Back to skill

Security audit

ClawGraph

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed memory skill, but it should be reviewed because it tells the agent to automatically save personal and project details persistently without an explicit per-fact opt-in.

Review this before installing if you handle personal, confidential, or workplace information. Use it only if you are comfortable with the agent saving stable facts across sessions and processing selected facts through the configured OpenAI-compatible provider. Prefer a dedicated, revocable API key and confirm how to inspect, correct, and delete ~/.clawgraph/data before enabling automatic memory use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:26
Finding

Automatic Persistent Collection of User Information Without Explicit Consent

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26-37 and 98-103
Vulnerability Type: other: Privacy-invasive automatic data persistence
Risk Level: Medium

Vulnerable Code

markdown
- Proactively store durable user facts without waiting for an explicit memory command when the user shares information that is likely to matter later.
- Only store facts that are explicitly stated by the user or already confirmed in the current session.
- Preserve the user's phrasing when possible, and preserve the user's meaning closely when storing facts; prefer the exact claim they made over a stronger paraphrase.
- Do not infer, upgrade, or invent facts. For example, "I'm learning Rust" does not mean "I am a Rust developer," and "I'm planning a demo" is not an occupation.
- If a detail is ambiguous, speculative, or feels too weak to persist, do not store it.
- When several explicit facts appear in one message, store only the durable facts that are likely to matter later.

## Automatic Decision Rule

When the user naturally shares stable personal, project, team, or preference information, assume you should store it in ClawGraph even if they did not say "remember this."

Do not store fleeting conversational filler, jokes, weak guesses, or details that are only implied.
markdown
- **Persistence**: Data stored at `~/.clawgraph/data` — survives restarts
- **Idempotent**: Uses MERGE — adding the same fact twice won't create duplicates
- **JSON output**: Always use `--output json` for structured, parseable results
- **Config**: `~/.clawgraph/config.yaml` for defaults (model, db path)
- **Models**: OpenAI-compatible APIs today via the OpenAI SDK. The current default model path is `gpt-5.4-mini` for ClawGraph extraction.
- **Env vars**: `OPENAI_API_KEY` is required. `OPENAI_BASE_URL` is optional for other OpenAI-compatible endpoints.

Technical Analysis

The Skill explicitly instructs the Agen ...[truncated 2271 chars]

Remediation
View remediation

Remediation Suggestions

  • Require explicit, informed opt-in before enabling automatic memory storage.
  • Ask for confirmation before storing personal, confidential, or organization-sensitive facts.
  • Clearly disclose that facts may be transmitted to an external model provider for extraction.
  • Deny storage of credentials, authentication tokens, financial information, health information, precise locations, and other sensitive categories by default.
  • Provide documented commands to inspect, correct, and permanently delete individual facts or the complete graph.
  • Define retention limits and support automatic expiration where indefinite persistence is unnecessary.
  • Restrict OPENAI_BASE_URL to administrator-approved HTTPS endpoints and clearly identify the configured data processor.
  • Apply restrictive filesystem permissions to ~/.clawgraph/data and the configuration file.
  • Prefer local extraction or a provider with appropriate privacy and retention guarantees when processing sensitive information.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unauditable Third-Party Runtime Dependency Installed from an External Registry

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 6
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

yaml
metadata: {"openclaw": {"emoji": "🧠", "requires": {"bins": ["clawgraph"], "env": ["OPENAI_API_KEY"]}, "primaryEnv": "OPENAI_API_KEY", "install": [{"id": "uv", "kind": "uv", "package": "clawgraph==0.1.3", "label": "Install ClawGraph (uv)", "bins": ["clawgraph"]}]}}

Technical Analysis

The Skill installs and executes the external Python package clawgraph==0.1.3. Pinning the version reduces exposure to unexpected future upgrades, but this project contains only SKILL.md; it does not include the dependency source, a dependency lockfile, package hashes, signatures, provenance attestations, or a list of reviewed transitive dependencies.

Therefore, the audited artifact cannot establish what the installed package does with filesystem access, network access, stored data, or OPENAI_API_KEY. Package installation and subsequent CLI execution occur under the Agent's operating-system identity. A compromised package release, registry account, package index, or transitive dependency could execute arbitrary code with that identity.

No evidence in the reviewed file proves that clawgraph==0.1.3 is malicious. The finding concerns an unverified supply-chain trust boundary and the inability to audit the actual runtime implementation from the submitted project.

Attack Path

  1. The Skill installation process requests clawgraph==0.1.3 through uv.
  2. The package and its transitive dependencies are resolved and downloaded from the configured package registry.
  3. A compromised registry artifact, maintainer release, or transitive dependency supplies malicious code under the expected package identity and version.
  4. Malicious code runs during installation, import, or invocation of the clawgraph executable.
  5. The code inherits the Agent process's accessible envir ...[truncated 811 chars]
Remediation
View remediation

Remediation Suggestions

  • Audit and vendor the exact ClawGraph source used at runtime, or include it in the review scope.
  • Generate a complete lockfile covering all transitive dependencies.
  • Require cryptographic hashes for every downloaded distribution and reject artifacts that do not match.
  • Use a trusted, allowlisted package index rather than accepting arbitrary configured indexes.
  • Verify package signatures, build provenance, or reproducible-build attestations where available.
  • Run the package in a restricted environment with only the filesystem and network access required for its documented function.
  • Expose OPENAI_API_KEY only to the process that requires it and use a narrowly scoped, revocable key with usage limits.
  • Restrict access to ~/.clawgraph/data and monitor unexpected outbound connections.
  • Establish a dependency-update review process that repeats source, provenance, and vulnerability checks before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to proactively store durable user facts without waiting for an explicit memory command encourages automatic persistence of personal data without contemporaneous consent. In practice, this can capture sensitive personal, professional, or relational information and retain it beyond the current session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly frames durable cross-conversation memory and instructs the agent to remember user information, but it does not provide a clear privacy warning or consent mechanism before persistence. This can lead to storage of personal or sensitive facts without the user's informed awareness, increasing privacy and retention risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to persist user-provided personal, project, team, and preference information across conversations by default. Even though it says not to infer facts, the cross-session storage of explicitly stated information still creates a meaningful privacy and surveillance risk if users did not knowingly request long-term memory.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill documents that data is stored under a persistent local path and survives restarts, which confirms session persistence of remembered user facts. In the context of a memory skill, that persistence is expected, but without strong consent, retention limits, or deletion guidance, it increases the impact of over-collection or accidental storage of sensitive information.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
## Key Details

- **Persistence**: Data stored at `~/.clawgraph/data` — survives restarts
- **Idempotent**: Uses MERGE — adding the same fact twice won't create duplicates
- **JSON output**: Always use `--output json` for structured, parseable results
- **Config**: `~/.clawgraph/config.yaml` for defaults (model, db path)
- **Models**: OpenAI-compatible APIs today via the OpenAI SDK. The current default model path is `gpt-5.4-mini` for ClawGraph extraction.

Static analysis

No suspicious patterns detected.