T09 · Insecure Skill Coding Practices
- Location
scripts/auto_compress.py:687- Finding
Automatic compression can irreversibly erase sessions without preserving any memories
- Content
View full analysis
50_000: # Large session with 0 memories extracted — still safe to wipe # (nothing to verify, no data loss) wiped = wipe_session_file(session_file, session_file.stem, 0, dry_run) if wiped: mark_session_wiped(db, session_file.stem) total_wiped += 1 log(f" {session_file.stem[:8]}: 0 memories, wiped large session") ``` The invoked wipe operation replaces the original transcript: ```python def wipe_session_file(session_file: Path, session_id: str, memory_count: int, dry_run: bool) -> bool: # ... try: session_file.write_text(stub + "\n", encoding="utf-8") return True except OSError as e: log(f" Wipe failed: {e}") return False ``` ### Technical Analysis The normal wipe path verifies that extracted memories are present and readable in SQLite before overwriting the source transcript. The zero-memory branch bypasses that preservation requirement whenever the session exceeds 50,000 bytes. A result of zero memories does not establish that the transcript contains nothing worth preserving. It can occur when: - `openclaw capability model run` is unavailable, times out, or returns malformed output. - Provider or gateway communication fails. - The model produces an unexpected response. - Heuristic extraction finds no matching phrases. - Extracted candidates are rejected or fail insertion. - The transcript contains valuable information that does not match the heuristic patterns. The comment claiming “no data loss” is therefore incorrect. The transcript may contain substantial user data even though extraction returned zero results. Because `write_text()` truncates the existing file before writing t ...[truncated 1489 chars]- Remediation
View remediation
