Back to skill

Security audit

Auto Memory

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is purpose-aligned but needs Review because it stores and shares conversation content broadly, sends unredacted memory to a configured LLM endpoint, and contains an agent-id code-execution flaw.

Review this skill carefully before installing. It is not clearly malicious, but it can retain private conversation content long term, share selected content across agents, index it for later retrieval, and send recent memory text to the configured model provider. Avoid using it with secrets or confidential data unless the scripts are fixed to redact before persistence and network use, require confirmation for shared writes, validate agent identifiers, and pin the installer version.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
weekly-distill.sh:29
Finding

Arbitrary Python Code Execution Through Unvalidated Agent Identifier

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi ``` - Canonicalize the resulting workspace path and verify that it remains beneath the expected OpenClaw workspace root. - Add regression tests using identifiers containing quotes, semicolons, newlines, command substitutions, and path traversal sequences. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
smart-summarize.sh:42
Finding

Unredacted Conversation Memory Is Transmitted to a Configured LLM Endpoint

Content
View full analysis
2000 else content request_data = { "model": model, "messages": [{ "role": "user", "content": f"用3个要点总结以下内容(每点10字内):\n{recent_content[:1500]}" }], "max_tokens": 100 } req = urllib.request.Request( f"{base_url}/chat/completions", data=json.dumps(request_data).encode('utf-8'), headers={ "Authorization": f"Bearer {api_key}", "Content-Type": "application/json" } ) with urllib.request.urlopen(req, timeout=15) as response: result = json.loads(response.read().decode('utf-8')) summary = result.get('choices', [{}])[0].get('message', {}).get('content', '') except Exception: pass # 回退到关键词 ``` ### Technical Analysis The script reads persistent conversation memory and sends up to 1,500 characters from its latest 2,000 characters to the endpoint specified by `baseUrl`. No redaction is performed before constructing the request. The implementation does not detec ...[truncated 1784 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
extract-memory.sh:106
Finding

Unredacted Session Content Is Persisted and Propagated Across Agents

Content
View full analysis
200: content = content[:200] + "..." f.write(f"**{role_label}**: {content}\n\n") ``` Correction-like user content is written to persistent learning state: ```python if learnings_to_add: with open(learnings_file, 'a') as f: for l in learnings_to_add: f.write(f"\n## [LRN-{datetime.now().strftime('%Y%m%d%H%M')}] {l['type']}\n\n") f.write(f"**Logged**: {datetime.now().isoformat()}\n") f.write(f"**Priority**: {l['priority']}\n") f.write(f"**Status**: pending\n\n") f.write(f"### Summary\n{l['content']}\n\n---\n") ``` Error content may be copied to a global shared file: ```python shared = [e for e in errors_to_add if e.get('shared')] if shared: with open(shared_errors, 'a') as f: for e in shared: f.write(f"\n## [SHARED-ERR-{datetime.now().strftime('%Y%m%d%H%M')}]\n\n") f.write(f"**Source**: {agent_id}\n") f.w ...[truncated 3055 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:19
Finding

Installation Guidance Executes an Unpinned Mutable Package Release

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill claims semantic understanding, intelligent summarization, and sensitive-data protection, but the file provides no auditable implementation evidence for those protections. Security-relevant overclaiming is a real risk because users may expose confidential content believing the system meaningfully filters or protects it when it may not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims semantic understanding, intelligent summarization, and sensitive-data protection, but the file provides no auditable implementation evidence for those protections. Security-relevant overclaiming is a real risk because users may expose confidential content believing the system meaningfully filters or protects it when it may not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill claims semantic understanding, intelligent summarization, and sensitive-data protection, but the file provides no auditable implementation evidence for those protections. Security-relevant overclaiming is a real risk because users may expose confidential content believing the system meaningfully filters or protects it when it may not.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill claims semantic understanding, intelligent summarization, and sensitive-data protection, but the file provides no auditable implementation evidence for those protections. Security-relevant overclaiming is a real risk because users may expose confidential content believing the system meaningfully filters or protects it when it may not.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill’s stated behavior explicitly includes persistent collection, summarization, reuse, and cross-agent sharing of conversation content across multiple stores. In the context of a memory-management skill, persistence is expected, but the breadth of reuse and sharing without strict minimization, consent, and sensitivity controls makes this materially dangerous.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script stores user and assistant messages into a persistent memory file using broad heuristics such as length and keyword presence, which will capture ordinary plain-language content including potentially sensitive information. There is no effective redaction beyond skipping a couple of system-like prefixes, so confidentiality-sensitive text can be retained long term.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code copies user message content into error, learning, and best-practice logs and shares selected entries into common cross-agent files based on simple keyword matching like API, network, config, or permissions. This is especially dangerous because those categories are exactly where users often mention tokens, endpoints, internal architecture, access problems, or security-sensitive troubleshooting details, making accidental propagation of secrets and confidential data likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that all conversations are automatically recorded to session files and that the skill extracts important dialogue into persistent memory files, but it does not prominently warn users about retention, privacy, or possible capture of sensitive data. In the context of an automatic memory system, this increases the chance that credentials, personal data, or confidential business information will be stored and propagated without informed consent or operator safeguards.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to execute npx clawhub@latest install auto-memory, which fetches and runs the latest remote package code without pinning to a specific version. This creates a supply-chain risk: a compromised upstream package, malicious publish, or breaking update could result in unintended code execution during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documentation instructs creation and execution of local scripts that read/write workspace memory and appear to invoke LLM-backed analysis, but the manifest declares no explicit tool scope or permissions. That mismatch prevents users and platforms from understanding that the skill can persist conversation-derived data, access files, and potentially make networked model calls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is explicitly designed to persist conversation-derived memory into daily logs, long-term memory files, and an index, yet the description does not provide a clear user warning about automatic persistent storage. This can lead to unintentional retention of sensitive or regulated data far beyond the current session.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The installation instructions create persistent directories under the user's home/workspace for scripts, archives, and shared learnings, confirming session-to-session data retention. Persistent storage is not automatically malicious, but in a memory skill it increases privacy risk because conversation-derived content may accumulate, be shared across runs, and remain after the user expects it to be gone.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

bash
# 创建目录
mkdir -p ~/.openclaw/scripts
mkdir -p ~/.openclaw/workspace/memory/archive
mkdir -p ~/.openclaw/workspace/.learnings/shared

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Comments and runtime messages are predominantly in Chinese, which effectively imposes a language choice on users and operators of the script. The file does not indicate that Chinese is optional, configurable, or required for a justified region-specific use case.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script is designed to copy extracted conversation-derived content into shared cross-agent files under a common workspace, which expands access beyond the originating agent. Because the content is derived from user and assistant sessions using broad heuristics and no consent gate or sanitization, this creates a real confidentiality and data-boundary violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code writes session-derived user content into persistent memory, learning, error, and shared files without any explicit warning, consent, or review step. This is dangerous because users may disclose secrets, personal data, credentials, or confidential project details in ordinary conversation, and the script persists and redistributes them automatically.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script invokes external commands that update indexes and optionally run a weekly maintenance script, creating side effects outside simple extraction. In a security review, hidden or undocumented secondary execution paths are risky because they increase trust assumptions and may process or transform sensitive memory further than expected.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Running an unrelated weekly external script from a memory-extraction workflow widens the attack surface and introduces behavior not clearly tied to the core function. If the maintenance script is replaced, misconfigured, or more permissive than expected, it can access or transform accumulated memory without clear user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The comments and user-facing echo messages in this script are written in Chinese, which imposes a specific language on users without any opt-in or locale selection. The policy requires either user choice or clear justification for locale constraints; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The runtime output shown via echo uses Chinese-only text such as status and completion messages. This can violate language/locale policy because the script does not offer users a language choice or state that the tool is region- or language-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script transmits up to ~1500 characters of the memory file to a remote LLM endpoint using credentials and a base URL from local configuration. Because this skill is specifically positioned as a memory/protection component, exporting memory contents off-host without explicit consent or robust redaction creates a real confidentiality risk, especially if the memory file contains prompts, secrets, personal data, or operational context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sends memory content to an external model API without any explicit warning, consent prompt, or indication in the shell script output that local memory is being exfiltrated to a third party. This is dangerous because users may reasonably expect a memory-management skill to operate locally, and the transmitted content may include sensitive internal notes or user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script appends to or creates MEMORY.md based on recent note contents, which modifies user data on disk. Although there are status messages after the write, there is no prior confirmation prompt, no warning comment/docstring describing the write impact, and no indication that the user is being alerted before the modification occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The user-facing skill description is presented entirely in Chinese, which can impose a language constraint without user opt-in. Under the policy, forcing a specific language is a natural-language policy concern unless the file offers alternatives or clearly documents a justified locale limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest description and the entire user-facing documentation are presented in Chinese, with no indication that other languages are supported or that the locale is intentionally region-specific. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The script runs state-changing external commands without a clear operator-facing warning or approval point. While not inherently malicious, this can surprise users and administrators by modifying indexes or triggering maintenance tasks that affect retained memory artifacts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.