T08 · Insecure Dependencies
- Location
package.json:7- Finding
Mutable and Unpinned Executable Dependencies Create a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill is mostly coherent, but it gives a separately installed sibling extension broad OpenClaw API access while also enabling broad cloud-backed memory capture and search.
Install only if you are comfortable with SuperMemory receiving memory queries and captured conversation-derived content, and only after verifying the exact sibling extension version. Prefer disabling autoCapture or narrowing capture scope for sensitive work, pin dependencies and installer versions, and treat the sibling SuperMemory extension as having broad OpenClaw plugin privileges until the proxy is restricted.
package.json:7Mutable and Unpinned Executable Dependencies Create a Supply-Chain Risk
proxy-api.ts:68Sibling Extension Receives Broad Access to the Real OpenClaw Plugin API
The declared description claims a broad composite memory integration layer with dual-provider operation, merged searches, mirrored writes, and dreaming support. This code chunk only constructs prompt text from two builders and filters out specific conflicting cloud instructions. That is related to integrating local and cloud memory guidance, but it does not implement the main declared capabilities. Therefore the description materially overstates what this supplied code chunk actually does.
The declared description promises a full composite memory solution: local memory-core plus external provider together, merged searches across all backends, writes to both, and full dreaming support. This code only builds a runtime facade. It obtains local and cloud managers, but the returned composite manager is constructed only from the local manager and a cloudSearchFn; the cloud manager itself is not used for read/write operations in this chunk. There is no implementation here of write fan-out to both providers, no explicit dreaming support, and no direct demonstration of search merging across all backends except a dependency on another class. While this file is related to the declared purpose, it does not substantiate several core promised capabilities, so the description overstates what this code chunk actually does.
The description claims a full composite proxy for local and external memory providers with merged search results, cloud persistence, dual writes, and full dreaming support. The code only substantiates part of that: merged search across a local backend and a cloud search function. There is no cloud write API, no mechanism to persist data to the external provider, and sync() only calls the local backend. Dreaming support is not implemented here; at most, the class preserves whatever the local backend already supports by delegating status/probe/read/sync/close. So the code’s actual behavior is materially narrower than the declared purpose.
Referenced artifact was not completely inspected
| `index.ts` | Entry point — loads backends, registers composite |
This plugin is a memory component whose stated purpose is to send data to a cloud provider for persistence, yet the manifest provides no prominent privacy warning, consent language, retention notice, or explanation of what may leave the local environment. Because memory plugins can process highly sensitive conversational context, automatic capture plus off-device storage creates a substantial privacy and compliance risk if users are not clearly warned and asked to consent.
The README enables autoRecall and autoCapture by default for a cloud-backed memory provider, but it does not clearly warn that conversation content and other potentially sensitive data may be transmitted to a third-party service. In a memory plugin, especially one advertised as capturing 'everything' and persisting across sessions/devices, lack of explicit privacy and data-handling disclosure can lead users to deploy it without understanding the exposure of secrets, personal data, or proprietary prompts.
The skill declares use of an environment variable API key but does not declare any explicit tool scope or permissions boundary. In a plugin that bridges local memory with a cloud provider, undeclared env access reduces transparency and makes it harder for operators to assess what secrets the skill may consume.
Using npx clawhub@latest install dual-memory pulls and executes the latest package version at install time, which creates a supply-chain risk. If the upstream package or dependency chain is compromised, users may execute attacker-controlled code during installation.
The instruction npx clawhub@latest install supermemory has the same unpinned remote execution risk as other @latest installs. This is especially sensitive because the skill depends on a sibling extension that will gain access to memory data and an API key.
The sample configuration enables autoCapture: true with captureMode: "everything", instructing the cloud memory provider to automatically collect all conversation content. In the context of an agent memory plugin, this can transmit sensitive prompts, credentials, personal data, and workspace-derived context to a third-party service without meaningful minimization.
The documentation explicitly states that the external provider automatically captures conversation content, confirming continuous transfer of agent interactions to a cloud service. Given this skill's purpose as a memory aggregator, the context increases risk because users may route especially sensitive long-term context through it and assume local-memory semantics still apply.
The composite manager sends the raw search query to a remote cloud provider whenever cloudSearch is configured, with no consent gate, disclosure, redaction, or policy enforcement visible in this component. In a memory/search subsystem, queries can contain sensitive prompts, secrets, file names, or personal data, so silent transmission to a third party creates a real confidentiality and privacy risk.
The composite search function sends user memory queries to SuperMemory and returns remote results, but this file provides no explicit runtime disclosure, consent gate, or query-scope restriction. Because memory queries can contain sensitive prompts, notes, or personal data, transmitting them to a third-party cloud backend materially changes the privacy and trust boundary of the skill.
The apiKey templating logic expands any ${ENV_VAR} placeholder against process.env, allowing the skill to read arbitrary environment variables rather than only a dedicated SuperMemory secret. In a plugin that already forwards data to an external cloud memory provider, this broad secret-resolution behavior increases the risk of accidental or intentional exfiltration of unrelated credentials if configuration is influenced by an untrusted party.
This code resolves a sensitive API key from config or environment with no accompanying consent, disclosure, or visibility in this file that cloud credentials will be consumed. In isolation that is not code-execution dangerous, but for a memory plugin that bridges local data to a third-party service, silent secret use weakens informed consent and can cause operators to unknowingly authorize external data flows.
The manifest explicitly advertises cloud memory persistence and includes broad automatic collection settings such as autoCapture and captureMode without any manifest-level indication of what data is eligible for capture, when capture is triggered, or what safeguards limit sensitive content from being uploaded. In a memory plugin, that ambiguity is dangerous because conversations, credentials, proprietary data, or user prompts may be forwarded to an external provider more broadly than the user expects.
The production dependency supermemory is specified with a caret range, which allows newer minor/patch releases to be installed without review. In a security-sensitive plugin that brokers local and cloud memory providers, an unexpected upstream change or compromised release could alter runtime behavior or introduce a supply-chain issue.
"description": "Dual memory plugin: memory-core (local + dreaming) + supermemory (cloud). Requires SUPERMEMORY_OPENCLAW_API_KEY env var.",
"license": "MIT",
"dependencies": {
"supermemory": "^4.0.0",
"@sinclair/typebox": "0.34.47"
},
"peerDependencies": {
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
}
},
"devDependencies": {
"typescript": "^5.9.3"
}
}
No suspicious patterns detected.