Back to skill

Security audit

OpenMem - Longterm Compressed Memory

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is mostly purpose-aligned, but it should be reviewed because its default automation can read, send, persist, inject, and overwrite sensitive session data.

Install only if you are comfortable with an hourly background job reading full OpenClaw session transcripts, possibly sending excerpts through your configured model provider, storing selected memories in plaintext SQLite/cache files, and injecting top memories into future sessions. Use --no-wipe or avoid the cron setup unless you explicitly want old transcripts overwritten, and review/delete stored memories regularly.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auto_compress.py:687
Finding

Automatic compression can irreversibly erase sessions without preserving any memories

Content
View full analysis
50_000: # Large session with 0 memories extracted — still safe to wipe # (nothing to verify, no data loss) wiped = wipe_session_file(session_file, session_file.stem, 0, dry_run) if wiped: mark_session_wiped(db, session_file.stem) total_wiped += 1 log(f" {session_file.stem[:8]}: 0 memories, wiped large session") ``` The invoked wipe operation replaces the original transcript: ```python def wipe_session_file(session_file: Path, session_id: str, memory_count: int, dry_run: bool) -> bool: # ... try: session_file.write_text(stub + "\n", encoding="utf-8") return True except OSError as e: log(f" Wipe failed: {e}") return False ``` ### Technical Analysis The normal wipe path verifies that extracted memories are present and readable in SQLite before overwriting the source transcript. The zero-memory branch bypasses that preservation requirement whenever the session exceeds 50,000 bytes. A result of zero memories does not establish that the transcript contains nothing worth preserving. It can occur when: - `openclaw capability model run` is unavailable, times out, or returns malformed output. - Provider or gateway communication fails. - The model produces an unexpected response. - Heuristic extraction finds no matching phrases. - Extracted candidates are rejected or fail insertion. - The transcript contains valuable information that does not match the heuristic patterns. The comment claiming “no data loss” is therefore incorrect. The transcript may contain substantial user data even though extraction returned zero results. Because `write_text()` truncates the existing file before writing t ...[truncated 1489 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/compress.py:184
Finding

Unsanitized session identifiers permit JSONL path traversal outside the sessions directory

Content
View full analysis
1: print(f"ERROR: ambiguous prefix '{session_id}', matches:", file=sys.stderr) for m in matches: print(f" {m.name}", file=sys.stderr) sys.exit(1) else: print(f"ERROR: session '{session_id}' not found in {sessions_dir}", file=sys.stderr) sys.exit(1) messages = read_session_messages(session_file) ``` ### Technical Analysis `session_id` is accepted directly from the command line and interpolated into a filesystem path without validating that it is a UUID, filename component, or safe prefix. For example, a value such as `../private/export` produces: ```text /../private/export.jsonl ``` If that file exists, the direct existence check succeeds and the script reads it without verifying that the resolved path remains under `sessions_dir`. The fallback glob also embeds untrusted metacharacters into a glob pattern. This can permit unexpected matching behavior in addition to directory traversal. The reader only outputs records that parse as JSON and have the expected OpenClaw message structure, so this is not unrestricted disclosure of every plaintext file. Nevertheless, any readable JSONL file c ...[truncated 1202 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
hooks/openclaw/handler.js:40
Finding

Verbatim bootstrap injection enables persistent agent memory poisoning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description’s core claim is a 'SQLite long-term memory compression system for extended memory life,' but the code is primarily an MCP server for managing a memory database. It creates and maintains a SQLite schema, supports full-text search, add/update/delete/list/stats operations, duplicate detection, access counting, and writes a JSON cache file. These are memory management/control capabilities, so the phrase about adding tools for agents to control memory functions is partially accurate. However, the main described function—memory compression—is not implemented anywhere in the code chunk. Because the primary purpose is materially different from the declared purpose, this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The code does implement agent memory control tools using SQLite, so it is related to the declared domain. However, the description specifically emphasizes a 'memory compression system for extended memory life,' while the supplied code does not perform compression, summarization, pruning, retention optimization, or any similar memory-life-extension logic. Instead, it is a general-purpose persistent memory management CLI with full CRUD operations, FTS search, ranking, stats, export, and cache-file generation. That makes the declared purpose materially inaccurate/incomplete relative to the actual primary behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description suggests a SQLite memory compression system with agent-facing memory tools. This code chunk does not implement compression behavior directly; instead, it performs installation/setup tasks: environment checks, database/schema creation, MCP registration, and cron scheduling. The most significant mismatch is the undeclared capability to modify external OpenClaw configuration by registering an MCP server and scheduled cron job through subprocess calls. Those are operational side effects beyond a simple SQLite memory subsystem description and should have been declared. Database initialization is consistent with the memory-related theme, but the primary behavior of this specific code chunk is setup and system integration, not memory compression itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents the skill as a memory compression and memory-control tool centered on SQLite long-term memory management. However, this code chunk does not implement memory compression or agent memory control. Its primary function is uninstallation and cleanup of OpenClaw integration components: it invokes the openclaw CLI to unset an MCP entry, disable a hook, and remove scheduled cron jobs. Although it references the memory database path, it explicitly does not operate on the database contents beyond printing its location. This is a materially different purpose and includes undeclared administrative capabilities affecting system configuration.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
ad access to session files and write access to the local DB while enabled. Run `uninstall.py` to remove all registered components.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code wipes large session files even when zero memories were extracted, yet claims this causes 'no data loss'. In reality, this destroys the original conversation record without preserving any extracted content, so failures in extraction, parsing, or filtering can lead to irreversible loss of user data and audit history.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares broad capabilities including shell, file read/write, and environment access, but does not define an explicit tool scope boundary such as permissions or allowed-tools. That makes the effective privilege surface larger and less auditable, especially for a skill that installs persistent components and processes sensitive session transcripts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The documented persistent presence means the skill retains ongoing access to session files and the memory database while enabled. In a memory-oriented skill that handles full transcripts and plaintext caches, this materially raises the risk of long-term privacy exposure and unauthorized retention if the component is misused or left enabled unintentionally.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
- **Cache file is plaintext.** After every memory write, top memories are written to `openmem-cache.json` in the same directory as the DB, unencrypted. Trust level is identical to the DB file.

- **Persistent presence.** `setup.py` registers an MCP server and an hourly cron job with your OpenClaw gateway. OpenMem has ongoing read access to session files and write access to the local DB while enabled. Run `uninstall.py` to remove all registered components.

## Filesystem & Credential Access

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill installs persistent components via an MCP server and hourly scheduled job, allowing it to continue operating after the initial install context. Persistence increases the blast radius of any logic error, prompt-trigger mistake, or future misuse because transcript processing and file modification can recur automatically without fresh user review.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

python3 ~/.openclaw/workspace/skills/openmem/scripts/setup.py

text

This creates the database, checks requirements, registers the MCP server, registers the auto-compression launchd job (macOS), and prints the next steps (hook enable).

## Uninstall

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases "compress my sessions" and especially "save this to long-term memory" are natural conversational language that could be invoked unintentionally or through prompt injection in normal dialogue. In this skill, triggering compression causes full transcript review and potentially persistent storage or destruction of session data, so accidental activation has real privacy consequences.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to read complete conversation transcripts, extract user facts/preferences/projects, store them persistently, and inject top memories into future sessions. This creates a durable cross-session data retention channel that can preserve secrets, personal data, or sensitive project details beyond the user's original context, increasing both privacy risk and prompt-surface leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The hook automatically injects long-term memory content into the agent context at session start, but the documentation does not clearly warn that this may expose sensitive stored data to the active agent, prompts, logs, or downstream tool/use flows. Because this happens during bootstrap, users may not realize private memories are being surfaced automatically, increasing the chance of unintended disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This bootstrap hook automatically injects prior-session memory into every eligible agent session without any explicit user notice, consent check, or trust boundary validation. Because the injected content is treated as context/instructions, stale, sensitive, or prompt-injected data from previous sessions can influence later agent behavior and leak across tasks or users if the cache is shared or contaminated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema explicitly documents persistent storage of session-derived memory content and associated metadata such as source, session_id, timestamps, and access counts, but provides no notice about retention, sensitivity, consent, or user controls. In a long-term memory skill, this creates a real privacy/security risk because agents may persist sensitive conversation or workspace-derived data beyond user expectations, increasing exposure if the database is accessed, copied, or reused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that OpenClaw sessions are compressed into memories and tracked in a persistent table, but does not warn that session contents may be transformed, retained, and resurfaced later. This is dangerous in the context of an agent memory skill because users may not realize ephemeral conversations, operational details, or secrets mentioned in sessions can become durable searchable records, leading to privacy leaks and unintended data persistence.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script sends session contents to openclaw capability model run, which may route data to a remote provider depending on user configuration, despite the skill being presented primarily as a local SQLite memory compression system. That creates a confidentiality boundary violation: sensitive conversation logs can be exfiltrated to third-party model backends without clear, explicit user consent at the point of use.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/auto_compress.py (reported line 240)May include surrounding context.

python
"""Run a single `openclaw capability model run` call. Returns parsed memories or []."""
    prompt = EXTRACT_PROMPT_TEMPLATE.format(text=text)
    try:
        proc = subprocess.run(
            [bin_path, "--no-color", "capability", "model", "run", "--prompt", prompt, "--json"],
            capture_output=True,
            text=True,

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script explicitly instructs the operator/agent to read complete session transcripts and store a summary in persistent memory. Because session contents may include sensitive user data, secrets, or prompt-injected text, this creates a data-retention and possible data-exposure path without any filtering, consent check, or sensitivity screening.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The MCP server exposes a permanently destructive memory_delete tool that will delete records immediately by ID with no confirmation, authorization check, soft-delete, or contextual safeguard. In an agent-tooling context, this increases the risk of accidental deletion from prompt confusion, tool misuse, or hostile instructions reaching the agent, causing irreversible loss of long-term memory data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says this skill is a "SQLite long-term memory compression system for extended memory life," which suggests storage compaction/compression behavior. In contrast, the code exposes commands to add, search, get, list, update, delete, inspect stats, and export memories, but contains no compression logic; it functions as a general memory database manager.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The cache writer silently serializes top memories into a JSON file alongside the database, duplicating potentially sensitive content into an additional plaintext artifact. This expands the data exposure surface because other local processes, backups, or users may read the cache even if they are not expected to inspect the database directly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The delete command permanently removes a memory record and updates the cache, but there is no confirmation prompt or explicit warning to the user that the action is destructive. The command help text only says 'Delete a memory' and does not disclose irreversibility.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The export command enables bulk extraction of all stored memories, which can include sensitive long-term agent data, and this capability is broader than the stated purpose of memory compression. In an agent environment, bulk export materially lowers the barrier to mass disclosure of accumulated secrets, prompts, or user data if the tool is invoked by an untrusted workflow or compromised agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The export feature emits all stored memories without any privacy guardrails, making large-scale disclosure easy once the command is reachable. In the context of an agent memory tool, the dataset may contain sensitive user context, internal reasoning artifacts, credentials, or operational details, so unrestricted bulk output is dangerous.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup script does more than initialize a local database: it modifies OpenClaw runtime configuration by registering an MCP server and scheduling recurring automation. That expands the skill's privileges and persistence beyond what users may expect from a setup step, creating a supply-chain style risk if the skill is malicious or later modified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.