Back to skill

Security audit

Context Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-built for context memory, but it automatically persists potentially sensitive project and session details without strong local permission hardening or clear user controls.

Install only if you are comfortable with project context, notes, file paths, command metadata, and task history being saved across sessions in plaintext under the OpenClaw memory directory. Review local filesystem permissions and avoid saving secrets or sensitive commands until the skill provides clearer opt-in, deletion, and permission-hardening controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/context-engine.js:17
Finding

Context Data Stored Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The changelog states the skill is triggered by 'session_start, explicit mentions, heartbeat' without defining clear scope or guard conditions. Broad or ambiguous triggers can cause the skill to activate unexpectedly, restoring or switching project context automatically and exposing or modifying stored workspace state without a deliberate user action.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

Session persistence is intentional for this skill, but it still represents a real security and privacy concern because it carries context across sessions and may restore prior sensitive information automatically. In this skill's context, persistence is expected functionality, which makes the behavior less suspicious, but not harmless if users are not clearly informed and controls are weak.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: context-engine
description: Smart Context Engine - Maintains conversation state and project continuity across OpenClaw sessions. Tracks active projects, saves/restores context, and provides project management. Use when: (1) starting a new session and wanting to restore previous context, (2) working on a specific project and wanting to track progress, (3) switching between projects, (4) asking "what are we working on" or "where did we leave off", (5) wanting to save current context manually.

metadata:
  claname: context-engine

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that context is automatically saved periodically and on session end, but it does not clearly warn users that conversation state and activity history will be persisted. This creates a privacy risk because users may share sensitive information without realizing it will be retained beyond the current session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The stored fields include sensitive metadata such as last file worked on and last command executed, but the skill documentation does not provide a clear warning about retaining this activity history. Persisting such data can expose confidential project names, file paths, or operational details to later sessions or other local users with access to the storage path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description uses broad phrases for explicit mentions without defining clear boundaries, which makes accidental activation more likely. Because this skill performs persistence and context restoration, ambiguous invocation can lead to unintended reads or writes of stored session data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger description uses broad phrases for explicit mentions without defining clear boundaries, which makes accidental activation more likely. Because this skill performs persistence and context restoration, ambiguous invocation can lead to unintended reads or writes of stored session data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.