T09 · Insecure Skill Coding Practices
- Location
scripts/context-engine.js:17- Finding
Context Data Stored Without Explicit Restrictive Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is purpose-built for context memory, but it automatically persists potentially sensitive project and session details without strong local permission hardening or clear user controls.
Install only if you are comfortable with project context, notes, file paths, command metadata, and task history being saved across sessions in plaintext under the OpenClaw memory directory. Review local filesystem permissions and avoid saving secrets or sensitive commands until the skill provides clearer opt-in, deletion, and permission-hardening controls.
scripts/context-engine.js:17Context Data Stored Without Explicit Restrictive Permissions
The changelog states the skill is triggered by 'session_start, explicit mentions, heartbeat' without defining clear scope or guard conditions. Broad or ambiguous triggers can cause the skill to activate unexpectedly, restoring or switching project context automatically and exposing or modifying stored workspace state without a deliberate user action.
Session persistence is intentional for this skill, but it still represents a real security and privacy concern because it carries context across sessions and may restore prior sensitive information automatically. In this skill's context, persistence is expected functionality, which makes the behavior less suspicious, but not harmless if users are not clearly informed and controls are weak.
---
name: context-engine
description: Smart Context Engine - Maintains conversation state and project continuity across OpenClaw sessions. Tracks active projects, saves/restores context, and provides project management. Use when: (1) starting a new session and wanting to restore previous context, (2) working on a specific project and wanting to track progress, (3) switching between projects, (4) asking "what are we working on" or "where did we leave off", (5) wanting to save current context manually.
metadata:
claname: context-engine
The skill states that context is automatically saved periodically and on session end, but it does not clearly warn users that conversation state and activity history will be persisted. This creates a privacy risk because users may share sensitive information without realizing it will be retained beyond the current session.
The stored fields include sensitive metadata such as last file worked on and last command executed, but the skill documentation does not provide a clear warning about retaining this activity history. Persisting such data can expose confidential project names, file paths, or operational details to later sessions or other local users with access to the storage path.
The trigger description uses broad phrases for explicit mentions without defining clear boundaries, which makes accidental activation more likely. Because this skill performs persistence and context restoration, ambiguous invocation can lead to unintended reads or writes of stored session data.
The trigger description uses broad phrases for explicit mentions without defining clear boundaries, which makes accidental activation more likely. Because this skill performs persistence and context restoration, ambiguous invocation can lead to unintended reads or writes of stored session data.
No suspicious patterns detected.