Back to skill

Security audit

Neverforget

Security checks for vulnerabilities and agentic risk

Overview

This local memory skill is purpose-aligned, but it asks to index the user's home directory and persist agent-operating instructions with limited scoping and rollback controls.

Install only if you intend this skill to build a persistent local memory index over broad parts of your home environment. Before approving setup, narrow the filesystem scope to specific project folders, review exclusions for secrets and private data, avoid symlink-based indexing unless deliberate, and treat the dependency install, gateway restart, config changes, and HEARTBEAT.md append as persistent changes you may need to undo manually.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
package.json:12
Finding

Overly Broad Home-Directory Access Creates Sensitive-File Indexing Risk

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:50
Finding

Unpinned Native Dependency Installation Executes Mutable Supply-Chain Code

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:71
Finding

Skill Appends Persistent Operational Directives to Shared Agent Heartbeat

Content
View full analysis
/dev/null; then echo "💓 Injecting Heartbeat monitor..." cat ~/.openclaw/skills/neverforget/HEARTBEAT.md >> ~/.openclaw/workspace/HEARTBEAT.md else echo "✅ Heartbeat logic already present." fi ``` The appended content contains operational directives that may affect future sessions: ```markdown 1. **If Index is 0:** The local vector store is empty. Trigger `openclaw memory index` immediately to crawl the defined workspace and sandboxed directories. 2. **If Paths are MISSING:** Confirm that the absolute paths in your `ULTIMATEMEMORY.md` match your disk. Do not use symlinks; use direct path indexing. 3. **Loop Protection Check:** If the gateway crashes during indexing, check `openclaw config get agents.defaults.memorySearch.exclude`. Ensure `**/.openclaw/memory/**` is listed to prevent the AI from indexing its own database. 4. **Disk Alert (>90%):** If disk usage exceeds 90%, do not run `openclaw memory index`. Manually prune large log files in `~/.openclaw/logs` before resuming. 5. **Provider Check:** If provider is not "local", run `openclaw config set agents.defaults.memorySearch.provider local` and restart the gateway. ``` ### Technical Analysis The installation procedure writes skill-controlled text into `~/.openclaw/workspace/HEARTBEAT.md`, a shared persistent instruction file that may be loaded by the agent after the installation session ends. This gives the skill durable influence over future agent behavior. The current content is related to memory maintenance and does not contain an overt safety override, credential-stealing instruction, or malicious payload. Nevertheless, the injection mechanism i ...[truncated 1683 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
* **`SKILL.md`**: (Above) Includes the documentation and the master install script.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions describe system-level and runtime-modifying actions such as installing packages, changing provider configuration, appending monitoring components, restarting services, and triggering indexing. Such actions can affect system integrity, availability, and trust settings, especially when initiated from a skill install path without a narrowly scoped, transparent permission model.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
"**/.ssh/**",
        "**/.aws/**",
        "**/.gnupg/**",
        "**/.env",
        "**/config/google-chrome/**",
        "**/.mozilla/**"
      ],

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · package.json (reported line 26)May include surrounding context.

json
"**/.ssh/**",
        "**/.aws/**",
        "**/.gnupg/**",
        "**/.env",
        "**/config/google-chrome/**",
        "**/.mozilla/**"
      ],

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill presents itself as operating without external dependencies and as 'sovereign local memory', yet its install/config flow fetches a model from Hugging Face and uses an hf: remote model reference. This is a misleading security/privacy claim that can cause users to underestimate network access, supply-chain exposure, and data governance implications during installation or model resolution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill promotes indexing ~/ and other broad filesystem paths while only lightly mentioning customization, without a strong warning that personal documents, tokens, private project data, and unrelated files may be embedded and searchable. In the context of a memory/indexing skill, broad home-directory coverage substantially increases accidental data collection and later retrieval risk, even if some secret paths are excluded.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script appends skill-controlled content into ~/.openclaw/workspace/HEARTBEAT.md, which extends beyond memory engine setup into persistent modification of workspace behavior/content. Because the injected file contents are not shown here and the action is only loosely justified as a 'heartbeat monitor', this creates an unnecessary trust boundary crossing and a potential persistence or prompt-injection surface.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document claims that no context or embeddings are ever sent to external APIs, but later describes contacting a registry and downloading models or packages. That contradiction is dangerous because it can cause users to make trust decisions based on false assumptions about network isolation and data exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

Automatically following symlinks into external directories creates persistent cross-boundary memory ingestion beyond the normal workspace, which can retain sensitive information in logs, embeddings, or indexes long after initial access. In the context of a memory skill, this is particularly risky because persistence is the product's core behavior, so accidental over-collection is more dangerous than in a transient tool.

Content

Scanner excerpt · ULTIMATEMEMORYtemplate.md (reported line 82)May include surrounding context.

md
| **Skills Directory** | `/home/$USER/.openclaw/skills` |
| **Main Config** | `/home/$USER/.openclaw/openclaw.json` |

> **💡 NOTE ON EXTERNAL DIRECTORIES:** > If you have infrastructure or data outside of the standard workspace that you want the AI to "remember," create a manual symbolic link inside `~/.openclaw/workspace/` pointing to that directory. The memory engine will automatically follow the link and index the external data.
> **Example:** `ln -s /path/to/my-external-data ~/.openclaw/workspace/external-data`

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template encourages users to symlink arbitrary external directories into the indexed workspace so the memory engine will automatically follow and ingest them, but it does not warn about indexing sensitive files, personal data, secrets, or regulated information. This can unintentionally broaden the skill's data collection scope and cause sensitive local content to become persistently searchable by the agent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template is presented as a memory manifest, but it also instructs users that installation will trigger broad system and application changes including package deployment, provider reconfiguration, loop-protection changes, heartbeat injection, gateway restart, and initial indexing. That scope expansion is dangerous because users may consent to a seemingly documentation-only skill without understanding it can alter runtime behavior and system state well beyond local memory configuration.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file describes reaching out to a registry and downloading a bundle as part of using a skill whose stated value proposition is sovereign local memory with no external dependency. Even if this is normal package retrieval, the mismatch between claimed isolation and actual network activity can mislead users and creates supply-chain and trust-boundary risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installation/update guidance tells users to approve an install script that performs multiple system and application modifications, but it does not provide a concise warning summary of side effects, persistence, network use, or rollback implications. This undermines informed consent and increases the likelihood of users authorizing changes they do not fully understand.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.