Back to skill

Security audit

Ecloud Long Term Memory

Security checks for vulnerabilities and agentic risk

Overview

This cloud memory skill is not clearly malicious, but it needs Review because it overreaches in credential handling, automatic personal-data upload, persistent agent-rule changes, and unsafe transport/logging behavior.

Install only after careful review. Use least-privilege, revocable credentials rather than production AK/SK values, do not enter secrets directly in chat or shell history, and confirm you are comfortable with personal memories being sent to a remote cloud service. Also review or patch the .env write behavior, debug logging, TLS bypass, and persistent rule instructions before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:15
Finding

Mandatory Skill Instructions Override Agent Safety and Tool Selection

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:76
Finding

Persistent Poisoning of Agent Memory and Project Rules

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
memory.js:258
Finding

Automatic External Disclosure of Verbatim Personal Information

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
memory.js:188
Finding

Configurable Arbitrary Destination and Conditional TLS Verification Bypass

Content
View full analysis
{ const queryParams = (method === 'GET' && payload) ? payload : {}; const { signature, canonicalQs } = generateSignature(method, pathStr, queryParams); const signedQs = `Signature=${percentEncode(signature)}`; let url; if (method === 'GET' && canonicalQs) { url = `${HOST}${pathStr}?${canonicalQs}&${signedQs}`; } else { url = `${HOST}${pathStr}?${canonicalQs}&${signedQs}`; } const parsedUrl = new URL(url); const isHttps = parsedUrl.protocol === 'https:'; const options = { hostname: parsedUrl.hostname, port: parsedUrl.port || (isHttps ? 443 : 80), path: parsedUrl.pathname + parsedUrl.search, method: method.toUpperCase(), headers: { 'Content-Type': 'application/json', 'Pool-Id': POOL_ID, }, timeout: 15000, }; if (isHttps && HOST.includes('31015')) { options.rejectUnauthorized = false; } const req = (isHttps ? https : http).request(options, (res) => { ``` ### Technical Analysis `MEMORY_BASE_URL` controls the complete request origin and is not restricted to the documented cloud endpoint. The implementation accepts both `https:` and `http:` URLs. If the host string contains `31015`, TLS certificate verification is explicitly disabled. An actor able to modify the process environment or one of the `.env` files read by the Skill can redirect all memory operations to another endpoint. Requests contain the Ac ...[truncated 1651 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
memory.js:19
Finding

Sensitive Request and Response Data Written to Local Logs

Content
View full analysis
300 ? '...' : ''}`); log('DEBUG', `[${requestId}] Response: ${data.substring(0, 500)}`); if (payload && (method === 'POST' || method === 'PUT')) { const body = JSON.stringify(payload); req.write(body); log('DEBUG', `[${requestId}] Request body: ${body.substring(0, 500)}`); } ``` ### Technical Analysis The log directory and file are created without an explicit restrictive permission mode. Their effective permissions therefore depend on the process umask and surrounding directory permissions. The URL contains canonical authentication parameters, including the Access Key, timestamp, nonce, request parameters, and signature. POST request bodies can contain user IDs, library IDs, personal memories, and search terms. Responses can contain returned memory records. Up to 300 or 500 characters are persisted for each of these values. The log function does not redact secrets or distinguish safe operational metadata from sensitive payload data. No rotation, retention limit, or secure deletion behavior is implemented. ### Attack Path 1. The user performs a save, search, list, or configuration-check operation. 2. The Skill constructs a signed URL and possibly a JSON body containi ...[truncated 834 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup.js:65
Finding

Parent Environment File Overwrite and Unsafe Secret Provisioning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description promises memory storage/search behavior, but the document also mandates credential collection, local configuration, and command execution that are not clearly disclosed in the top-level purpose. This mismatch can mislead operators and users about the real data flows and trust boundary, especially because highly sensitive AK/SK secrets are requested and persisted during setup.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
3. **所有记忆操作(存储、检索、列出、搜索)必须通过执行本目录下的 `memory.js` 脚本完成。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
3. **所有记忆操作(存储、检索、列出、搜索)必须通过执行本目录下的 `memory.js` 脚本完成。**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
`memory.js` 和 `setup.js` 位于当前 skill 目录下(与 `SKILL.md` 同级)。执行命令时无需切换目录,直接使用相对路径即可。

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to collect AK/SK cloud credentials directly in conversation and execute setup commands, but provides no warning about the sensitivity of those secrets, how they are stored, or safer alternatives. This exposes users to credential theft, accidental logging, transcript retention, and misuse if the conversation or local environment is compromised.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Requiring users to provide AK/SK secrets in plain conversational flow is a serious secret-handling weakness. Chat transcripts, tool logs, shell history, and local process inspection can all expose these credentials, potentially allowing unauthorized access to the user's cloud resources.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs persistence of user-provided cloud configuration state and identifiers beyond the immediate setup flow. Persisting setup artifacts broadens the exposure window for account-linked data and encourages the agent to maintain durable records outside a secure secret-management path.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill reads process environment variables and multiple local .env files to obtain credentials and runtime configuration, but this capability is not limited to narrowly scoped memory operations. In an agent-skill context, undeclared access to host configuration expands trust boundaries and can expose secrets from the host environment if the skill is installed or invoked unexpectedly.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The code is built to access credentials from local .env files, which is a real credential-access capability on the host filesystem. In a third-party skill context, this matters because the skill is not limited to direct user input and can harvest secrets from adjacent configuration files to authenticate outbound requests.

Content

Scanner excerpt · memory.js (reported line 29)May include surrounding context.

js
}

function getEnvPaths() {
    const paths = [path.join(__dirname, '.env')]; // 当前 skill 目录优先
    paths.push(path.join(__dirname, '..', '.env'));

    // 判断当前目录是否包含 mobileclaw

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

Reading a parent-directory .env file expands secret access beyond the skill directory and may capture unrelated application credentials. This widens the blast radius if the skill is misused or compromised, especially on shared hosts where parent configs serve multiple components.

Content

Scanner excerpt · memory.js (reported line 30)May include surrounding context.

js
function getEnvPaths() {
    const paths = [path.join(__dirname, '.env')]; // 当前 skill 目录优先
    paths.push(path.join(__dirname, '..', '.env'));

    // 判断当前目录是否包含 mobileclaw
    const cwd = process.cwd();

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Accessing ~/.config/mobileclaw/.env reaches into the user's home configuration, which is a high-value secret source outside the skill's own sandbox. In an agent memory skill, this host-level credential reach is more dangerous because the skill already handles sensitive personal data and has network egress to transmit it.

Content

Scanner excerpt · memory.js (reported line 36)May include surrounding context.

js
const cwd = process.cwd();
    const isMobileClaw = cwd.includes('mobileclaw');
    if (isMobileClaw) {
        paths.push(path.join(os.homedir(), '.config', 'mobileclaw', '.env'));
    }
    // else {
    //     paths.push(path.join(os.homedir(), '.openclaw', '.env'));

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory.js (reported line 39)May include surrounding context.

js
paths.push(path.join(os.homedir(), '.config', 'mobileclaw', '.env'));
    }
    // else {
    //     paths.push(path.join(os.homedir(), '.openclaw', '.env'));
    // }

    return paths;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.js (reported line 66)May include surrounding context.

js
paths.push(path.join(os.homedir(), '.config', 'mobileclaw', '.env'));
    }
    // else {
    //     paths.push(path.join(os.homedir(), '.openclaw', '.env'));
    // }

    return paths;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.js (reported line 67)May include surrounding context.

js
paths.push(path.join(os.homedir(), '.config', 'mobileclaw', '.env'));
    }
    // else {
    //     paths.push(path.join(os.homedir(), '.openclaw', '.env'));
    // }

    return paths;

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

Direct access to process.env is a real credential-access primitive and, in combination with outbound network requests, enables the skill to use host-provided secrets without a narrow permission boundary. This is particularly sensitive here because the skill persists and searches personal memories remotely, so misuse can affect both secrets and user data.

Content

Scanner excerpt · memory.js (reported line 50)May include surrounding context.

js
// 1. 进程环境变量优先
    if (process.env[key]) return process.env[key];

    // 2. 按优先级读取 .env 文件
    const envPaths = getEnvPaths();
    for (const envPath of envPaths) {
        if (fs.existsSync(envPath)) {

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly disables TLS certificate verification for certain HTTPS hosts by setting rejectUnauthorized = false. This permits man-in-the-middle interception of requests carrying credentials and sensitive memory data, defeating transport security entirely for matching hosts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The description and required trigger phrases are specified only in Chinese, and the skill says these phrases '必须使用此技能' without indicating that users may interact in other languages or opt into Chinese-only behavior. This is a natural-language policy concern because it imposes a language expectation without explicit user choice or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill first forbids local storage of user information, then later instructs the agent to record configuration details in local files or internal memory. This contradictory guidance increases the chance that sensitive identifiers or other user data will be persisted outside the intended cloud system, undermining privacy guarantees and policy compliance.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document states that future memory must use only cloud long-term memory, but also requires local or internal recording of configuration state and identifiers. This creates an unsafe split-storage model where operators may believe data is cloud-only while sensitive state is still retained elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill requires storing configuration status and identifiers locally or in internal memory without clearly informing the user that this data will persist beyond the current session. Even if the stored values are not full secrets, they are account-linked identifiers that can expose usage patterns and weaken privacy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions for saving memory are broad enough to capture ordinary conversation, preferences, plans, and updates without strong scope limits or confirmation. In a memory skill handling personal data, this can lead to over-collection and storage of sensitive information the user did not meaningfully intend to persist.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest explicitly advertises cloud-backed long-term memory that stores highly sensitive personal data such as name, age, occupation, and preferences, but it provides no user-facing disclosure that this content will be transmitted to and persisted on a remote third-party service. In a memory skill, this omission materially weakens informed consent and can cause users to reveal sensitive information they would not share if they understood the storage and transmission model.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The save_memory function is specifically designed to upload raw user statements to the cloud, yet its description does not warn that submitted content will leave the local agent context and be remotely persisted. Because the skill is intended to capture personal memories from natural language, this creates a meaningful risk of silently exfiltrating sensitive user data to external infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest requires Access Key and Secret Key credentials for a cloud service but gives no warning about secure handling of those secrets. In agent ecosystems, undocumented secret use increases the chance of unsafe deployment practices, accidental exposure in logs or repos, and overbroad trust in an external service handling sensitive memory data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code enumerates and reads several local .env files, including paths under the user's home directory, to discover credentials and configuration. This broad secret discovery behavior increases the chance of unintentionally consuming or exposing host secrets unrelated to the memory function, especially in a skill that handles sensitive personal data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.