T01 · Skill Instruction Hijacking
- Location
openclaw_hooks/nima-recall-live/index.js:584- Finding
Persistent indirect prompt injection through recalled memories
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a powerful persistent memory system, but it asks for and uses sensitive long-term access in ways that are broader and less clearly controlled than its main description suggests.
Review before installing. Use local embeddings unless you explicitly want remote processing, avoid running the installer against mutable branches without pinning a commit, do not run doctor.sh with an untrusted ~/.nima/.env, disable or review precognitive cron jobs, and treat stored memories as sensitive data because chats, thinking-like content, affect state, and recalled context can persist across sessions.
openclaw_hooks/nima-recall-live/index.js:584Persistent indirect prompt injection through recalled memories
nima_core/cognition/sparse_block_memory.py:1475Arbitrary code execution through automatic legacy pickle deserialization
install.sh:22Installer retrieves and executes mutable remote code and unpinned dependencies
scripts/doctor.sh:12Diagnostic script executes shell commands from the NIMA environment file
openclaw_hooks/nima-memory/index.js:1714Automatic compaction hook can send stored conversation text to Voyage without a provider gate
nima_core/llm_client.py:52Custom LLM base URLs can receive API credentials and private memory-derived prompts over arbitrary HTTP or HTTPS endpoints
nima_core/cognition/precog_actions.py:283Precognitive actions access undeclared workspace files, logs, repositories, and calendar data
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
headers={"Authorization": f"Bearer {api_key}", "Content-Type": "application/json"},
method="POST"
)
with urllib.request.urlopen(req, timeout=8) as resp:
data = _json.loads(resp.read())
emb = data["data"][0]["embedding"]
if verbose: print(f"[ladybug_recall] ✅ Voyage embedding (API): {len(emb)}D", file=sys.stderr)
The documentation states that the system persistently captures conversations and emotional state but does not provide a clear privacy warning, retention notice, or consent flow. Because this includes sensitive personal content and inferred affect, deployment without explicit notice can violate privacy expectations and increase harm from compromise or misuse.
The documented memory flow explicitly stores input, contemplation, and output in a database, directing broad retention of both user data and model reasoning. This is especially dangerous because the recall hook later reinjects stored content into prompts, increasing the blast radius from any sensitive data captured once.
The configuration section explicitly promotes capturing user input, contemplation, and output as memories, which is a direct instruction for over-collection. Such broad default collection is hazardous because it normalizes storage of secrets, personal data, and hidden chain-of-thought-like content without necessity controls.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
An attacker controlling these inputs could potentially:
- **Exfiltrate sensitive data** using comment injection to bypass query logic
- **Modify or delete memory nodes** using query termination and chained queries
- **Cause denial of service** through malformed queries or excessive resource consumption
- **Bypass access controls** using boolean logic injection (e.g., `' OR '1'='1`)
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
An attacker controlling these inputs could potentially:
- **Exfiltrate sensitive data** using comment injection to bypass query logic
- **Modify or delete memory nodes** using query termination and chained queries
- **Cause denial of service** through malformed queries or excessive resource consumption
- **Bypass access controls** using boolean logic injection (e.g., `' OR '1'='1`)
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.
No suspicious patterns detected.