Back to skill

Security audit

local-tencentdb-agent-memory-flash

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent memory-plugin setup guide, but it asks users to install an unpinned third-party plugin and run an unaudited patch script that changes OpenClaw behavior while storing conversation and tool-call data persistently.

Review before installing. Only proceed if you trust the package publisher and are comfortable with OpenClaw storing and recalling conversation content, preferences, and tool-call results. Prefer a pinned, verified package version, inspect the patch script before running it, avoid sudo for installation, and confirm how to disable the plugin and delete stored memories/logs. Use remote embeddings only if you intend to send memory content to that provider.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
skill.md:121
Finding

Execution of an Unpinned Third-Party Plugin Patch

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 37 and 121-125
Vulnerability Type: Third-party supply-chain risk
Risk Level: Medium

Vulnerable Code

Installation command at line 37:

bash
openclaw plugins install @tencentdb-agent-memory/memory-tencentdb

Patch execution instructions at lines 121-125:

bash
cd ~/.openclaw/extensions/memory-tencentdb
bash scripts/openclaw-after-tool-call-messages.patch.sh
openclaw gateway restart

Technical Analysis

The instructions install a third-party package without pinning an exact version or requiring signature, checksum, provenance, or source verification. They subsequently direct the user to execute a shell script supplied by that package.

The patch script is not included in the audited project, so its behavior cannot be statically verified. Because it is described as changing the handling of tool-call messages, it may modify security-sensitive OpenClaw behavior and gain access to tool outputs. A mutable or compromised package version could therefore execute arbitrary commands with the installing user's privileges.

The issue is not evidence that the named package is currently malicious. The vulnerability is the unsafe trust and execution model imposed by the installation instructions.

Attack Path

  1. An attacker compromises the package publisher, registry account, distribution infrastructure, or a future package release.
  2. The user follows the Skill and installs the package without an exact version or integrity verification.
  3. The compromised package is placed under ~/.openclaw/extensions/memory-tencentdb.
  4. The user executes scripts/openclaw-after-tool-call-messages.patch.sh.
  5. Attacker-controlled shell commands run with the user's privileges.
  6. The script modifies OpenClaw files or tool-call handling.
  7. The Gateway restart activates the modified behavior in subsequent sessions.

Impact Assessment

Successful exploitation could provide arbitrary code exec ...[truncated 639 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the plugin to a specific reviewed version rather than accepting the latest available release.
  • Document the authoritative registry namespace and source repository.
  • Require cryptographic checksum or signature verification before installation.
  • Review and vendor the required patch script within the Skill so its contents are covered by the audit.
  • Display or inspect the patch before execution and fail closed if it differs from the reviewed version.
  • Run the plugin and patch under a dedicated, unprivileged account with narrowly scoped filesystem access.
  • Prevent the extension from accessing credentials or unrelated conversation data unless explicitly required.
  • Back up affected files and verify the exact modifications before restarting the Gateway.
  • Prefer a supported OpenClaw API or versioned integration mechanism over patching installed application behavior.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
skill.md:193
Finding

Unsafe Recommendation to Use Elevated Privileges for Package Installation

Content
View full analysis

Vulnerability Details

File Location: skill.md, line 193
Vulnerability Type: Improper privilege elevation guidance
Risk Level: Low

Vulnerable Guidance

English rendering of the source troubleshooting entry:

text
Permission error EACCES | Add sudo or use a Node version managed by nvm

Technical Analysis

The troubleshooting guidance recommends sudo as a generic solution to npm permission failures. It does not identify which command should be elevated, restrict the operation, or warn that package installation can execute dependency lifecycle scripts.

If a user applies sudo to the plugin or npm installation command, package-controlled installation scripts could execute as the root user. This crosses the least-privilege boundary even though the described memory plugin does not require system-wide administrative access to perform its intended function.

Attack Path

  1. The user encounters an EACCES error while installing the plugin or its dependencies.
  2. Following the troubleshooting guidance, the user repeats the installation command with sudo.
  3. npm or the plugin invokes package lifecycle scripts under root privileges.
  4. A compromised dependency uses those privileges to modify protected files, install additional software, alter system configuration, or access root-readable data.
  5. The resulting modifications remain effective beyond the original installation operation.

Impact Assessment

Exploitation could elevate the consequences of a supply-chain compromise from user-level execution to root-level execution. A malicious package running as root could potentially:

  • Read or modify system-wide files.
  • Alter services, executables, or security configuration.
  • Access sensitive data unavailable to the normal user.
  • Install persistent system components.
  • Compromise other users or applications on the same host.

The guidance does not itself execute an elevated command, so exploitation requires the user to apply `s ...[truncated 75 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the generic recommendation to use sudo.
  • Recommend a user-scoped Node installation through nvm, Volta, or another unprivileged version manager.
  • Alternatively, configure a user-owned npm prefix rather than changing system directory permissions.
  • Explicitly warn users not to run plugin installation or dependency lifecycle scripts as root.
  • If an administrative operation is genuinely necessary, document the exact command, affected paths, reason for elevation, and expected changes.
  • Disable unnecessary npm lifecycle scripts during initial package inspection and review them before allowing execution.
  • Ensure OpenClaw extensions and their dependencies are installed in directories owned by the dedicated OpenClaw user.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to enable persistent conversation memory and recall of personal preferences without any privacy notice, consent flow, or guidance on retention and sensitive-data handling. Because the plugin is explicitly designed to store user conversation data, the omission can lead to unintentional collection and long-term retention of personal or sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide tells users to execute a local shell patch script that modifies behavior/files but does not explain what the script changes, prompt users to inspect it, or warn about the risks of arbitrary shell execution. Running extension-provided scripts from a plugin directory can introduce code execution and integrity risks, especially if the extension package or path has been tampered with.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The troubleshooting advice suggests using sudo to resolve permission errors during package installation, which can cause users to run package-manager operations and possibly extension install hooks with elevated privileges. If the package, dependency chain, or install scripts are compromised, this increases the blast radius to system-wide compromise.

Content

Scanner excerpt · skill.md (reported line 210)May include surrounding context.

md
| 症状 | 解法 |
|------|------|
| npm 安装超时 | `npm config set registry https://registry.npmmirror.com` |
| 权限报错 EACCES | 加 sudo 或使用 nvm 管理的 Node |
| Gateway 重启后起不来 | `openclaw logs gateway` 或查看 `~/.openclaw/logs/` |
| 记忆召回失败 | 检查配置中 `recall.enabled` 是否为 true |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example SOUL.md content includes the instruction "用中文思考,回复口语化," which imposes a specific language/locale behavior. The document does not present this as an optional user choice or opt-in language preference, so it can conflict with organizational language-choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.