Back to skill

Security audit

Dual memory

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is mostly coherent, but it gives a separately installed sibling extension broad OpenClaw API access while also enabling broad cloud-backed memory capture and search.

Install only if you are comfortable with SuperMemory receiving memory queries and captured conversation-derived content, and only after verifying the exact sibling extension version. Prefer disabling autoCapture or narrowing capture scope for sensitive work, pin dependencies and installer versions, and treat the sibling SuperMemory extension as having broad OpenClaw plugin privileges until the proxy is restricted.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
package.json:7
Finding

Mutable and Unpinned Executable Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
proxy-api.ts:68
Finding

Sibling Extension Receives Broad Access to the Real OpenClaw Plugin API

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description claims a broad composite memory integration layer with dual-provider operation, merged searches, mirrored writes, and dreaming support. This code chunk only constructs prompt text from two builders and filters out specific conflicting cloud instructions. That is related to integrating local and cloud memory guidance, but it does not implement the main declared capabilities. Therefore the description materially overstates what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description promises a full composite memory solution: local memory-core plus external provider together, merged searches across all backends, writes to both, and full dreaming support. This code only builds a runtime facade. It obtains local and cloud managers, but the returned composite manager is constructed only from the local manager and a cloudSearchFn; the cloud manager itself is not used for read/write operations in this chunk. There is no implementation here of write fan-out to both providers, no explicit dreaming support, and no direct demonstration of search merging across all backends except a dependency on another class. While this file is related to the declared purpose, it does not substantiate several core promised capabilities, so the description overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims a full composite proxy for local and external memory providers with merged search results, cloud persistence, dual writes, and full dreaming support. The code only substantiates part of that: merged search across a local backend and a cloud search function. There is no cloud write API, no mechanism to persist data to the external provider, and sync() only calls the local backend. Dreaming support is not implemented here; at most, the class preserves whatever the local backend already supports by delegating status/probe/read/sync/close. So the code’s actual behavior is materially narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
| `index.ts` | Entry point — loads backends, registers composite |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This plugin is a memory component whose stated purpose is to send data to a cloud provider for persistence, yet the manifest provides no prominent privacy warning, consent language, retention notice, or explanation of what may leave the local environment. Because memory plugins can process highly sensitive conversational context, automatic capture plus off-device storage creates a substantial privacy and compliance risk if users are not clearly warned and asked to consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README enables autoRecall and autoCapture by default for a cloud-backed memory provider, but it does not clearly warn that conversation content and other potentially sensitive data may be transmitted to a third-party service. In a memory plugin, especially one advertised as capturing 'everything' and persisting across sessions/devices, lack of explicit privacy and data-handling disclosure can lead users to deploy it without understanding the exposure of secrets, personal data, or proprietary prompts.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares use of an environment variable API key but does not declare any explicit tool scope or permissions boundary. In a plugin that bridges local memory with a cloud provider, undeclared env access reduces transparency and makes it harder for operators to assess what secrets the skill may consume.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx clawhub@latest install dual-memory pulls and executes the latest package version at install time, which creates a supply-chain risk. If the upstream package or dependency chain is compromised, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The instruction npx clawhub@latest install supermemory has the same unpinned remote execution risk as other @latest installs. This is especially sensitive because the skill depends on a sibling extension that will gain access to memory data and an API key.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The sample configuration enables autoCapture: true with captureMode: "everything", instructing the cloud memory provider to automatically collect all conversation content. In the context of an agent memory plugin, this can transmit sensitive prompts, credentials, personal data, and workspace-derived context to a third-party service without meaningful minimization.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly states that the external provider automatically captures conversation content, confirming continuous transfer of agent interactions to a cloud service. Given this skill's purpose as a memory aggregator, the context increases risk because users may route especially sensitive long-term context through it and assume local-memory semantics still apply.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The composite manager sends the raw search query to a remote cloud provider whenever cloudSearch is configured, with no consent gate, disclosure, redaction, or policy enforcement visible in this component. In a memory/search subsystem, queries can contain sensitive prompts, secrets, file names, or personal data, so silent transmission to a third party creates a real confidentiality and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The composite search function sends user memory queries to SuperMemory and returns remote results, but this file provides no explicit runtime disclosure, consent gate, or query-scope restriction. Because memory queries can contain sensitive prompts, notes, or personal data, transmitting them to a third-party cloud backend materially changes the privacy and trust boundary of the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The apiKey templating logic expands any ${ENV_VAR} placeholder against process.env, allowing the skill to read arbitrary environment variables rather than only a dedicated SuperMemory secret. In a plugin that already forwards data to an external cloud memory provider, this broad secret-resolution behavior increases the risk of accidental or intentional exfiltration of unrelated credentials if configuration is influenced by an untrusted party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code resolves a sensitive API key from config or environment with no accompanying consent, disclosure, or visibility in this file that cloud credentials will be consumed. In isolation that is not code-execution dangerous, but for a memory plugin that bridges local data to a third-party service, silent secret use weakens informed consent and can cause operators to unknowingly authorize external data flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly advertises cloud memory persistence and includes broad automatic collection settings such as autoCapture and captureMode without any manifest-level indication of what data is eligible for capture, when capture is triggered, or what safeguards limit sensitive content from being uploaded. In a memory plugin, that ambiguity is dangerous because conversations, credentials, proprietary data, or user prompts may be forwarded to an external provider more broadly than the user expects.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The production dependency supermemory is specified with a caret range, which allows newer minor/patch releases to be installed without review. In a security-sensitive plugin that brokers local and cloud memory providers, an unexpected upstream change or compromised release could alter runtime behavior or introduce a supply-chain issue.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"description": "Dual memory plugin: memory-core (local + dreaming) + supermemory (cloud). Requires SUPERMEMORY_OPENCLAW_API_KEY env var.",
	"license": "MIT",
	"dependencies": {
		"supermemory": "^4.0.0",
		"@sinclair/typebox": "0.34.47"
	},
	"peerDependencies": {

Unverifiable Dependency: openclaw has 16 known advisory(ies) (CVE-2026-53846 (OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency); CVE-2026-32064 (OpenClaw's andbox browser noVNC observer lacked VNC authentication); CVE-2026-32006 (OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallbac) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
}
	},
	"devDependencies": {
		"typescript": "^5.9.3"
	}
}

Static analysis

No suspicious patterns detected.