Back to skill

Security audit

Context Engine

Security checks for vulnerabilities and agentic risk

Overview

This memory skill stores and restores project context locally as advertised, but users should understand that saved context can include sensitive notes, filenames, commands, and tasks.

Install this only if you want project context retained across sessions. Avoid saving secrets, credentials, sensitive commands, or confidential notes; review the JSON files in the documented memory directory as local persistent records, and consider tightening filesystem permissions or clearing them when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/context-engine.js:42
Finding

Persistent Sensitive Context Is Stored Without Explicit Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/context-engine.js, lines 9-18, 42-45, 75-77, and 158-162
Vulnerability Type: Plaintext sensitive-data storage with permissions dependent on the process umask
Risk Level: Medium

Vulnerable Code

js
const PROJECTS_DIR = '/home/deus/.openclaw/workspace/memory/projects';
const PROJECTS_FILE = path.join(PROJECTS_DIR, 'projects.json');
const SESSION_FILE = path.join(PROJECTS_DIR, 'session.json');

// Ensure directory exists
function ensureDir() {
  if (!fs.existsSync(PROJECTS_DIR)) {
    fs.mkdirSync(PROJECTS_DIR, { recursive: true });
  }
}
js
// Save projects
function saveProjects(data) {
  data.lastUpdated = now();
  fs.writeFileSync(PROJECTS_FILE, JSON.stringify(data, null, 2));
}
js
// Save session
function saveSession(data) {
  fs.writeFileSync(SESSION_FILE, JSON.stringify(data, null, 2));
}
js
// Update context
if (contextData.lastTopic) project.context.lastTopic = contextData.lastTopic;
if (contextData.lastFile) project.context.lastFile = contextData.lastFile;
if (contextData.lastCommand) project.context.lastCommand = contextData.lastCommand;
if (contextData.pendingTasks) project.context.pendingTasks = contextData.pendingTasks;
if (contextData.notes) project.context.notes = contextData.notes;

Technical Analysis

The Skill persistently records conversation and project context, including command history, file paths, topics, tasks, and notes. This information is serialized as plaintext JSON in a fixed directory.

Neither fs.mkdirSync nor fs.writeFileSync specifies a restrictive permission mode. Consequently, permissions are determined by the runtime environment's umask or by the permissions of pre-existing files. Under a permissive configuration, other local users or processes may be able to read the stored context.

The write operations also overwrite existing paths without expl ...[truncated 1693 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create the storage directory with owner-only permissions:

    js
    fs.mkdirSync(PROJECTS_DIR, {
      recursive: true,
      mode: 0o700
    });
    
  2. Create and write persistent state files with mode 0600:

    js
    fs.writeFileSync(
      PROJECTS_FILE,
      JSON.stringify(data, null, 2),
      { encoding: 'utf8', mode: 0o600 }
    );
    

    Apply the same protection to SESSION_FILE, initial file creation, and backup files.

  3. Enforce permissions on existing paths with fs.chmodSync, because specifying mode does not necessarily correct permissions on files that already exist.

  4. Before writing, inspect paths with lstat and reject symbolic links, non-regular files, or files not owned by the expected user.

  5. Redact likely credentials and tokens before persisting lastCommand, notes, lastTopic, or task content. Avoid storing complete command lines when a minimal summary is sufficient.

  6. Document what data is retained, how long it is retained, and how users can securely clear project and session history.

  7. Where stored context is expected to contain credentials or highly confidential information, use encryption at rest with keys protected separately from the JSON data.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The changelog states the skill can trigger on 'session_start, explicit mentions, heartbeat' without defining sufficiently narrow conditions. Broad or ambiguous triggers increase the chance the skill runs unintentionally, which is more concerning here because the skill can restore context, switch projects, and access persistent workspace memory automatically.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

Session persistence is an intentional feature here, but it still introduces a real security and privacy risk because prior-session data is restored automatically across sessions. In the context of a memory skill, that means sensitive project details can be surfaced to the wrong user/session or retained longer than expected if access controls, consent, and retention limits are not explicit.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: context-engine
description: Smart Context Engine - Maintains conversation state and project continuity across OpenClaw sessions. Tracks active projects, saves/restores context, and provides project management. Use when: (1) starting a new session and wanting to restore previous context, (2) working on a specific project and wanting to track progress, (3) switching between projects, (4) asking "what are we working on" or "where did we leave off", (5) wanting to save current context manually.

metadata:
  claname: context-engine

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that it automatically restores prior context and saves context periodically, but it does not prominently warn users that potentially sensitive details such as last commands, files, notes, and pending tasks may be persisted. This creates a privacy and data-handling risk because users may disclose information assuming the conversation is ephemeral when it is instead stored across sessions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes the generic term "project," which is broad enough to match ordinary conversation and cause the skill to activate unexpectedly. In a memory/persistence skill, unintended activation is more dangerous because it can save, reveal, or switch context based on incidental user phrasing rather than clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script persistently stores project metadata, notes, pending tasks, and session state under a fixed directory in the user's home folder without any consent prompt, disclosure, access-control hardening, or data minimization. Because this context can contain sensitive filenames, commands, notes, and task details, local compromise, multi-user access, backups, or accidental disclosure can expose private project information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The term "heartbeat辅助" mixes in Chinese language text in an action name, which may impose a language-specific convention without offering user choice or documenting why that locale is required. This can conflict with organizational language or locale expectations when not clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation shows commands that save and restore project context and explicitly lists the on-disk storage paths, but it does not warn users that any context they save may persist locally in plaintext-like JSON files under the workspace memory directory. This can lead users to store sensitive prompts, notes, filenames, or task details without realizing they are retained across sessions and potentially readable by other local processes or users with filesystem access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The restore flow automatically reloads prior session/project context and immediately updates session metadata on disk, which creates silent persistence and reuse of potentially sensitive state. While this is likely intended functionality, the lack of explicit disclosure or user confirmation increases the chance that old context is retained longer than expected and exposed through local file access or unintended cross-session reuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.