Back to skill

Security audit

Lumetra Engram

Security checks for vulnerabilities and agentic risk

Overview

This memory skill appears purpose-aligned, but it needs review because it can automatically send and persist conversation facts to a hosted service and its setup may expose an API token.

Install only if you are comfortable with selected conversation facts and memory queries being sent to Lumetra's hosted service and processed through configured model providers. Use a narrowly scoped, revocable ENGRAM_API_KEY, avoid storing secrets or regulated data, review where mcporter stores authorization headers, and ask the agent to confirm before storing or deleting memories.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–19
Vulnerability Type: Unpinned npm supply-chain dependency
Risk Level: Medium

yaml
requires:
  bins: ["mcporter"]
  env: ["ENGRAM_API_KEY"]
install:
  - id: "node"
    kind: "node"
    package: "mcporter"

Technical Analysis

The Skill declares installation of the mcporter npm package without an exact version or integrity constraint. Consequently, the installed artifact can change after the Skill has been reviewed. A compromised maintainer account, malicious package update, or compromised transitive dependency could introduce arbitrary code into later installations.

The package installation is necessary to provide the declared MCP client functionality, but accepting an unconstrained version exceeds the minimum supply-chain trust required. The audit found no evidence that the current package is malicious; the vulnerability is the absence of reproducible dependency controls.

Attack Path

  1. An attacker compromises the mcporter npm package, a maintainer account, or a transitive dependency.
  2. The attacker publishes a malicious release under the expected package name.
  3. OpenClaw processes the Skill requirement and installs the unconstrained package.
  4. Malicious installation lifecycle code or runtime code executes under the operator's account.
  5. The code may access files, environment variables, or network resources available to that account, including ENGRAM_API_KEY.

Impact Assessment

Successful exploitation could result in arbitrary code execution with the privileges of the user running OpenClaw or the package installer. The accessible scope may include that user's files, environment variables, MCP configuration, and network credentials. The declaration does not itself request elevated operating-system privileges, so administrator or root access is not directly established.

Remediation
View remediation

Remediation Suggestions

  • Pin mcporter to an exact reviewed version rather than accepting the latest available release.
  • Where the installation framework permits it, verify the package using a lockfile or cryptographic integrity hash.
  • Disable or restrict npm lifecycle scripts when they are not required.
  • Review transitive dependencies and establish a controlled process for dependency upgrades.
  • Confirm that the package comes from the intended publisher and official registry.
  • Run the dependency with a restricted account or sandbox that cannot access unrelated files and credentials.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Bearer Credential Passed Through Command-Line Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34–39
Vulnerability Type: Potential plaintext credential exposure in process arguments and persistent configuration
Risk Level: High

bash
mcporter config add engram-lumetra https://mcp.lumetra.io/mcp/sse \
  --transport sse \
  --header "Authorization=Bearer $ENGRAM_API_KEY"

After that, mcporter list should show engram-lumetra with 6 tools and mcporter call engram-lumetra.list_buckets should return a JSON bucket list.

text

### Technical Analysis

The shell expands `$ENGRAM_API_KEY` before invoking `mcporter`, causing the complete bearer credential to be supplied as a command-line argument. Depending on the operating system and execution environment, command arguments may be visible to process inspection, monitoring tools, audit telemetry, debugging logs, or command wrappers.

The command also registers the expanded authorization header in MCP configuration. If `mcporter` persists that header literally rather than retaining a secure environment-variable reference, the bearer token may be stored in plaintext. The Skill does not document configuration file permissions, credential encryption, token scoping, or secure secret-store integration.

Authentication is necessary for the hosted service, but exposing the expanded secret through a command argument and potentially persistent configuration is not the minimum-privilege approach.

### Attack Path

1. The operator exports a valid `ENGRAM_API_KEY` and runs the documented setup command.
2. The shell expands the variable into the complete `Authorization=Bearer ...` argument.
3. A local process monitor, audit collector, command wrapper, or other appropriately positioned local user captures the process arguments; alternatively, an attacker reads the generated MCP configuration.
4. The attacker extracts the bearer token.
5. The attacker authenticates to the hosted Engram endpoint as the affected te
...[truncated 589 chars]
Remediation
View remediation

Remediation Suggestions

  • Use an MCP configuration mechanism that references the environment variable at runtime without expanding and persisting its value.
  • Prefer an operating-system credential manager or another supported encrypted secret store.
  • Avoid transmitting credentials in command-line arguments.
  • Restrict MCP configuration permissions to the owning user and verify that backups and logs do not contain the token.
  • Use a narrowly scoped, revocable token with the shortest practical lifetime.
  • Redact authorization headers from process telemetry, diagnostics, and error output.
  • Document a token rotation procedure and immediately revoke credentials suspected of exposure.

other

Warning
Location
SKILL.md:45
Finding

Conversation Facts May Be Persisted to a Remote Service Without Explicit Consent or Sensitive-Data Filtering

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45–48
Vulnerability Type: Privacy-sensitive remote data storage
Risk Level: Medium

markdown
## When to use

- **Before answering** anything that may rely on prior context: call `engram-lumetra.query_memory` first and ground your answer in the results.
- **When the user shares a fact** worth remembering (preferences, project details, decisions, deadlines): call `engram-lumetra.store_memory` to capture it.
- **At the end of a useful conversation**: capture stable takeaways with `engram-lumetra.store_memory`.

Technical Analysis

The Skill directs the Agent to store facts and stable takeaways automatically when they appear useful. It does not require explicit user approval for each upload and does not prohibit storage of credentials, authentication material, personal data, regulated information, or confidential project content.

Remote persistence is intrinsic to the declared hosted-memory functionality. However, automatically classifying broad categories such as project details, decisions, and deadlines as suitable for storage lacks data-minimization and purpose-limitation controls. The document also states that inference uses a provider key configured through Lumetra, indicating that stored or queried content may participate in processing involving external model providers.

This is not confirmed malicious exfiltration: the external storage function is disclosed by the Skill. The issue is insufficient consent and sensitive-data filtering around that disclosed behavior.

Attack Path

  1. A user shares a confidential fact, personal detail, internal project decision, deadline, or secret during a conversation.
  2. The Agent interprets that information as a fact worth remembering or as a stable takeaway.
  3. Following the Skill instructions, the Agent sends the content to engram-lumetra.store_memory.
  4. The content is persistently associated with th ...[truncated 1027 chars]
Remediation
View remediation

Remediation Suggestions

  • Require explicit user consent before storing each memory, particularly on the first use or when content may be sensitive.
  • Display the exact proposed memory and destination bucket before transmission.
  • Prohibit storage of passwords, API keys, access tokens, private keys, recovery codes, financial data, health data, and other regulated or highly sensitive information.
  • Add automatic secret and personal-data detection before invoking store_memory.
  • Default to local, session-only handling when consent or data classification is uncertain.
  • Clearly document retention, deletion, provider-processing, and tenant-access policies.
  • Provide straightforward controls to inspect, edit, delete, and clear stored memories.
  • Separate work and personal data using explicit buckets and least-privilege access controls.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to send user facts and queries to a hosted third-party memory service, but it does not provide a clear user-facing warning that potentially sensitive conversation data will leave the local environment. Because the skill is user-invocable and explicitly encourages storing preferences, project details, decisions, and deadlines, users may disclose sensitive information without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented tools include delete_memory and especially clear_memories(bucket), which can irreversibly remove stored data, but the skill provides no confirmation, authorization, or safety guidance before destructive use. In an agent setting, ambiguous prompts or tool misuse could lead to accidental bulk deletion of memory, causing loss of important persisted context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.