T06 · System Persistence
- Location
SKILL.md:63- Finding
Persistent Scheduled Task Performs Destructive Vector-Memory Deletion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is for memory maintenance, but it recommends unguarded deletion of all vector memory and a persistent monthly job that repeats that deletion.
Review carefully before installing. Use the audit and storage guidance only if useful, but do not run the wipe command or add the monthly cron job unless you have a verified backup, understand that vector memories may be permanently lost, and have a clear way to remove the scheduled job afterward.
SKILL.md:63Persistent Scheduled Task Performs Destructive Vector-Memory Deletion
The specific command 'rm -rf ~/.clawdbot/memory/lancedb/' is a destructive filesystem operation that permanently removes the vector memory store. In a skill intended for operational use by an agent or user, presenting this as a one-step maintenance action is dangerous because path mistakes, symlink issues, or blind execution can cause irreversible loss and normalize unsafe command patterns.
Wipe: Clear all vector memory
rm -rf ~/.clawdbot/memory/lancedb/
Then restart gateway: clawdbot gateway restart
The specific command 'rm -rf ~/.clawdbot/memory/lancedb/' is a destructive filesystem operation that permanently removes the vector memory store. In a skill intended for operational use by an agent or user, presenting this as a one-step maintenance action is dangerous because path mistakes, symlink issues, or blind execution can cause irreversible loss and normalize unsafe command patterns.
Wipe: Clear all vector memory
rm -rf ~/.clawdbot/memory/lancedb/
Then restart gateway: clawdbot gateway restart
The skill provides a direct destructive deletion command for the memory database without requiring confirmation, backup, or an explicit warning about irreversible data loss. This is dangerous because users or agents may execute it as written and permanently erase useful memories, including sensitive operational context that may not be easily reconstructed.
The skill goes beyond manual memory hygiene guidance by directing the user to install a recurring cron job that performs deletion and reseeding automatically. Even if intended for maintenance, scheduled destructive actions increase risk because they can run without situational review, propagate mistakes repeatedly, and create persistence for an operation that removes stored data.
The monthly cron workflow automates recurring wipe-and-reseed behavior without clearly warning that it performs repeated destructive deletion. Automating an irreversible action makes mistakes persistent and harder to notice, increasing the likelihood of silent data loss or repeated deletion of valuable memory entries.
The stated purpose is to audit, clean, and optimize vector memory. Telling the operator to restart the gateway reaches into service lifecycle management, which is adjacent operational control rather than core memory maintenance, and the manifest does not mention this broader capability.
No suspicious patterns detected.