Back to skill

Security audit

Context Compactor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible context compactor, but it persistently monitors the workspace and automatically reads and stores sensitive OpenClaw memory and agent-instruction data without tight scope or clear user controls.

Review carefully before installing. Only use this in a workspace where you are comfortable with conversation memory and some agent instruction content being read and stored locally. Remove or disable cron jobs, hard-coded outbound alert examples, AGENTS.md reads, and plaintext original-context retention unless you explicitly need them and have retention, deletion, and access controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T06 · System Persistence

Warning
Location
INSTALL.md:63
Finding

Opt-In Installation Instructions Establish Persistent Scheduled Execution

Content
View full analysis
/dev/null; echo "0 * * * * cd ~/.openclaw/workspace/skills/context-compactor && python3 integration.py --check") | crontab - # Delete old logs every day (crontab -l 2>/dev/null; echo "0 2 * * * cd ~/.openclaw/workspace/skills/context-compactor && find logs -name '*.log' -mtime +7 -delete") | crontab - ``` ``` ### Technical Analysis The installation guide tells users to modify their crontab. Once installed, the hourly entry survives the current Skill invocation and executes `integration.py` in future sessions. The second entry performs recurring deletion of matching log files. Scheduled monitoring is related to the declared automatic-compression functionality, but permanent scheduling is not necessary for manual context compression. The instructions do not make the persistence implications prominent, prevent duplicate entries, assign a unique marker to managed entries, or provide an uninstall procedure. There is also a functional safety concern: the audited `integration.py` does not implement the documented `--check` command-line interface in the examined source and ends with incomplete code. Consequently, the persistent task may repeatedly fail while still consuming resources and producing logs. ### Attack Path 1. A user follows the installation guide. 2. The shell pipeline copies the current crontab and appends the supplied entry. 3. The modified crontab is installed under the user's account. 4. Cron invokes code from the Skill directory every hour across future sessions. 5. Repeating the installation command creates duplicate entries, potentially causing multiple executions. 6. The daily cleanup task deletes matching logs older than seven days, reducing historical diagnostic evidence. ### ...[truncated 357 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
integration.py:218
Finding

Automatic Collection of OpenClaw Memory and Agent Instruction Files Exceeds Least Privilege

Content
View full analysis
List[Dict]: """收集会话数据""" try: # 尝试从OpenClaw工作区获取数据 workspace_dir = os.path.expanduser("~/.openclaw/workspace") data = [] # 检查内存文件 memory_dir = os.path.join(workspace_dir, "memory") if os.path.exists(memory_dir): # 获取今天的内存文件 today = datetime.now().strftime("%Y-%m-%d") memory_file = os.path.join(memory_dir, f"{today}.md") if os.path.exists(memory_file): with open(memory_file, "r", encoding="utf-8") as f: content = f.read() # 解析为消息 lines = content.strip().split("\n") for i, line in enumerate(lines): if line.strip(): data.append({ "content": line.strip(), "timestamp": datetime.now().isoformat(), "source": "memory_file", "line_number": i + 1 }) # 检查AGENTS.md agents_file = os.path.join(workspace_dir, "AGENTS.md") if os.path.exists(agents_file): with open(agents_file, "r", encoding="utf-8") as f: content = f.read() # 提取最近修改的部分 lines = content.strip().split("\n") recent_lines = lines[-20:] # 最近20行 for line in recent_lines: if line.strip() and not line.startswith("#"): data.append({ "content": line.strip(), "timestamp": datetime.now().isoformat(), "source": "AGENTS. ...[truncated 1937 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
hierarchical_compactor.py:267
Finding

Original Sensitive Context Is Duplicated in a Plaintext SQLite Database

Content
View full analysis
Remediation
View remediation

other

Warning
Location
OPENCLAW_INTEGRATION.md:198
Finding

Integration Guide Sends Operational Telemetry to a Hard-Coded External Phone Number

Content
View full analysis
alert_compactor.sh << 'EOF' #!/bin/bash THRESHOLD=0.8 STATS=$(curl -s http://127.0.0.1:8081/api/stats) TOKEN_USAGE=$(echo $STATS | jq '.current_stats.current_token_usage') if (( $(echo "$TOKEN_USAGE > $THRESHOLD" | bc -l) )); then echo "⚠️ 告警:token使用率过高 ($TOKEN_USAGE)" # 发送通知(可根据需要集成到iMessage、邮件等) imsg send --to +8613501662537 --text "OpenClaw压缩代理告警:token使用率${TOKEN_USAGE}超过阈值${THRESHOLD}" fi EOF chmod +x alert_compactor.sh ``` ### Technical Analysis The guide instructs users to create an executable alert script that sends token-usage telemetry to a fixed phone number. The recipient is not supplied by the user or derived from configuration. This behavior is unrelated to the core requirement of locally compressing context. The transmitted value is operational metadata rather than message content or a credential. Nevertheless, it can disclose that OpenClaw and this Skill are in use, when activity thresholds occur, and the approximate usage pattern. The transmission occurs only if a user copies and runs or schedules the documented script; it is not automatically executed by the audited Python modules. ### Attack Path 1. A user follows the integration guide and creates `alert_compactor.sh`. 2. The user invokes or schedules the script. 3. The script queries the local API for current token usage. 4. Token usage crosses the configured threshold. 5. `imsg` sends the telemetry and usage value to the embedded external number. 6. The fixed recipient receives recurring information about local Agent activity. ### Impact Assessment The recipient can learn installation status, threshold events, and usage timing. The shown command does not transmit conversation text, credentials, or database content, and it does not grant system privil ...[truncated 88 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
stop_system.sh:113
Finding

Stop Script Can Terminate Unrelated Python Processes

Content
View full analysis
/dev/null || true sleep 2 # 检查是否还有进程 REMAINING_PROCESSES=$(pgrep -f "python3.*(monitor|integration|hierarchical_compactor)" || true) if [ -n "$REMAINING_PROCESSES" ]; then log_warning "强制停止剩余进程..." echo "$REMAINING_PROCESSES" | xargs kill -KILL 2>/dev/null || true fi fi ``` ### Technical Analysis The fallback process search matches any Python command line containing `monitor`, `integration`, or `hierarchical_compactor`. The terms `monitor` and `integration` are generic and can occur in unrelated applications, test runners, directory names, or command arguments. The script sends `SIGTERM` and then `SIGKILL` without verifying that a matched process was launched by this Skill, that its executable resides in this project directory, or that its PID is recorded in a Skill-owned PID file. This exceeds the privileges needed to stop the Skill's own services. ### Attack Path 1. An unrelated same-user Python service runs with `monitor` or `integration` in its command line. 2. The user invokes `stop_system.sh`. 3. `pgrep -f` includes the unrelated process in its results. 4. The script sends `SIGTERM`. 5. If the process remains alive after two seconds, the script sends `SIGKILL`. 6. The unrelated service terminates without an opportunity for graceful recovery. ### Impact Assessment The script can terminate processes that the invoking user is permitted to signal. It does not gain privileges over processes owned by other users, but it can cause denial of service, interrupted jobs, lost ...[truncated 80 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependency Installation Is Not Reproducible or Integrity-Pinned

Content
View full analysis
=2.3.0 ``` The dependency is installed by the commands in `INSTALL.md:24-30`: ```bash # 安装Python依赖 pip install -r requirements.txt # 或者使用pip3 pip3 install -r requirements.txt ``` ### Technical Analysis The lower-bound-only constraint allows any future Flask release accepted by the resolver. Transitive dependencies are also not locked, and no package hashes are supplied. Installations at different times can therefore execute and deploy different third-party code than the version reviewed with the Skill. No evidence of dependency confusion, typosquatting, a malicious package, or an unsafe custom package index was found. The issue is supply-chain hardening and reproducibility rather than a confirmed malicious dependency. ### Attack Path 1. A user runs the documented `pip install` command. 2. The resolver selects the newest compatible Flask release and a current transitive dependency set. 3. Those versions may differ from the versions tested by the Skill author. 4. A compromised, vulnerable, or unexpectedly incompatible future release is installed. 5. Its code executes during installation or when the local API server imports Flask. ### Impact Assessment A compromised dependency executes with the privileges of the user running `pip` or the API service. Potential scope includes Skill data and other files accessible to that account. The current audit did not identify a known malicious dependency, so this represents preventable supply-chain exposure rather than evidence of present compromise. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (84)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · INSTALL.md (reported line 68)May include surrounding context.

添加到心跳检查

编辑 ~/.openclaw/workspace/HEARTBEAT.md:

markdown
# 上下文压缩检查
- 检查压缩系统状态:cd ~/.openclaw/workspace/skills/context-compactor && ./check_status.sh
- 查看最近压缩报告:python3 integration.py --report
- 优化配置参数:python3 integration.py --config --optimize

创建定时任务

bash
# 每小时检查一次
(crontab -l 2>/dev/null; echo "0 * * * * cd ~/.openclaw/workspace/skills/context-compactor && python3 integration.py --check") | crontab -

# 每天清理旧日志
(crontab -l 2>/dev/null; echo "0 2 * * * cd ~/.openclaw/workspace/skills/context-compactor && find logs -name '*.log' -mtime +7 -delete") | crontab -

📊 验证安装

1. 检查系统状态

bash
./check_status.sh

2. 运行测试

bash
python3 test_compaction.py

3. 查看日志

bash
tail -f logs/system.log

🔍 故障排除

常见问题

问题1:Python依赖安装失败

bash

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The troubleshooting step deletes the SQLite database file with no warning that all stored state and history will be lost. In a context compaction skill, the database likely contains session metadata or retained summaries, so this can cause permanent loss of user data and operational state.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documentation presents a compaction feature, but also instructs installation, health checks, permission changes via chmod, and validation of local files and runtime dependencies. That mismatch can cause an agent or operator to execute setup and host-modification actions under the guise of a benign memory-management task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation presents a compaction feature, but also instructs installation, health checks, permission changes via chmod, and validation of local files and runtime dependencies. That mismatch can cause an agent or operator to execute setup and host-modification actions under the guise of a benign memory-management task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation presents a compaction feature, but also instructs installation, health checks, permission changes via chmod, and validation of local files and runtime dependencies. That mismatch can cause an agent or operator to execute setup and host-modification actions under the guise of a benign memory-management task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documentation presents a compaction feature, but also instructs installation, health checks, permission changes via chmod, and validation of local files and runtime dependencies. That mismatch can cause an agent or operator to execute setup and host-modification actions under the guise of a benign memory-management task.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The sample content includes a phone number-like identifier and a verification code-like value, and labels them as important memory items to preserve. This is dangerous because the skill's stated purpose is to compress and retain context, so sensitive identifiers and secrets could be intentionally carried forward into durable summaries or memory layers, increasing exposure and misuse risk.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

The health endpoint invokes a shell via os.popen('date') to generate a timestamp. Although the command string is constant and not directly user-controlled, spawning a shell from a web endpoint is unnecessary and expands attack surface through shell execution, environment/path manipulation, and operational policy violations.

Content

Scanner excerpt · api_server.py (reported line 46)May include surrounding context.

python
return jsonify({
        "status": "healthy",
        "service": "context-compactor",
        "timestamp": os.popen('date').read().strip()
    })

if __name__ == '__main__':

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 73)May include surrounding context.

tail -f logs/compactor.log

检查API

curl http://127.0.0.1:8081/api/health

text

## 配置管理

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented cleanup command permanently deletes historical compaction records from SQLite, but there is no prominent warning about irreversible data loss. In a memory/history management skill, operators may run maintenance commands expecting safe cleanup and unintentionally destroy audit history or recovery data needed for troubleshooting or compliance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · DEPLOYMENT.md (reported line 203)May include surrounding context.

修改 compactor.py 中的 analyze_importance 方法

调整保留策略

curl -X POST http://127.0.0.1:8081/api/config
-d '{"retain_decisions": true, "remove_chitchat": true}'

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The deployment guide shows a /api/compact interface that accepts message content for compression, but the skill metadata/description does not clearly warn users that conversation text will be sent to a local HTTP service. In a context-compaction skill, this matters because users may assume processing stays inside the agent runtime, while the documented design introduces an extra transport and service boundary where prompts, secrets, or personal data may be exposed or logged.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The guide instructs users to install persistent cron jobs even though periodic system-wide execution is not obviously necessary for a context compaction helper. Persistence mechanisms create lasting behavior that survives sessions and can repeatedly execute code, which is risky for an agent skill because it broadens operational scope and can mask unintended or later-modified behavior.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

This command installs a persistent cron entry that repeatedly executes the skill outside normal interactive control. Persistence is security-relevant because it can continue consuming resources, operate on future data, and become a foothold if the underlying script is later modified or compromised.

Content

Scanner excerpt · INSTALL.md (reported line 68)May include surrounding context.

创建定时任务

bash
# 每小时检查一次
(crontab -l 2>/dev/null; echo "0 * * * * cd ~/.openclaw/workspace/skills/context-compactor && python3 integration.py --check") | crontab -

# 每天清理旧日志
(crontab -l 2>/dev/null; echo "0 2 * * * cd ~/.openclaw/workspace/skills/context-compactor && find logs -name '*.log' -mtime +7 -delete") | crontab -

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented log cleanup command irreversibly deletes files without warning, confirmation, or backup guidance. While not code execution, it can destroy audit trails and troubleshooting data, which is especially risky in agent environments where logs may be needed to investigate unexpected actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

This second cron entry adds scheduled deletion behavior, creating persistent automated file removal. In skill context, automated destructive maintenance is more dangerous because it keeps operating after installation and may remove artifacts needed for accountability or debugging.

Content

Scanner excerpt · INSTALL.md (reported line 71)May include surrounding context.

(crontab -l 2>/dev/null; echo "0 * * * * cd ~/.openclaw/workspace/skills/context-compactor && python3 integration.py --check") | crontab -

每天清理旧日志

(crontab -l 2>/dev/null; echo "0 2 * * * cd ~/.openclaw/workspace/skills/context-compactor && find logs -name '*.log' -mtime +7 -delete") | crontab -

text

## 📊 验证安装

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The install guide exposes an API server and localhost HTTP endpoints for a skill whose stated purpose is local context compaction. Adding network-accessible functionality increases attack surface and may permit unauthorized triggering or information exposure if the server binds beyond localhost or lacks authentication. In the context of an agent skill, undocumented service exposure is more dangerous because users may install it expecting only offline/local behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The maintenance section recommends deleting logs without noting that the action is irreversible. This can eliminate evidence needed for security review, incident response, or diagnosing failures, making it a meaningful safety issue in a system that runs persistently or semi-autonomously.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · OPENCLAW_INTEGRATION.md (reported line 80)May include surrounding context.

)

或者通过API

exec("curl -X POST http://127.0.0.1:8081/api/compact -H 'Content-Type: application/json' -d '{"token_usage": 0.85}'")

text

### 2. 获取压缩统计

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · OPENCLAW_INTEGRATION.md (reported line 132)May include surrounding context.

md
# 如果token使用超过阈值,触发压缩
  if (( $(echo "$token_usage > 0.7" | bc -l) )); then
    echo "token使用率过高 ($token_usage),触发压缩"
    curl -X POST http://127.0.0.1:8081/api/compact \
      -H "Content-Type: application/json" \
      -d "{\"token_usage\": $token_usage}"
  fi

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation instructs the compactor to ingest memory from one skill and publish compressed summaries into a shared memory store for other agents. That broadens the skill from local optimization into cross-skill data brokerage, which can expose sensitive conversation history or derived summaries to components that were not originally authorized to access them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples describe sharing memory data and compressed summaries across skills without any warning about privacy, consent, or downstream visibility. In an agent ecosystem, summaries can still contain sensitive user content, so omitting disclosure makes accidental data exposure much more likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Natural-language instructions telling the agent to fetch memory data from another skill and store compressed summaries in shared memory create a direct data-exposure path. Because this is framed as ordinary operation, an agent may propagate sensitive data across trust boundaries without any technical enforcement or user review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The monitoring example sends alerts to a phone number but does not warn that telemetry may leave the local system or identify a recipient. This can normalize outbound messaging and lead operators to expose internal operational data or misdirect alerts to unintended recipients.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide adds an unrelated alerting capability that sends operational data to a phone number via iMessage. Even if the content is only token-usage telemetry, this expands the skill's data-flow surface beyond context compaction and creates a path for accidental disclosure or unauthorized notification delivery.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
DEPLOYMENT.md:279