T01 · Skill Instruction Hijacking
- Location
SKILL.md:15- Finding
Mandatory Skill Instructions Override Agent Safety and Tool Selection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This cloud memory skill is not clearly malicious, but it needs Review because it overreaches in credential handling, automatic personal-data upload, persistent agent-rule changes, and unsafe transport/logging behavior.
Install only after careful review. Use least-privilege, revocable credentials rather than production AK/SK values, do not enter secrets directly in chat or shell history, and confirm you are comfortable with personal memories being sent to a remote cloud service. Also review or patch the .env write behavior, debug logging, TLS bypass, and persistent rule instructions before use.
SKILL.md:15Mandatory Skill Instructions Override Agent Safety and Tool Selection
SKILL.md:76Persistent Poisoning of Agent Memory and Project Rules
memory.js:258Automatic External Disclosure of Verbatim Personal Information
memory.js:188Configurable Arbitrary Destination and Conditional TLS Verification Bypass
memory.js:19Sensitive Request and Response Data Written to Local Logs
setup.js:65Parent Environment File Overwrite and Unsafe Secret Provisioning
The skill description promises memory storage/search behavior, but the document also mandates credential collection, local configuration, and command execution that are not clearly disclosed in the top-level purpose. This mismatch can mislead operators and users about the real data flows and trust boundary, especially because highly sensitive AK/SK secrets are requested and persisted during setup.
Referenced artifact was not completely inspected
3. **所有记忆操作(存储、检索、列出、搜索)必须通过执行本目录下的 `memory.js` 脚本完成。**
Referenced artifact was not completely inspected
3. **所有记忆操作(存储、检索、列出、搜索)必须通过执行本目录下的 `memory.js` 脚本完成。**
Referenced artifact was not completely inspected
`memory.js` 和 `setup.js` 位于当前 skill 目录下(与 `SKILL.md` 同级)。执行命令时无需切换目录,直接使用相对路径即可。
The skill instructs the agent to collect AK/SK cloud credentials directly in conversation and execute setup commands, but provides no warning about the sensitivity of those secrets, how they are stored, or safer alternatives. This exposes users to credential theft, accidental logging, transcript retention, and misuse if the conversation or local environment is compromised.
Requiring users to provide AK/SK secrets in plain conversational flow is a serious secret-handling weakness. Chat transcripts, tool logs, shell history, and local process inspection can all expose these credentials, potentially allowing unauthorized access to the user's cloud resources.
The skill explicitly instructs persistence of user-provided cloud configuration state and identifiers beyond the immediate setup flow. Persisting setup artifacts broadens the exposure window for account-linked data and encourages the agent to maintain durable records outside a secure secret-management path.
The skill reads process environment variables and multiple local .env files to obtain credentials and runtime configuration, but this capability is not limited to narrowly scoped memory operations. In an agent-skill context, undeclared access to host configuration expands trust boundaries and can expose secrets from the host environment if the skill is installed or invoked unexpectedly.
The code is built to access credentials from local .env files, which is a real credential-access capability on the host filesystem. In a third-party skill context, this matters because the skill is not limited to direct user input and can harvest secrets from adjacent configuration files to authenticate outbound requests.
}
function getEnvPaths() {
const paths = [path.join(__dirname, '.env')]; // 当前 skill 目录优先
paths.push(path.join(__dirname, '..', '.env'));
// 判断当前目录是否包含 mobileclaw
Reading a parent-directory .env file expands secret access beyond the skill directory and may capture unrelated application credentials. This widens the blast radius if the skill is misused or compromised, especially on shared hosts where parent configs serve multiple components.
function getEnvPaths() {
const paths = [path.join(__dirname, '.env')]; // 当前 skill 目录优先
paths.push(path.join(__dirname, '..', '.env'));
// 判断当前目录是否包含 mobileclaw
const cwd = process.cwd();
Accessing ~/.config/mobileclaw/.env reaches into the user's home configuration, which is a high-value secret source outside the skill's own sandbox. In an agent memory skill, this host-level credential reach is more dangerous because the skill already handles sensitive personal data and has network egress to transmit it.
const cwd = process.cwd();
const isMobileClaw = cwd.includes('mobileclaw');
if (isMobileClaw) {
paths.push(path.join(os.homedir(), '.config', 'mobileclaw', '.env'));
}
// else {
// paths.push(path.join(os.homedir(), '.openclaw', '.env'));
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
paths.push(path.join(os.homedir(), '.config', 'mobileclaw', '.env'));
}
// else {
// paths.push(path.join(os.homedir(), '.openclaw', '.env'));
// }
return paths;
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
paths.push(path.join(os.homedir(), '.config', 'mobileclaw', '.env'));
}
// else {
// paths.push(path.join(os.homedir(), '.openclaw', '.env'));
// }
return paths;
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
paths.push(path.join(os.homedir(), '.config', 'mobileclaw', '.env'));
}
// else {
// paths.push(path.join(os.homedir(), '.openclaw', '.env'));
// }
return paths;
Direct access to process.env is a real credential-access primitive and, in combination with outbound network requests, enables the skill to use host-provided secrets without a narrow permission boundary. This is particularly sensitive here because the skill persists and searches personal memories remotely, so misuse can affect both secrets and user data.
// 1. 进程环境变量优先
if (process.env[key]) return process.env[key];
// 2. 按优先级读取 .env 文件
const envPaths = getEnvPaths();
for (const envPath of envPaths) {
if (fs.existsSync(envPath)) {
The code explicitly disables TLS certificate verification for certain HTTPS hosts by setting rejectUnauthorized = false. This permits man-in-the-middle interception of requests carrying credentials and sensitive memory data, defeating transport security entirely for matching hosts.
The description and required trigger phrases are specified only in Chinese, and the skill says these phrases '必须使用此技能' without indicating that users may interact in other languages or opt into Chinese-only behavior. This is a natural-language policy concern because it imposes a language expectation without explicit user choice or justification.
The skill first forbids local storage of user information, then later instructs the agent to record configuration details in local files or internal memory. This contradictory guidance increases the chance that sensitive identifiers or other user data will be persisted outside the intended cloud system, undermining privacy guarantees and policy compliance.
The document states that future memory must use only cloud long-term memory, but also requires local or internal recording of configuration state and identifiers. This creates an unsafe split-storage model where operators may believe data is cloud-only while sensitive state is still retained elsewhere.
The skill requires storing configuration status and identifiers locally or in internal memory without clearly informing the user that this data will persist beyond the current session. Even if the stored values are not full secrets, they are account-linked identifiers that can expose usage patterns and weaken privacy expectations.
The trigger conditions for saving memory are broad enough to capture ordinary conversation, preferences, plans, and updates without strong scope limits or confirmation. In a memory skill handling personal data, this can lead to over-collection and storage of sensitive information the user did not meaningfully intend to persist.
The manifest explicitly advertises cloud-backed long-term memory that stores highly sensitive personal data such as name, age, occupation, and preferences, but it provides no user-facing disclosure that this content will be transmitted to and persisted on a remote third-party service. In a memory skill, this omission materially weakens informed consent and can cause users to reveal sensitive information they would not share if they understood the storage and transmission model.
The save_memory function is specifically designed to upload raw user statements to the cloud, yet its description does not warn that submitted content will leave the local agent context and be remotely persisted. Because the skill is intended to capture personal memories from natural language, this creates a meaningful risk of silently exfiltrating sensitive user data to external infrastructure.
The manifest requires Access Key and Secret Key credentials for a cloud service but gives no warning about secure handling of those secrets. In agent ecosystems, undocumented secret use increases the chance of unsafe deployment practices, accidental exposure in logs or repos, and overbroad trust in an external service handling sensitive memory data.
The code enumerates and reads several local .env files, including paths under the user's home directory, to discover credentials and configuration. This broad secret discovery behavior increases the chance of unintentionally consuming or exposing host secrets unrelated to the memory function, especially in a skill that handles sensitive personal data.
No suspicious patterns detected.