Back to skill

Security audit

Memphis Cognitive

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill is mostly coherent, but its setup guides recommend running unverified remote install scripts, including one through sudo, so users should review it before installing.

Before installing, avoid the documented curl | bash, curl | sh, and curl | sudo bash patterns. Prefer a pinned release or package version, verify checksums or signatures, inspect installer scripts before running them, and be cautious with trade/share-sync because memory records may contain private or proprietary data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T03 Β· Remote Payload Retrieval and Execution

Error
Location
SKILL.md:57
Finding

Mutable Memphis installer is downloaded and executed directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:57
Additional Location: SKILL.md:430
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
# Option 1: One-liner (RECOMMENDED)
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash

The same file also recommends executing the Ollama installer:

bash
curl -fsSL https://ollama.com/install.sh | sh
ollama pull nomic-embed-text

Technical Analysis

These commands pipe network responses directly into a shell. The Memphis installer is retrieved from the mutable main branch of a personal GitHub repository and is not pinned to a reviewed commit or release. Neither command verifies a cryptographic signature or checksum before execution.

Consequently, the effective code executed by users can change after this Skill has been reviewed. HTTPS protects transport under normal conditions but does not protect users if the upstream repository, publisher account, release process, or served installer is compromised.

Installing an external CLI may be necessary because this package is documentation-only, but executing an unverified mutable response is not the minimum privilege or minimum trust mechanism necessary. Ollama is explicitly optional and is not required for the Skill's core decision-memory functionality.

Attack Path

  1. An attacker compromises the Memphis repository, maintainer account, or installation-script publishing process.
  2. The attacker modifies install.sh on the main branch to contain malicious shell commands.
  3. A user or agent follows the Skill's recommended installation instructions.
  4. curl retrieves the modified response.
  5. bash or sh executes it immediately, without an inspection or integrity-validation step.
  6. The payload operates with all permissions held by the invoking user and can subsequently attempt privilege e ...[truncated 727 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all curl | bash and curl | sh installation patterns.
  2. Pin Memphis to an immutable, reviewed release tag or commit rather than main.
  3. Download the installer or release artifact to disk as a separate step.
  4. Publish SHA-256 checksums and preferably signed release manifests.
  5. Verify the checksum and publisher signature before any execution.
  6. Show users how to inspect the downloaded installer before running it.
  7. Prefer a signed package repository or a reproducible, versioned package.
  8. Mark Ollama clearly as optional and direct users to its platform-specific, signature-verified package installation process.

T03 Β· Remote Payload Retrieval and Execution

Error
Location
README.md:91
Finding

README recommends unverified remote installation, including root-level execution

Content
View full analysis

Vulnerability Details

File Location: README.md:91, README.md:108, and README.md:128
Vulnerability Type: Remote payload retrieval and execution with excessive privileges
Risk Level: Critical

Vulnerable Code

bash
# Install Node.js 20 LTS
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs
bash
# Option 1: One-liner (RECOMMENDED)
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash
bash
curl -fsSL https://ollama.com/install.sh | sh
ollama pull nomic-embed-text

Technical Analysis

All three commands execute mutable remote responses without checksum or signature verification. The NodeSource command is especially dangerous because it explicitly invokes the downloaded response through sudo, granting it root privileges while preserving portions of the caller's environment through -E.

Root-level execution of a network response is broader than the privileges required by this documentation-only Skill. Installing a supported Node.js package can instead be performed through a signed operating-system package repository or another version-pinned distribution mechanism. Ollama is optional, and its installation is not necessary for the core declared functionality.

The Memphis installer is also retrieved from the moving main branch. This prevents the reviewed Skill package from determining what code will actually execute at installation time.

Attack Path

  1. An attacker compromises one of the installer hosts, source repositories, maintainer accounts, or publishing pipelines.
  2. The served script is replaced with attacker-controlled shell commands.
  3. A user copies the documented command.
  4. curl downloads the attacker's response and pipes it directly to a shell.
  5. For the NodeSource command, sudo -E bash executes the payload as root.
  6. The payload can modify the operating s ...[truncated 796 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove every direct network-to-shell pipeline.
  2. Do not execute remotely downloaded setup scripts with sudo.
  3. Install Node.js through a distribution repository that validates signed package metadata, with an explicitly supported version.
  4. If a third-party repository is required, install and verify its signing key and repository configuration through auditable, separate steps.
  5. Pin Memphis and Ollama artifacts to immutable releases.
  6. Publish expected checksums and validate them locally before installation.
  7. Prefer signature verification using a documented publisher key.
  8. Separate download, verification, inspection, and execution into distinct commands.
  9. Run installation with the least privileged account possible and request elevation only for narrowly scoped filesystem operations.

T03 Β· Remote Payload Retrieval and Execution

Error
Location
QUICKSTART.md:13
Finding

Quick-start workflow executes a mutable GitHub script without verification

Content
View full analysis

Vulnerability Details

File Location: QUICKSTART.md:13
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
# One command:
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash

Technical Analysis

The quick-start guide presents direct execution of remote content as the primary one-command installation method. The response comes from the mutable main branch and is passed to Bash before the user can inspect it. No release pin, checksum, signature, or provenance validation is performed.

The quick-start context increases exposure because users are encouraged to prioritize speed and may execute the command without reviewing the repository or installer. The code executed is not included in this Skill artifact and therefore falls outside the reviewed package.

Attack Path

  1. An attacker gains the ability to modify the upstream install.sh response.
  2. The attacker adds commands that steal data, modify configuration, or retrieve another payload.
  3. A user follows the advertised quick-start command.
  4. Bash immediately executes the attacker's content under the user's account.
  5. The payload accesses all resources available to that account and may establish further access.

Impact Assessment

Successful exploitation provides arbitrary command execution with the invoking user's privileges. This can expose user documents, development repositories, SSH material, environment variables, OpenClaw configuration, and local memory data. The payload could also alter shell startup files or user services where permitted.

The audited file does not itself contain a confirmed malicious payload, but its installation mechanism allows the effective payload to change independently of the Skill review.

Remediation
View remediation

Remediation Suggestions

Replace the one-line installer with a version-pinned procedure:

  1. Select an immutable Memphis release or commit.
  2. Download the artifact without executing it.
  3. Verify a published cryptographic checksum and release signature.
  4. Inspect the installer or documented package contents.
  5. Execute it only after verification, using an unprivileged account.
  6. Document the exact files and configuration the installer will modify.

T08 Β· Insecure Dependencies

Warning
Location
SKILL.md:60
Finding

SKILL documentation installs unpinned source and executes dependency build scripts

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:60-67 and SKILL.md:529-531
Vulnerability Type: Insecure dependency and source installation
Risk Level: Medium

Vulnerable Code

bash
# Option 2: Manual
git clone https://github.com/elathoxu-crypto/memphis.git ~/memphis
cd ~/memphis
npm install && npm run build
npm link  # Or: npm run install-global

# Option 3: From npm (when published)
npm install -g @elathoxu-crypto/memphis

The production-ready section repeats the unpinned source installation:

bash
git clone https://github.com/elathoxu-crypto/memphis.git ~/memphis
cd ~/memphis && npm install && npm run build && npm link
clawhub install memphis-cognitive

Technical Analysis

The Git workflow clones the repository's moving default branch instead of a reviewed commit or release. It then runs npm install, project build scripts, and global linking operations. npm dependency installation may execute package lifecycle scripts, while npm run build executes repository-controlled commands.

The global npm option does not specify an exact package version and is described as usable β€œwhen published,” making its reviewed provenance unclear. Although using third-party dependencies is expected for a Node.js CLI, executing an unpinned dependency graph and moving source tree is not necessary.

No evidence of dependency confusion or a currently malicious package was found in the artifact. The issue is the absence of controls that bind installation to reviewed source and dependency versions.

Attack Path

  1. An attacker compromises the upstream Memphis repository, npm account, or a transitive dependency.
  2. Malicious code is introduced into a build script, lifecycle script, or dependency release.
  3. A user clones the latest default branch or installs the latest npm package.
  4. npm install or npm run build executes the introduced code.
  5. `npm ...[truncated 551 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the source checkout to a signed, immutable release tag or full commit hash.
  2. Publish and verify release signatures and checksums.
  3. Commit a reviewed lockfile and use npm ci instead of an unconstrained npm install.
  4. Pin the npm package to an exact reviewed version.
  5. Enable npm provenance and verify package integrity metadata.
  6. Audit dependency lifecycle scripts and document which scripts execute during installation.
  7. Consider installing with lifecycle scripts disabled during verification, then explicitly run only required reviewed scripts.
  8. Avoid global linking unless necessary; prefer a scoped, user-owned installation location.

T08 Β· Insecure Dependencies

Warning
Location
README.md:20
Finding

README uses unpinned repository and npm installation workflows

Content
View full analysis

Vulnerability Details

File Location: README.md:20-26 and README.md:111-118
Vulnerability Type: Insecure dependency and source installation
Risk Level: Medium

Vulnerable Code

bash
# Clone + build
git clone https://github.com/elathoxu-crypto/memphis.git ~/memphis
cd ~/memphis
npm install
npm run build

# Global command
npm link

The full installation instructions repeat the workflow and provide an unpinned npm alternative:

bash
# Option 2: Manual
git clone https://github.com/elathoxu-crypto/memphis.git ~/memphis
cd ~/memphis && npm install && npm run build
npm link

# Option 3: From npm (when published)
npm install -g @elathoxu-crypto/memphis

Technical Analysis

These instructions execute source and dependency-controlled scripts from moving upstream versions. The repository is cloned without selecting a specific tag or commit, and the npm package command does not specify a version. npm install may execute lifecycle scripts from Memphis or its dependencies, while npm run build executes commands defined by the unpinned repository.

This approach makes the installed implementation different from the documentation package that was audited. A later upstream change can alter behavior without requiring a new Skill release or review.

Attack Path

  1. The repository, npm publisher account, or a dependency is compromised.
  2. The attacker publishes malicious source, package metadata, or a lifecycle script.
  3. A user follows the README and obtains the latest mutable version.
  4. npm executes the malicious installation or build logic.
  5. The linked or globally installed memphis command preserves attacker-controlled behavior for later use.

Impact Assessment

Exploitation can produce arbitrary code execution with user privileges during installation and can replace the expected Memphis executable with a compromised implementation. Subsequent ...[truncated 321 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace default-branch cloning with a signed release tag or full commit hash.
  2. Pin the npm package to an exact version that corresponds to the Skill release.
  3. Include and enforce a reviewed lockfile using npm ci.
  4. Verify npm provenance, package integrity, release signatures, and checksums.
  5. Document all lifecycle and build scripts that will execute.
  6. Avoid claiming that an installation is production-ready until the referenced versions are consistent and reproducibly linked to audited source.
  7. Align the versions shown in SKILL.md, README.md, and _meta.json to improve release traceability.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (25)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash construct directly chains downloaded remote content into a shell, eliminating any inspection point and maximizing the blast radius of a compromise. A tampered installer could run arbitrary commands with the user's privileges, install persistence, exfiltrate secrets, or modify development environments immediately.

Content

Scanner excerpt Β· QUICKSTART.md (reported line 13)May include surrounding context.

bash
# One command:
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash

βœ… Done! Memphis is installed!

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This command chains network retrieval directly into a privileged shell (curl ... | sudo -E bash -), eliminating any inspection step and granting full administrative execution to remote content. If abused, it can install backdoors, alter system packages, exfiltrate secrets, or completely take over the machine.

Content

Scanner excerpt Β· README.md (reported line 90)May include surrounding context.

bash
# Install Node.js 20 LTS
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs

# Verify

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping downloaded content straight into bash is a classic command-chaining abuse pattern because it turns documentation into an immediate arbitrary-code-execution vector. The danger is amplified here by recommending an installer from a mutable branch path (main) rather than an immutable release artifact.

Content

Scanner excerpt Β· README.md (reported line 108)May include surrounding context.

bash
# Option 1: One-liner (RECOMMENDED)
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash

# Option 2: Manual
git clone https://github.com/elathoxu-crypto/memphis.git ~/memphis

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The README instructs users to fetch and execute an external installer from ollama.com with sh, again without integrity checks or warnings. Even for optional dependencies, this normalizes unsafe install practices and can lead to arbitrary code execution on the user's system.

Content

Scanner excerpt Β· README.md (reported line 128)May include surrounding context.

5. Ollama (optional)

bash
curl -fsSL https://ollama.com/install.sh | sh
ollama pull nomic-embed-text

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The curl ... | sh pattern for Ollama chains remote content directly into a shell, creating the same arbitrary-code-execution risk as any pipe-to-shell installer. Even though it is listed as optional, users may still run it blindly from the README and compromise their environment.

Content

Scanner excerpt Β· README.md (reported line 128)May include surrounding context.

5. Ollama (optional)

bash
curl -fsSL https://ollama.com/install.sh | sh
ollama pull nomic-embed-text

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash construct is classic command chaining abuse because it converts fetched network data directly into executable shell input without inspection. In documentation for a developer tool, this is dangerous because users are likely to paste the command verbatim, making compromise straightforward if the upstream content changes.

Content

Scanner excerpt Β· SKILL.md (reported line 57)May include surrounding context.

bash
# Option 1: One-liner (RECOMMENDED)
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash

# Option 2: Manual
git clone https://github.com/elathoxu-crypto/memphis.git ~/memphis

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The command fetches and executes an installer script from an external domain in one step, giving that remote content full shell execution. This is especially risky because the skill presents it as routine setup, which lowers user caution and normalizes unsafe installation behavior.

Content

Scanner excerpt Β· SKILL.md (reported line 430)May include surrounding context.

Install Ollama:

bash
curl -fsSL https://ollama.com/install.sh | sh
ollama pull nomic-embed-text

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh pipeline causes immediate execution of whatever bytes are returned by the remote server, collapsing download and execution into one opaque action. This is a well-known unsafe pattern that meaningfully increases the likelihood of arbitrary code execution during setup.

Content

Scanner excerpt Β· SKILL.md (reported line 430)May include surrounding context.

Install Ollama:

bash
curl -fsSL https://ollama.com/install.sh | sh
ollama pull nomic-embed-text

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quick start instructs users to fetch and immediately execute a remote installer with curl | bash, which gives arbitrary code from an external source direct execution on the user's system. In a documentation-only skill, this is especially unjustified because the skill itself should not require unsafe bootstrapping behavior, and users are given no opportunity to inspect or verify the script before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The markdown explicitly tells users to run a remote shell installer without any warning, verification guidance, version pinning, or trust boundary explanation. If the upstream repository, network path, or referenced script is compromised, users could execute attacker-controlled commands immediately.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
96% confidence
Finding

Use of sudo -E preserves user-controlled environment variables when invoking a root shell on remote-fetched content. That can widen exploitation paths and makes the already-dangerous pipe-to-shell pattern even riskier in environments where environment variables influence shell or installer behavior.

Content

Scanner excerpt Β· README.md (reported line 90)May include surrounding context.

bash
# Install Node.js 20 LTS
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs

# Verify

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
96% confidence
Finding

Use of sudo -E preserves user-controlled environment variables when invoking a root shell on remote-fetched content. That can widen exploitation paths and makes the already-dangerous pipe-to-shell pattern even riskier in environments where environment variables influence shell or installer behavior.

Content

Scanner excerpt Β· README.md (reported line 90)May include surrounding context.

bash
# Install Node.js 20 LTS
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs

# Verify

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt Β· README.md (reported line 91)May include surrounding context.

bash
# Install Node.js 20 LTS
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs

# Verify
node --version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt Β· README.md (reported line 100)May include surrounding context.

bash
# Install Node.js 20 LTS
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt install -y nodejs

# Verify
node --version

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README recommends executing a remote script directly via curl ... | bash from GitHub without any integrity verification, version pinning, or warning about system impact. If the upstream repository, network path, or referenced branch is compromised, users could execute arbitrary code on their machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation includes another shell-piped installer command (curl ... | sh) without warning users that it executes fetched code with local system effects. This pattern is inherently risky because the fetched script can change over time and may run arbitrary commands during installation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt Β· README.md (reported line 181)May include surrounding context.

bash
memphis share-sync --push  # Multi-agent sync
memphis graph build        # Knowledge graph
memphis trade create ...   # Share with team

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The document includes a dedicated 'Polish Support' section listing supported Polish keywords, while the rest of the README mixes English and Polish without clarifying whether language behavior is optional or configurable. Under the stated policy, language or locale constraints should offer user choice or be clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends executing a remotely fetched install script via curl ... | bash with no integrity verification, pinning, or safety warning. This creates a direct trust boundary violation: if the remote content, repository, network path, or hosting account is compromised, arbitrary code will run immediately on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trade protocol examples show exporting and accepting knowledge bundles without emphasizing that they may contain sensitive memory or decision records. Because the package is specifically designed to store cognitive history and knowledge, sharing artifacts like /tmp/trade.json can expose confidential data if users accept or export blindly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The multi-agent sync examples encourage pushing and pulling data to remote systems without a clear warning that memory, journal, or decision data may contain sensitive information. In a memory system, this context increases risk because users may sync highly personal, operational, or proprietary data to another host they do not fully control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Ollama installation instructions invoke a remote installer script with curl ... | sh and provide no warning or verification guidance. This exposes users to arbitrary code execution if the remote script or delivery path is malicious or compromised.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The command fetches executable content from an external URL at runtime, creating a supply-chain and integrity risk. Although external script fetching can be legitimate, here it becomes dangerous because it is paired with immediate execution and presented as the default setup path.

Content

Scanner excerpt Β· QUICKSTART.md (reported line 13)May include surrounding context.

bash
# One command:
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash

βœ… Done! Memphis is installed!

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

Fetching an external script from a mutable GitHub URL and immediately executing it exposes users to arbitrary code execution if that resource is modified or compromised. The skill context makes this more dangerous because the README labels the method as 'RECOMMENDED,' encouraging unsafe execution by default.

Content

Scanner excerpt Β· README.md (reported line 108)May include surrounding context.

bash
# Option 1: One-liner (RECOMMENDED)
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash

# Option 2: Manual
git clone https://github.com/elathoxu-crypto/memphis.git ~/memphis

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

This is a concrete instance of external script fetching followed by immediate execution from GitHub raw content. Even if the repository is legitimate today, account compromise, malicious updates, DNS/TLS interception at trust boundaries, or dependency on mutable remote content can turn this into silent code execution on the user's host.

Content

Scanner excerpt Β· SKILL.md (reported line 57)May include surrounding context.

bash
# Option 1: One-liner (RECOMMENDED)
curl -fsSL https://raw.githubusercontent.com/elathoxu-crypto/memphis/main/install.sh | bash

# Option 2: Manual
git clone https://github.com/elathoxu-crypto/memphis.git ~/memphis

Static analysis

No suspicious patterns detected.