T09 · Insecure Skill Coding Practices
- Location
cli/server.js:20- Finding
Unauthenticated OS Command Injection in the HTTP Recall API
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill is coherent in purpose, but it has serious implementation and privacy-boundary problems that warrant Review before installation.
Install only after reviewing and fixing the shell execution paths, pinning dependencies, and tightening memory isolation. Do not expose the recall server beyond localhost, do not enable RECALL_ALLOW_PRIVATE on shared hosts, set publicOnly for untrusted agents, and rebuild or purge existing ChromaDB data after privacy-boundary fixes.
cli/server.js:20Unauthenticated OS Command Injection in the HTTP Recall API
extensions/openclaw-plugin/index.ts:48OS Command Injection in the OpenClaw Recall Plugin
scripts/index-digests.py:64Whole-File Classification Exposes Private Sections Through Shared Collections
scripts/recall.py:108Public-Only Recall Falls Back to an Unrestricted Legacy Collection
scripts/write-learning.py:64Sandboxed Agents Can Persist Unreviewed Content into Shared Agent Memory
scripts/sync-shared.py:51Shared-Memory Synchronization Does Not Enforce the Privacy Scanner
cli/jasper-recall.js:137Setup Installs Unpinned Python Dependencies at Runtime
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
"Collection not found"
rm -rf ~/.openclaw/chroma-db # Clear and rebuild
index-digests
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
"Collection not found"
rm -rf ~/.openclaw/chroma-db # Clear and rebuild
index-digests
The changelog recommends executing npx jasper-recall serve --port 3458 without pinning a package version. npx will resolve the latest available package at execution time, so users may run a newer or compromised release than the one documented, creating a supply-chain risk if the package is hijacked or a malicious update is published.
The documented setup command uses npx jasper-recall setup without an explicit version. This exposes users to execution of whatever version npm resolves at that moment, which is especially risky for bootstrap/setup flows because they typically run with broad filesystem and configuration access.
The update example npx jasper-recall update is unpinned and therefore can fetch and execute an unintended package version. Because this command is specifically about updates, users may be conditioned to trust remote code execution paths, increasing the chance of supply-chain compromise if the package or dependency chain is tampered with.
The configuration example references npx jasper-recall config without pinning the package version. Even though this appears lower risk than setup, it still executes code fetched at runtime and can be abused through package compromise, typo-squatting, or malicious release publication.
The README instructs users to execute npx jasper-recall setup without pinning a version. Because npx resolves the latest published package at execution time, a compromised maintainer account, dependency confusion event, or malicious future release could cause arbitrary code execution on the user's machine during installation.
The documented command npx jasper-recall doctor invokes code fetched by package name without a pinned version. Even though this is framed as a health check, it still executes package code locally and could be abused if the package or its distribution path is compromised.
npx jasper-recall doctor --fix is more dangerous than a read-only check because it both fetches unpinned code and then performs environment modifications like creating venvs and installing packages. A malicious or tampered upstream release could leverage this trusted repair flow to run arbitrary commands and persist changes.
npx jasper-recall doctor --dry-run still executes unpinned package code despite sounding non-invasive. Users may incorrectly assume dry-run is safe, but the initial package resolution and execution remain a supply-chain risk.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### Setup for Sandboxed Agents
1. Create shared directory: `mkdir -p ~/.openclaw/workspace/memory/shared`
2. Symlink to sandboxed workspace: `ln -s ~/.openclaw/workspace/memory/shared ~/.openclaw/workspace-sandbox/shared`
3. Use `--public-only` flag in sandboxed agent's recall queries
The README documents npx jasper-recall serve without version pinning, causing users to run the latest package code when starting a local API server. Because server startup often involves long-lived processes and access to local memory data, compromise of the package can expose sensitive information and permit persistent malicious behavior.
npx jasper-recall serve --port 8080 has the same unpinned remote execution risk as other npx examples. In this context the impact is amplified because the process exposes an HTTP interface that may handle sensitive memory content, so a malicious release could both execute code and alter server behavior.
The plugin's auto-recall feature injects retrieved memories from past conversations into every message context, but the README does not prominently warn about the privacy implications or obtain explicit user consent. In an agent-memory product, this can unintentionally surface sensitive historical content to prompts, tools, logs, or downstream models beyond what the user expects.
The setup instructions again rely on npx jasper-recall setup without version pinning. This is a classic supply-chain footgun because installation/setup commands are high-trust operations that typically receive broad filesystem permissions and can modify agent configuration.
The skill instructs users to run npx jasper-recall setup without pinning a specific package version. This allows whatever version is current on npm at execution time to be fetched and run, creating a supply-chain risk if a future release is malicious, compromised, or breaking. In a security-sensitive agent skill, executing unpinned remote code is dangerous because installation happens with user privileges and sets up persistent binaries and services.
The skill explicitly promotes creation of session digests from prior conversations, which establishes persistent storage and retrieval of interaction history. While this is core functionality rather than malicious behavior, it increases privacy and data-retention risk because sensitive prompts, secrets, or personal data may be summarized and made searchable across sessions. In an agent-memory skill, this is contextually expected but still security-relevant.
index-digests # Index memory files into ChromaDB
**Create session digests:**
```bash
digest-sessions # Process new sessions
digest-sessions --dry-run # Preview what would be processed
npx jasper-recall moltbook-setup fetches and executes an unpinned package version from npm. Because this command configures wrappers for sandboxed agents, a malicious or unexpected package update could alter the isolation model or install backdoored scripts. The security context makes the risk higher because this command establishes trust boundaries for other agents.
npx jasper-recall moltbook-verify is another unpinned execution path to code retrieved at runtime. Verification commands are especially sensitive because users may trust their output to confirm isolation or privacy guarantees, but an altered package could falsely report a secure state. This creates both code-execution and trust-manipulation risk.
The documentation claims sandboxed agents can only search shared memories via a wrapper that forces --public-only, but elsewhere it documents direct collection selection flags such as --collection private_memories and --all. If the sandboxed agent can invoke the underlying CLI directly instead of only the wrapper, the privacy boundary becomes policy-only rather than technically enforced. This mismatch can lead to private memory disclosure in multi-agent environments.
The serve command is documented as npx jasper-recall serve [OPTIONS], again causing unpinned package execution. Since this starts a long-lived HTTP API over local memory data, a compromised future package version could expose data, weaken defaults, or open additional network-accessible behavior. The network-facing nature of this component increases impact.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
"No index found"
index-digests # Create the index first
"Collection not found"
The document plans and tracks implementation of bidirectional memory sharing, shared directories, symlinks, and scheduled sync between agents, but it does not prominently warn about the privacy and data-exposure risks of cross-agent memory propagation. In this context, agents may handle sensitive prompts, notes, or derived data, so normalizing shared-memory features without explicit guardrails increases the chance of unintended disclosure or privacy-boundary bypass.
The file is presented as a 'system health check', but when run with --fix it creates directories, creates a Python virtual environment, installs packages with pip, and runs an indexing script. That mismatch increases the chance a user or calling agent will treat it as read-only diagnostics and trigger state-changing operations without adequate consent or review.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
* Local RAG system for AI agent memory
*
* Usage:
* npx jasper-recall setup # Install dependencies and create scripts
* npx jasper-recall recall # Run a query (alias)
* npx jasper-recall index # Index files (alias)
* npx jasper-recall digest # Digest sessions (alias)
Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command