Back to skill

Security audit

self-evolving-memory

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about being a persistent memory system, but it gives agents broad authority to change future behavior and use remote embedding providers without enough consent or data-safety boundaries.

Install only if you want an agent to maintain long-term workspace memory and you are willing to review persistent changes. Require explicit approval and diffs before edits to SOUL.md, AGENTS.md, TOOLS.md, skills, scripts, or hooks; avoid storing secrets or sensitive personal data; prefer local embeddings; do not pipe remote installers directly to a shell; and use HTTPS/authentication for any non-local embedding service.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/embedding-setup.md:13
Finding

Unverified Remote Script Download and Immediate Shell Execution

Content
View full analysis

Vulnerability Details

File Location: references/embedding-setup.md:13-19
Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: Critical

Vulnerable Code:

bash
### 1. Install Ollama

```bash
curl -fsSL https://ollama.ai/install.sh | sh

Or download from ollama.ai.

text

### Technical Analysis

The installation instructions pipe content retrieved from an external URL directly into a shell. The downloaded script is not pinned to a reviewed version, saved for inspection, or validated through a cryptographic signature or checksum.

Consequently, the effective code executed by this instruction can change after the Skill package has been reviewed. Compromise of the remote server, its publishing process, DNS resolution, or the TLS trust chain could substitute arbitrary shell commands.

Installing Ollama is not required for the Skill's core rule-based memory-routing functionality because the documentation explicitly supports operation without vector embeddings. Immediate remote shell execution therefore exceeds the minimum privileges necessary for the declared core functionality.

### Attack Path

1. An attacker compromises the remote installation-script host, publishing process, or relevant network trust path.
2. The attacker modifies the content returned by `https://ollama.ai/install.sh`.
3. A user follows the documented installation command.
4. `curl` retrieves the attacker-controlled content.
5. The pipe sends the content directly to `sh` without inspection or integrity verification.
6. The payload executes with all privileges available to the invoking user and may request or invoke elevated installation operations.

### Impact Assessment

Successful exploitation provides arbitrary command execution under the invoking account. The payload could read or alter workspace files, OpenClaw configuration, persistent memory, credentials accessible to the us
...[truncated 255 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the curl | sh installation pattern.
  • Direct users to an official, version-pinned release artifact.
  • Require verification using a publisher-provided cryptographic signature or SHA-256 checksum.
  • Download the installer to a local file and instruct users to inspect it before execution.
  • Document the expected filesystem and privilege changes made by the installer.
  • Explicitly state that embeddings are optional and that the Skill can operate without installing Ollama.
  • Prefer operating-system package managers with signed repositories where available.
  • Do not recommend running the installer with elevated privileges unless a specific operation demonstrably requires them.

T09 · Insecure Skill Coding Practices

Error
Location
references/embedding-setup.md:53
Finding

Remote Memory Embedding Configuration Uses Unencrypted and Unauthenticated HTTP

Content
View full analysis

Vulnerability Details

File Location: references/embedding-setup.md:53-65
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: High

Vulnerable Code:

json
If Ollama is running on a **remote machine or NAS**:

```json
{
  "memorySearch": {
    "enabled": true,
    "sources": ["memory"],
    "provider": "ollama",
    "remote": {
      "baseUrl": "http://<your-ollama-host>:11434/ollama",
      "apiKey": ""
    },
    "model": "nomic-embed-text"
  }
}
text

### Technical Analysis

The documented configuration recommends connecting to a remote machine or NAS over plaintext HTTP and leaves authentication empty. Unlike a loopback-only service, a remote endpoint causes memory-related requests to traverse a network without transport encryption or endpoint authentication.

Semantic embedding requests may contain memory text, fragments, or retrieval queries derived from files such as `memory/preferences.md`, `memory/system.md`, and `memory/projects.md`. An on-path attacker can observe this traffic or modify responses. An unauthenticated service may also be accessed or impersonated by other network participants.

### Attack Path

1. A user configures a remote Ollama host using the documented HTTP URL and empty API key.
2. OpenClaw sends memory embedding or search requests across the local network or another routed network.
3. An attacker with network visibility captures plaintext requests and recovers sensitive memory content or queries.
4. Alternatively, the attacker performs address spoofing, DNS manipulation, gateway interception, or service impersonation.
5. The attacker returns manipulated embedding responses or records the transmitted information.
6. Manipulated responses can degrade or corrupt semantic recall, while intercepted requests disclose persistent user and environment information.

### Impact Assessment

The primary impact is confidentiality lo
...[truncated 480 chars]
Remediation
View remediation

Remediation Suggestions

  • Require HTTPS with certificate validation for every non-loopback embedding endpoint.
  • Require authentication for remote Ollama or compatible services.
  • Restrict plaintext HTTP examples to 127.0.0.1 or another explicitly loopback-only address.
  • Warn users not to expose an unauthenticated Ollama service directly to a LAN, WAN, or the Internet.
  • Recommend a mutually authenticated reverse proxy, VPN, or SSH tunnel for remote deployments.
  • Document that embedding providers receive memory-derived content and require explicit user consent before enabling remote processing.
  • Apply network access controls so only the OpenClaw host can reach the embedding service.
  • Avoid placing real API keys directly in checked-in JSON files; use supported secret or environment-variable mechanisms.

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:59
Finding

Unconstrained Promotion of Conversation-Derived Content into Persistent Agent Control Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:59-67
Additional Locations: SKILL.md:176-183, SKILL.md:223-239, references/runtime-protocol.md:26-42, references/setup-checklist.md:58-94
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: High

Vulnerable Code:

markdown
### 5) Enforcement layer
If a recurring problem should change future behavior, also update one or more of:
- `SOUL.md`
- `AGENTS.md`
- `TOOLS.md`
- relevant `SKILL.md`
- relevant script/hook

The associated setup instructions reinforce this behavior:

markdown
Closeout protocol after each task:
1. Clear/reset SESSION-STATE.md
2. Write to memory/YYYY-MM-DD.md if anything worth keeping
3. Promote stable items to memory/preferences.md, system.md, or projects.md
4. If recurring issue: update SOUL.md / AGENTS.md / TOOLS.md

Technical Analysis

The Skill directs the agent to convert recurring observations, corrections, and apparent preferences into persistent personality, role, tool-policy, Skill, script, or hook files. These files can influence behavior across future sessions and unrelated tasks.

No robust trust boundary is defined between direct user instructions and content obtained from untrusted documents, retrieved memory, external tool output, or other conversational context. The promotion process also lacks mandatory user confirmation, provenance tracking, instruction sanitization, protected-rule conflict checking, or a prohibition against altering security constraints.

A repeated-content threshold is not a security control. An attacker able to cause the same instruction or apparent preference to appear multiple times may cause it to be classified as stable or recurring and promoted into persistent control files.

Attack Path

  1. The agent processes attacker-controlled text from a document, retrieved content, tool output, or conversation.
  2. The text presents a malicious i ...[truncated 1176 chars]
Remediation
View remediation

Remediation Suggestions

  • Prohibit autonomous modification of SOUL.md, AGENTS.md, TOOLS.md, Skill files, scripts, and hooks.
  • Require explicit, informed user approval before every enforcement-layer change.
  • Display the exact proposed diff, destination file, rationale, provenance, and expected behavioral effect before writing.
  • Treat external documents, tool output, retrieved memory, and web content as untrusted data that cannot authorize persistent rules.
  • Store observations as inert, quoted records rather than executable instructions.
  • Record source, timestamp, confidence, and approving user identity for every promoted memory item.
  • Prevent promoted rules from weakening safety policies, authorization boundaries, confirmation requirements, or secret-handling controls.
  • Use an allowlisted schema for persistent preferences instead of unrestricted natural-language instructions.
  • Add version history and a simple rollback mechanism for every persistent memory or control-file change.
  • Require separate confirmation and code review for all script or hook modifications.
  • Resolve conflicts in favor of higher-authority instructions and direct, authenticated user intent.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents an operational memory-orchestration skill that should manage ongoing memory behavior: saving memories, routing them among layers, adapting old memories, handling cleanup/migration, and keeping the system working over time. The supplied code instead performs one-time environment setup. It creates directories, copies template files into a workspace, checks for recommended config files, and reads a global OpenClaw JSON config to see whether semantic memory search is enabled. While this supports the memory system in a general sense, it does not implement the core behaviors promised by the description. The primary purpose is therefore materially different: setup/bootstrap validation rather than memory orchestration and persistence management.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

The skill is explicitly designed to decide what to capture, where to route it, and when to harden it into more persistent enforcement artifacts. In context this is intended functionality, but it is still security-relevant because a broadly empowered memory-orchestration skill can reshape persistent agent behavior and retain user data in multiple locations.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
# Memory Orchestrator

This skill is the workflow layer for the memory system. It does **not** replace
memory storage. It decides **what to capture, where to route it, when to
promote it, and when to harden it**.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
- relevant `SKILL.md`

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The command downloads a remote shell script and pipes it directly to the shell, executing unreviewed code from the network. If the site, transport, DNS, or upstream distribution path is compromised, users could run attacker-controlled code on their machine immediately.

Content

Scanner excerpt · references/embedding-setup.md (reported line 16)May include surrounding context.

1. Install Ollama

bash
curl -fsSL https://ollama.ai/install.sh | sh

Or download from ollama.ai.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh construct is a classic chaining pattern that removes the opportunity to inspect downloaded content before execution. In installation documentation, this materially increases the chance of accidental remote code execution from a compromised or tampered script source.

Content

Scanner excerpt · references/embedding-setup.md (reported line 16)May include surrounding context.

1. Install Ollama

bash
curl -fsSL https://ollama.ai/install.sh | sh

Or download from ollama.ai.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/memory/system.md (reported line 7)May include surrounding context.

md
> Update when a fact is confirmed. Mark outdated facts as [STALE].

## Environment
<!-- OS, shell, key tools and versions -->

## Key Paths
<!-- Important file paths, workspace directories, output directories -->

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 95)May include surrounding context.

md
A discipline that prevents memory debt from accumulating:

1. Reset `SESSION-STATE.md` — clear the hot state
2. Write daily recap — what happened, what was learned
3. Promote anything stable — to preferences, system, or projects
4. Enforce anything recurring — update SOUL/AGENTS/TOOLS
5. Mark converged entries — annotate old daily files if content has been promoted

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
"provider": "openai",
    "model": "text-embedding-3-small",
    "remote": {
      "baseUrl": "https://api.openai.com/v1",
      "apiKey": "YOUR_OPENAI_API_KEY"
    }
  }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to automatically create files and modify the workspace during setup without an upfront warning or confirmation. Silent filesystem changes can surprise users, overwrite expected project conventions, or create persistence artifacts the user did not intend.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The routing rules direct broad storage of user-provided preferences and other information into persistent memory files without defining sensitivity boundaries, minimization rules, or consent checks. In practice, this can cause accidental retention of secrets, personal data, or sensitive task context well beyond what the user expected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough that the skill could activate on many ordinary conversations about remembering, noting, or project continuity. In this skill's context, unintended invocation is riskier because the instructions also encourage persistent writes and edits across multiple workspace memory files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide recommends cloud embeddings via OpenAI but does not warn that memory content sent for embedding may leave the local system and be processed by a third party. In a memory skill, recalled and indexed content can include sensitive user preferences, task history, and other workspace data, so omission of a privacy warning materially increases the risk of unintentional data disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This example explicitly configures a remote OpenAI API endpoint, which means memory content and search queries may be transmitted off-host for embedding generation. In the context of a memory orchestration skill, that data flow is security-relevant because the indexed content may contain private or organizationally sensitive information.

Content

Scanner excerpt · references/embedding-setup.md (reported line 85)May include surrounding context.

md
"provider": "openai",
    "model": "text-embedding-3-small",
    "remote": {
      "baseUrl": "https://api.openai.com/v1",
      "apiKey": "YOUR_OPENAI_API_KEY"
    }
  }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The third-party OpenAI-compatible examples normalize sending memory content to arbitrary remote endpoints without any privacy, retention, or trust-boundary warning. Because this skill manages long-term memory, using unknown providers can expose highly sensitive workspace data to self-hosted or commercial services with different logging and retention practices.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The generic third-party provider URL encourages users to send embedding requests to arbitrary external services, expanding the trust boundary without warning. Since the feature operates over memory content, this can expose persistent notes, preferences, and other sensitive information to unvetted providers.

Content

Scanner excerpt · references/embedding-setup.md (reported line 144)May include surrounding context.

md
"provider": "openai",
    "model": "PROVIDER_MODEL_NAME",
    "remote": {
      "baseUrl": "https://api.YOUR_PROVIDER.com/v1",
      "apiKey": "YOUR_PROVIDER_API_KEY"
    }
  }

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The operational instructions are presented entirely in Chinese, which can impose a language constraint on users or downstream agents without opt-in. The file does not state that Chinese is required for a justified regional context, nor does it offer an alternative language option.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The protocol explicitly directs clearing or resetting SESSION-STATE.md and writing to multiple memory files, but it does not require user awareness, confirmation, or guardrails before modifying persisted data. In a memory-management skill, this creates a real risk of silent data loss, unwanted retention, or unauthorized state changes, especially because the skill is designed to orchestrate durable memory across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The checklist instructs users to copy template files directly into their workspace using plain cp, which can overwrite existing files without prompting depending on shell aliases, habits, or if users adapt the commands into scripts. In this skill’s context, the affected files are authoritative memory and behavior files, so accidental overwrite could destroy prior memory state or replace customized agent rules and summaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.