Back to skill

Security audit

Mnemon Memory

Security checks for vulnerabilities and agentic risk

Overview

This memory skill has a coherent purpose, but its default setup runs mutable third-party code that installs persistent OpenClaw hooks and plugins outside the reviewed artifact.

Review this before installing. Use a pinned, trusted release if available, inspect what `mnemon setup` will create before running it with `--yes`, and avoid storing secrets or sensitive account data in persistent memory. Expect it to modify OpenClaw behavior across future sessions until ejected.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:9
Finding

Unpinned Third-Party Dependency Installs Persistent OpenClaw Hooks

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 9–50
Vulnerability Type: Unpinned and mutable third-party dependency installation
Risk Level: High

The Skill instructs users to install the mnemon executable from mutable external sources and then run an unattended setup command that deploys persistent OpenClaw hooks and extensions.

yaml
install:
  - id: "brew"
    kind: "brew"
    formula: "mnemon-dev/tap/mnemon"
    bins: ["mnemon"]
    label: "Install mnemon (Homebrew)"
  - id: "go"
    kind: "go"
    package: "github.com/mnemon-dev/mnemon@latest"
    bins: ["mnemon"]
    label: "Install mnemon (go install)"
bash
brew install mnemon-dev/tap/mnemon
bash
go install github.com/mnemon-dev/mnemon@latest
bash
mnemon setup --target openclaw --yes
text
This single command deploys all components:
- Skill → ~/.openclaw/skills/mnemon/SKILL.md
- Hook → ~/.openclaw/hooks/mnemon-prime/ (agent:bootstrap — injects behavioral guide)
- Plugin → ~/.openclaw/extensions/mnemon/ (remind, nudge, compact hooks)
- Prompts → ~/.mnemon/prompt/ (guide.md, skill.md)

Technical Analysis

The Go installation explicitly selects @latest, while the Homebrew instruction references a third-party tap without pinning an immutable version or verifying an artifact checksum or signature. The effective code installed by these commands can therefore change after this Skill has been reviewed.

The downloaded executable is immediately trusted to run mnemon setup --target openclaw --yes. The --yes option suppresses interactive approval, and the setup operation writes an agent bootstrap hook, an extension, prompts, and a replacement or additional Skill outside the audited project. Those deployed components are not included in the artifact and consequently cannot be statically validated by this audit.

No evidence in the reviewed file demonstrates that the curren ...[truncated 2027 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace github.com/mnemon-dev/mnemon@latest with a reviewed, immutable release version or commit digest.
  2. Pin the Homebrew installation to a reviewed release artifact where supported, and verify its cryptographic checksum or signature before execution.
  3. Publish release checksums through an independently protected channel and fail installation if verification does not succeed.
  4. Remove --yes from the default setup instructions. Require explicit confirmation after displaying every file, hook, extension, prompt, and configuration entry that will be created or modified.
  5. Vendor or include the exact hook, plugin, prompt, and generated Skill sources in the audited package so their behavior can be reviewed before installation.
  6. Apply least privilege during setup and runtime. The installer should reject elevated execution unless a narrowly scoped operation genuinely requires it.
  7. Make setup transactional, back up files before modification, and provide a manifest containing installed paths, versions, hashes, and rollback instructions.
  8. Reproducibly build releases and sign both release artifacts and update metadata using protected keys.
  9. Document the dependency update process and require security review before changing pinned versions or artifact hashes.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description advertises very broad capabilities like 'Store facts, recall past knowledge, link related memories, manage lifecycle' without defining specific trigger phrases, activation boundaries, or exclusion conditions. In a manifest file, this kind of generic description can overlap with many ordinary memory- or note-related requests and does not clarify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

text

This single command deploys all components:
- **Skill** → `~/.openclaw/skills/mnemon/SKILL.md`
- **Hook** → `~/.openclaw/hooks/mnemon-prime/` (agent:bootstrap — injects behavioral guide)
- **Plugin** → `~/.openclaw/extensions/mnemon/` (remind, nudge, compact hooks)
- **Prompts** → `~/.mnemon/prompt/` (guide.md, skill.md)

Static analysis

No suspicious patterns detected.