Back to skill

Security audit

Hypabase Memory

Security checks for vulnerabilities and agentic risk

Overview

This persistent-memory skill is purpose-aligned, but it needs review because it stores broad user and project facts long-term while running an unpinned external MCP package.

Install only if you are comfortable with an agent keeping a persistent local memory database. Avoid storing secrets, credentials, health, financial, legal, or confidential work data unless you have a clear retention policy. Pin and review the `hypabase` package before use where possible, and do not enable the OpenAI embedder unless you accept memory contents being processed by that provider.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
claw.json:19
Finding

Unpinned Python Package Is Downloaded and Executed at Runtime

Content
View full analysis

Vulnerability Details

File Location: claw.json:19-24 and SKILL.md:22-28
Vulnerability Type: Supply-chain exposure through an unpinned runtime dependency
Risk Level: Medium

The skill configures uvx to download and execute the hypabase package without an exact version, integrity hash, lockfile, or bundled auditable implementation.

Complete configuration from claw.json:19-24:

json
"mcp": {
  "command": "uvx",
  "args": ["--from", "hypabase", "hypabase-memory"],
  "env": {
    "HYPABASE_DB_PATH": "hypabase.db"
  }
},

The same behavior is documented in SKILL.md:22-28:

json
{
  "mcpServers": {
    "hypabase-memory": {
      "command": "uvx",
      "args": ["--from", "hypabase", "hypabase-memory"],
      "env": { "HYPABASE_DB_PATH": "hypabase.db" }
    }

Technical Analysis

The uvx command resolves the named Python package from an external package registry and executes its hypabase-memory entry point. Because hypabase has no exact version constraint, each installation or invocation may resolve to a newer or otherwise different package release than the one originally reviewed.

The project contains only SKILL.md and claw.json; it does not contain the executable server implementation, a dependency lockfile, package hashes, or signature-verification policy. Consequently, the effective executable payload is outside the audited artifact and may change independently of it.

Exploitation requires compromise or malicious modification of the resolved package or its dependency chain. The audit found no evidence that the package is currently malicious.

Attack Path

  1. An attacker compromises the package publication account, registry distribution path, or an unpinned transitive dependency.
  2. The attacker publishes a modified release that is eligible for resolution under the unrestricted package name.
  3. OpenClaw starts the configured MCP server.
  4. ` ...[truncated 1137 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin hypabase to an explicitly reviewed, immutable version rather than resolving the latest compatible release.
  2. Generate and retain a dependency lockfile covering the package and all transitive dependencies.
  3. Require cryptographic hashes for downloaded distributions and reject artifacts whose hashes do not match the reviewed values.
  4. Prefer vendoring the reviewed MCP implementation into the skill or distributing it as a signed, immutable artifact so its executable behavior is included in security review.
  5. Verify package provenance and publisher identity before updates, and review dependency changes before changing the pinned version.
  6. Run the MCP server in a sandbox with minimum filesystem and network access. Restrict it to the intended database path wherever practical.
  7. Use a dedicated low-privilege operating-system account and avoid exposing unrelated secrets through inherited environment variables.
  8. Apply equivalent version and integrity controls to every transitive dependency, not only the top-level hypabase package.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises persistent storage of user preferences, decisions, facts, and events, but does not prominently warn users about privacy, retention, or the possibility that sensitive information may be stored long-term. Because the core function is memory persistence, the missing warning is especially dangerous: users and agents may treat ordinary conversation as ephemeral when it is actually being retained in a searchable knowledge graph.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guidance for when to store memories is broad enough that an agent could persist large amounts of routine conversation, including sensitive facts, without a strong relevance threshold or explicit user consent. In a persistent-memory skill, over-collection materially increases privacy risk and can lead to retention of confidential or unnecessary personal data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a persistent memory skill backed by a local knowledge graph, which is well aligned with storing and recalling memories. However, the documented support for an openai embedder implies sending memory content to an external API, a capability that is not clearly justified or declared by the skill's stated purpose as presented in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.