobs, missing scope declarations weakens reviewability and increases the chance of over-privileged execution or unintended data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill promotes cloud backup and auto-capture of memory-derived content but does not clearly warn that potentially sensitive user/session data may be sent to a third-party service. In this context, memory logs can easily contain secrets, personal data, internal URLs, tokens, or incident details, so missing consent and sensitivity warnings materially raise privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prerequisite section tells users to place an API key in .env but gives no guidance on protecting that credential or preventing secrets from being uploaded through stored memory. In a skill that scans logs and environment-backed configuration, failure to warn about credential hygiene increases the likelihood of accidental exposure of both the API key and unrelated secrets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.