Back to skill

Security audit

TalonForge Memory System (EN/AR)

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed memory setup tool, but it needs review because it adds recurring background conversation review and long-term personal memory storage without clear consent, limits, or removal guidance.

Install only if you intentionally want OpenClaw to maintain long-term memory from your conversations. Before enabling the cron job, decide what data categories are allowed, add rules to avoid storing secrets or sensitive personal information, review the generated memory files, and confirm how to disable the scheduled job and delete or redact stored entries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrase "Set up the memory system" is generic enough that it could plausibly match ordinary user setup requests and cause the skill to run unexpectedly. Because the skill performs file creation and installs a scheduled cron job, accidental invocation increases the chance of unintended persistence and background automation without sufficiently explicit user consent.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill describes actions that create persistent files and install a recurring cron task, but it does not present a clear upfront warning or ask for informed consent before making those changes. This is dangerous because it can lead to stealthy persistence, unexpected background processing of conversations, and ongoing collection of user-derived data.

Ssd 3

Medium
Confidence
93% confidence
Finding
These rules instruct the AI to continually store user preferences, patterns, decisions, and other conversation-derived facts in long-term memory files. Persistent profiling of a user across sessions creates privacy and data minimization risks, especially if the user has not explicitly consented to retention or if sensitive inferences are recorded.

Ssd 3

High
Confidence
98% confidence
Finding
The nightly cron prompt directs automated review of conversations to extract durable facts, relationships, decisions, status changes, milestones, and preferences into persistent files. This is particularly risky because it operationalizes ongoing background surveillance and retention of potentially sensitive personal data without a per-run consent check or strong scope limitations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.