Back to skill

Security audit

Memory Hygiene

Security checks for vulnerabilities and agentic risk

Overview

The skill is for memory maintenance, but it recommends unguarded deletion of all vector memory and a persistent monthly job that repeats that deletion.

Review carefully before installing. Use the audit and storage guidance only if useful, but do not run the wipe command or add the monthly cron job unless you have a verified backup, understand that vector memories may be permanently lost, and have a clear way to remove the scheduled job afterward.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
SKILL.md:63
Finding

Persistent Scheduled Task Performs Destructive Vector-Memory Deletion

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The specific command 'rm -rf ~/.clawdbot/memory/lancedb/' is a destructive filesystem operation that permanently removes the vector memory store. In a skill intended for operational use by an agent or user, presenting this as a one-step maintenance action is dangerous because path mistakes, symlink issues, or blind execution can cause irreversible loss and normalize unsafe command patterns.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Wipe: Clear all vector memory

bash
rm -rf ~/.clawdbot/memory/lancedb/

Then restart gateway: clawdbot gateway restart

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The specific command 'rm -rf ~/.clawdbot/memory/lancedb/' is a destructive filesystem operation that permanently removes the vector memory store. In a skill intended for operational use by an agent or user, presenting this as a one-step maintenance action is dangerous because path mistakes, symlink issues, or blind execution can cause irreversible loss and normalize unsafe command patterns.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Wipe: Clear all vector memory

bash
rm -rf ~/.clawdbot/memory/lancedb/

Then restart gateway: clawdbot gateway restart

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill provides a direct destructive deletion command for the memory database without requiring confirmation, backup, or an explicit warning about irreversible data loss. This is dangerous because users or agents may execute it as written and permanently erase useful memories, including sensitive operational context that may not be easily reconstructed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill goes beyond manual memory hygiene guidance by directing the user to install a recurring cron job that performs deletion and reseeding automatically. Even if intended for maintenance, scheduled destructive actions increase risk because they can run without situational review, propagate mistakes repeatedly, and create persistence for an operation that removes stored data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The monthly cron workflow automates recurring wipe-and-reseed behavior without clearly warning that it performs repeated destructive deletion. Automating an irreversible action makes mistakes persistent and harder to notice, increasing the likelihood of silent data loss or repeated deletion of valuable memory entries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The stated purpose is to audit, clean, and optimize vector memory. Telling the operator to restart the gateway reaches into service lifecycle management, which is adjacent operational control rather than core memory maintenance, and the manifest does not mention this broader capability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.