Back to skill

Security audit

Nima Core

Security checks for vulnerabilities and agentic risk

Overview

This skill is a powerful persistent memory system, but it asks for and uses sensitive long-term access in ways that are broader and less clearly controlled than its main description suggests.

Review before installing. Use local embeddings unless you explicitly want remote processing, avoid running the installer against mutable branches without pinning a commit, do not run doctor.sh with an untrusted ~/.nima/.env, disable or review precognitive cron jobs, and treat stored memories as sensitive data because chats, thinking-like content, affect state, and recalled context can persist across sessions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T01 · Skill Instruction Hijacking

Error
Location
openclaw_hooks/nima-recall-live/index.js:584
Finding

Persistent indirect prompt injection through recalled memories

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
nima_core/cognition/sparse_block_memory.py:1475
Finding

Arbitrary code execution through automatic legacy pickle deserialization

Content
View full analysis
None: """Best-effort SHA-256 verification for legacy pickle files.""" hash_path = filepath.with_suffix(filepath.suffix + '.sha256') if not hash_path.exists(): print(f"⚠️ Warning: No integrity hash found for {filepath}") return try: with open(hash_path, 'r') as f: hash_data = json.load(f) expected_hash = hash_data.get('hash') if not expected_hash: return with open(filepath, 'rb') as f: actual_hash = hashlib.sha256(f.read()).hexdigest() if actual_hash != expected_hash: raise IntegrityError( f"Memory file integrity check FAILED for {filepath}!\n" f"Expected: {expected_hash}\n" f"Actual: {actual_hash}\n" "This could indicate file corruption or tampering." ) print(f"✅ Integrity verified for {filepath}") except (json.JSONDecodeError, KeyError) as e: print(f"⚠️ Warning: Could not verify integrity: {e}") ``` ```python def load(self, filepath: str, verify_integrity: bool = True): filepath = Path(filepath) if not filepath.exists(): raise FileNotFoundError(f"Memory file not found: {filepath}") if self._is_json_file(filepath): self.safe_load(str(filepath), verify=verify_integrity) return import pickle self._warn_legacy_pickle(filepath) if verify_integrity: self._verify_legacy_pickle_integrity(filepath) # Load with pickle (verified above) with open(filepath, 'rb') as f: state = pickle.load(f) self._restore_legacy_pickle_state(state) ``` ### Technical Analysis Python pickle deserializatio ...[truncated 1792 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:22
Finding

Installer retrieves and executes mutable remote code and unpinned dependencies

Content
View full analysis
/dev/null; then echo "✅ Python dependencies installed" elif python3 -m pip install -r requirements.txt --quiet --break-system-packages 2>/dev/null; then echo "✅ Python dependencies installed (--break-system-packages)" fi ``` ```bash python3 -m pip install real-ladybug --quiet ``` ```text numpy>=1.24.0 ``` ```python install_requires=[ "numpy>=1.24.0", ], extras_require={ "vector": [ "faiss-cpu>=1.7.4", "voyageai>=0.2.0", ], }, ``` ### Technical Analysis The installer does not limit itself to installing the audited artifact. It clones or updates a mutable Git branch and then installs dependencies whose versions are expressed as lower bounds without hashes. A branch can point to different code after the audit. Likewise, dependency resolution can select future package versions that were not reviewed. The `--break-system-packages` fallback can also modify the interpreter's system-managed environment. Provenance is further weakened by inconsistent metadata observed across the package: versions `2.3.0`, `3.1.0`, `3.1.5`, and `3.3.3` are present, while repository identity differs between `nima-project/nima-core` and `lilubot/nima-core`. ### Attack Path 1. An upstream repository account, mutable branch, package-index release, or dependency publishing account is compromised. 2. The attacker changes the bran ...[truncated 800 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/doctor.sh:12
Finding

Diagnostic script executes shell commands from the NIMA environment file

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
openclaw_hooks/nima-memory/index.js:1714
Finding

Automatic compaction hook can send stored conversation text to Voyage without a provider gate

Content
View full analysis
{ try { log.info?.(`[nima-memory] Compaction complete (compacted ${event.compactedCount} messages, ${event.messageCount} remain)`); // Trigger embedding indexing for newly stored memories const embeddingScript = join(MEMORY_DIR, "..", "..", "openclaw_hooks", "nima-memory", "embeddings.py"); if (existsSync(embeddingScript)) { try { const result = await execPython("python3", [embeddingScript, "backfill", "--batch-size", "100"], { timeout: 30000, encoding: "utf-8", cwd: dirname(embeddingScript), breakerId: "embeddings" }); log.info?.(`[nima-memory] Embedding index updated: ${result.trim()}`); } catch (embErr) { log.warn?.(`[nima-memory] Embedding indexing failed (non-critical): ${embErr.message}`); } } } catch (err) { console.error(`[nima-memory] after_compaction error: ${err.message}`); } }); ``` ```python def embed_texts(client, texts, use_cache=True): truncated = [t[:MAX_TEXT_CHARS] if t else "" for t in texts] valid = [(i, t) for i, t in enumerate(truncated) if t.strip()] if not valid: return [None] * len(texts) indices, valid_texts = zip(*valid) if use_cache: cached_client = get_cached_client() if cached_client: embeddings_list = cached_client.embed_batch(list(valid_texts)) embeddings = [None] * len(texts) for idx, emb in zip(indices, embeddings_list): if emb is not None: embeddings[idx] = emb.tolist() return embeddings result = client.embed(list(valid_te ...[truncated 2144 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
nima_core/llm_client.py:52
Finding

Custom LLM base URLs can receive API credentials and private memory-derived prompts over arbitrary HTTP or HTTPS endpoints

Content
View full analysis
Dict[str, Any]: base = base_url.rstrip("/") return { "provider": "openai", "base_url": base, "model": model, "key": key, "headers": {"Authorization": f"Bearer {key}", "Content-Type": APPLICATION_JSON}, "endpoint": f"{base}/chat/completions", "response_path": ["choices", 0, "message", "content"], } ``` ```python def _anthropic_config(key: str, base_url: str, model: str) -> Dict[str, Any]: base = base_url.rstrip("/") endpoint = (base + "/messages") if base.endswith("/v1") else (base + "/v1/messages") return { "provider": "anthropic", "base_url": base, "model": model, "key": key, "headers": { "x-api-key": key, "anthropic-version": "2023-06-01", "content-type": APPLICATION_JSON }, "endpoint": endpoint, "response_path": ["content", 0, "text"], } ``` ```python endpoint = config.get("endpoint") if not endpoint: return None parsed = urlparse(endpoint) if parsed.scheme not in ("http", "https"): logger.warning("Invalid URL scheme in endpoint: %s", endpoint) return None ``` ```python req = urllib.request.Request( endpoint, data=json.dumps(payload).encode("utf-8"), headers=dict(config["headers"]), method="POST", ) with urllib.request.urlopen(req, timeout=timeout) as resp: data = json.loads(resp.read().decode("utf-8")) ``` ### Technical Analysis The only endpoint restriction is that the URL scheme must be `http` or `https`. There is no provider-host allowlist, no prohibition on cleartext HTTP, and no binding between a credential and the domain fo ...[truncated 1410 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
nima_core/cognition/precog_actions.py:283
Finding

Precognitive actions access undeclared workspace files, logs, repositories, and calendar data

Content
View full analysis
str: """Run command as list of args (no shell=True), return stdout.""" try: r = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout) return r.stdout.strip()[:500] except (subprocess.TimeoutExpired, subprocess.CalledProcessError, OSError, FileNotFoundError) as e: logger.warning("Command failed: %s", e) return "" ``` ```python def git_status() -> str: repos = [WORKSPACE] results = [] for repo in repos: if (repo / ".git").exists(): status = _run(["git", "-C", str(repo), "status", "--short"], timeout=5) status = "\n".join(status.split("\n")[:5]) branch = _run(["git", "-C", str(repo), "branch", "--show-current"], timeout=5) ``` ```python def open_prs() -> str: return _run([ "gh", "pr", "list", "--limit", "3", "--json", "number,title", "--jq", '.[] | "#\\(.number) \\(.title)"' ], timeout=10) ``` ```python def check_calendar() -> str: """Check upcoming calendar events (if available).""" result = _run(["icalBuddy", "-n", "-nc", "-li", "3", "eventsToday+2"], timeout=5) return result[:300] if result else "no calendar access" ``` ```python def check_docs() -> str: docs_dir = WORKSPACE / "docs" if not docs_dir.exists(): docs_dir = WORKSPACE recent = sorted( [f for f in docs_dir.glob("**/*.md") if ".git" not in str(f)], key=lambda p: p.stat().st_mtime, reverse=True )[:3] return " | ".join(p.name for p in recent) ``` ```python def load_spreadsheets() -> str: exts = ["*.csv", "*.xlsx", "*.tsv", "*.json"] files = [] for ext in exts: files.extend(WORKSPACE. ...[truncated 2357 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (238)

Tainted flow: 'req' from os.environ.get (line 375, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · openclaw_hooks/nima-recall-live/ladybug_recall.py (reported line 381)May include surrounding context.

python
headers={"Authorization": f"Bearer {api_key}", "Content-Type": "application/json"},
            method="POST"
        )
        with urllib.request.urlopen(req, timeout=8) as resp:
            data = _json.loads(resp.read())
            emb = data["data"][0]["embedding"]
            if verbose: print(f"[ladybug_recall] ✅ Voyage embedding (API): {len(emb)}D", file=sys.stderr)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states that the system persistently captures conversations and emotional state but does not provide a clear privacy warning, retention notice, or consent flow. Because this includes sensitive personal content and inferred affect, deployment without explicit notice can violate privacy expectations and increase harm from compromise or misuse.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented memory flow explicitly stores input, contemplation, and output in a database, directing broad retention of both user data and model reasoning. This is especially dangerous because the recall hook later reinjects stored content into prompts, increasing the blast radius from any sensitive data captured once.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The configuration section explicitly promotes capturing user input, contemplation, and output as memories, which is a direct instruction for over-collection. Such broad default collection is hazardous because it normalizes storage of secrets, personal data, and hidden chain-of-thought-like content without necessity controls.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SECURITY.md (reported line 28)May include surrounding context.

md
An attacker controlling these inputs could potentially:

- **Exfiltrate sensitive data** using comment injection to bypass query logic
- **Modify or delete memory nodes** using query termination and chained queries
- **Cause denial of service** through malformed queries or excessive resource consumption
- **Bypass access controls** using boolean logic injection (e.g., `' OR '1'='1`)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · nima_core/hive_mind.py (reported line 50)May include surrounding context.

python
An attacker controlling these inputs could potentially:

- **Exfiltrate sensitive data** using comment injection to bypass query logic
- **Modify or delete memory nodes** using query termination and chained queries
- **Cause denial of service** through malformed queries or excessive resource consumption
- **Bypass access controls** using boolean logic injection (e.g., `' OR '1'='1`)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If only Voyage embeddings are effectively supported while the skill claims broader providers and zero-config install, users may unintentionally route transcript content to an external service or discover hidden setup/network dependencies only after deployment. For a memory system handling agent transcripts, inaccurate network-default claims directly affect privacy expectations and trust.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.