Back to skill

Security audit

AOMS - Always-On Memory Service

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local memory service, but it asks users to run persistent, mutable agent memory infrastructure with weak scoping and security guidance.

Install only if you intentionally want long-lived local agent memory. Before use, pin the package or container version, bind the service to 127.0.0.1, add authentication or network isolation, avoid storing secrets or regulated data, review any migration or ingestion input, and treat recalled memories as untrusted notes rather than instructions for the agent to follow.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:95
Finding

Persistent Agent Memory Is Injected into Future Sessions Without a Trust Boundary

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:29
Finding

Documented Deployment Can Expose a Mutable Memory API Without Authentication

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Installation Instructions Use Unpinned Executable Dependencies and a Mutable Container Tag

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
references/openclaw-setup.md:9
Finding

Always-Restarting Service Configuration Creates Cross-Session Persistence Without Hardening

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description is broad enough to trigger on many generic requests about memory, learning, recall, or long-term context, increasing the chance the skill is invoked in contexts where persistent storage is not appropriate. Over-broad activation is dangerous here because the skill is explicitly designed to store and later reinject prior task data into prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill promotes storing experiences, facts, and skills persistently, but the warning language does not clearly emphasize that task data, agent-generated content, and potentially sensitive workspace-derived information will be written to disk and reused later. Users may unknowingly persist secrets, proprietary code details, or personal data beyond the current session.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill instructs users to pull a Docker image using the mutable latest tag, which prevents reproducible builds and allows upstream image changes to silently alter what gets executed later. If the registry account or tag is compromised, users may run an unexpected or malicious image without noticing.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The docker run example executes the same unpinned image reference, so runtime behavior depends on whatever image the mutable tag resolves to at that moment. This creates supply-chain risk and weakens auditability and rollback safety.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The quick-reference 'Write Memory' guidance normalizes persistent storage of task-derived information without surrounding boundaries on what should not be retained. In a skill centered on memory, this increases the likelihood of indiscriminate retention of sensitive session content across runs.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

API Quick Reference

Write Memory

bash
curl -X POST http://localhost:9100/memory/episodic \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Write Memory

bash
curl -X POST http://localhost:9100/memory/episodic \
  -H "Content-Type: application/json" \
  -d '{
    "type": "experience",

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The session-boot recall pattern instructs agents to fetch prior memories and inject them directly into prompts, which can cause sensitive or stale information to be reintroduced into unrelated future tasks. Without minimization, scoping, or sensitivity filtering, this creates cross-task data leakage and prompt-context contamination risks.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guidance to log learnings after tasks and migrate existing workspace memory encourages broad retention of historical inputs and logs into a persistent store, potentially sweeping in secrets, credentials, proprietary information, or personal data. Because the skill is for long-term memory, overcollection here materially increases privacy and data-governance exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

Adding a workspace boot script that automatically recalls and prints stored context at every session start creates persistent cross-session state injection without strong user review. This can surface sensitive historical data in new sessions and cause the agent to act on stale, over-broad, or attacker-planted memories.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

2. Session boot script

Add a boot script to your workspace (see references/openclaw-setup.md for a full example):

python
# boot_aoms.py — call at session start

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The API reference encourages persistent storage and retrieval of free-form memory content, including experiences, titles, outcomes, and tags, without any warning about storing sensitive, personal, or secret data. In a long-term agent memory system, users may unknowingly persist credentials, proprietary context, or regulated data, increasing confidentiality and compliance risk over time.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented GET /memory/browse/{path} endpoint exposes arbitrary module-tree browsing and file content access, which is outside the core memory-service purpose and creates a strong risk of local file disclosure. In an agent-integrated service, this is especially dangerous because agents may be induced to read secrets, source files, tokens, or other sensitive local data through a seemingly legitimate memory API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document ingestion and entity extraction endpoints accept full document text and optionally store extracted relations, but the documentation does not warn that sensitive content may be transmitted to the service and retained or processed by external components such as Ollama. Because these endpoints are designed for broad contextual ingestion, they increase the chance of bulk exposure of confidential documents and metadata.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The setup instructs users to automatically run a boot script every session that retrieves persistent memory context and displays it to the agent/operator. In an agent setting, this creates durable cross-session context injection and may reintroduce stale, sensitive, or adversarially planted content into future sessions without fresh validation.

Content

Scanner excerpt · references/openclaw-setup.md (reported line 54)May include surrounding context.

4. Session Boot Script

Create a boot script in your workspace:

python
# boot_aoms.py

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/openclaw-setup.md (reported line 61)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · SKILL.md (reported line 201)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · references/openclaw-setup.md (reported line 61)May include surrounding context.

md
import httpx, sys

try:
    r = httpx.post("http://localhost:9100/recall", json={
        "task": "session boot — what's recent and relevant",
        "token_budget": 300,
        "format": "markdown"

Static analysis

No suspicious patterns detected.