Back to skill

Security audit

Memory Evolver

Security checks for vulnerabilities and agentic risk

Overview

This memory-management skill is mostly purpose-aligned, but it reads and writes persistent agent memory from a hard-coded Administrator workspace and encourages scheduled unattended runs without clear user control.

Review before installing. Only use this skill if you are comfortable with it reading OpenClaw memory and project files and writing an optimization log. Prefer running it manually against a confirmed workspace, avoid enabling the cron schedule until the path and write behavior are scoped, and treat its optimization log as advisory because it can report actions as completed without actually changing the underlying memory files.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
index.py:20
Finding

Unrestricted Access to Persistent Agent Workspace State

Content
View full analysis

Vulnerability Details

File Location: index.py, lines 20-25, 33-36, 46-49, 57, 63-68, and 173-185
Vulnerability Type: Access beyond least-privilege requirements
Risk Level: Medium

Vulnerable Code

python
BASE_DIR = r'C:\Users\Administrator\.openclaw\workspace'
MEMORY_FILE = os.path.join(BASE_DIR, 'MEMORY.md')
PROJECTS_FILE = os.path.join(BASE_DIR, 'PROJECTS.md')
MEMORY_DIR = os.path.join(BASE_DIR, 'memory')
KG_DIR = os.path.join(BASE_DIR, 'knowledge_graph')
OPTIMIZATION_LOG = os.path.join(BASE_DIR, 'memory', 'optimization循环.md')
python
if os.path.exists(MEMORY_FILE):
    with open(MEMORY_FILE, 'r', encoding='utf-8') as f:
        content = f.read()
        lines = len(content.split('\n'))
python
if os.path.exists(PROJECTS_FILE):
    with open(PROJECTS_FILE, 'r', encoding='utf-8') as f:
        content = f.read()
python
daily_files = [f for f in os.listdir(MEMORY_DIR) if f.startswith('2026-') and f.endswith('.md')]
python
kg_file = os.path.join(KG_DIR, 'graph.json')
if os.path.exists(kg_file):
    with open(kg_file, 'r', encoding='utf-8') as f:
        kg = json.load(f)
python
# Append to the log
if os.path.exists(OPTIMIZATION_LOG):
    with open(OPTIMIZATION_LOG, 'r', encoding='utf-8') as f:
        existing = f.read()
    content = existing + content
else:
    content = "# 记忆系统优化循环日志\n" + content

with open(OPTIMIZATION_LOG, 'w', encoding='utf-8') as f:
    f.write(content)

Technical Analysis

The script is bound to a hard-coded global OpenClaw workspace under the Windows Administrator profile. When invoked, it reads long-term memory, project information, daily-memory metadata, and knowledge-graph data without requiring the caller to select or authorize the workspace. It also writes a persistent file inside the Agent's memory directory.

A diagnostic skill should follow least privilege by operating ...[truncated 1888 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the hard-coded Administrator workspace path.
  2. Require the workspace to be supplied explicitly through a command-line argument or trusted configuration source.
  3. Resolve the path with os.path.realpath and verify that it is inside an approved workspace root.
  4. Reject paths belonging to unexpected users or privileged profiles.
  5. Default to a read-only diagnostic mode and require an explicit option such as --write-log before changing persistent state.
  6. Display the exact files that will be read or written and obtain confirmation before accessing sensitive Agent memory.
  7. Open the log in append mode rather than reading and rewriting the entire file.
  8. Apply restrictive file permissions to the generated log and avoid recording sensitive memory contents.
  9. Handle missing directories and malformed graph data safely so that validation failures do not cause unintended behavior.
  10. Run the skill under a dedicated, non-administrative account with access only to the intended workspace.

T09 · Insecure Skill Coding Practices

Note
Location
index.py:139
Finding

Optimization Actions Are Persisted as Successful Without Being Executed

Content
View full analysis

Vulnerability Details

File Location: index.py, lines 139-149 and 169-178
Vulnerability Type: Persistent state-integrity failure caused by false execution reporting
Risk Level: Low

Vulnerable Code

python
def execute_optimization(plan):
    """执行优化"""
    print("\n" + "=" * 60)
    print("⚡ 执行优化")
    print("=" * 60)
    
    executed = []
    
    for item in plan:
        if item['priority'] == '高':
            print(f"  🔴 执行: {item['action']}")
            executed.append(item['action'])
    
    return executed
python
for item in plan:
    status = "✅" if item['action'] in executed else "⏳"
    content += f"- {status} [{item['priority']}] {item['type']}: {item['action']}\n"

content += "\n### 执行结果\n"
for action in executed:
    content += f"- ✅ {action}\n"

Technical Analysis

execute_optimization() does not perform the actions contained in the plan. It only prints each high-priority action and adds its text to the executed list. The logging function subsequently treats list membership as proof that an action completed successfully and records a success marker in persistent Agent memory.

For example, an action claiming that MEMORY.md was supplemented or PROJECTS.md was improved is marked complete even though neither file is changed. There are also no postcondition checks to verify that the requested state exists.

This behavior contradicts the documented optimization functionality and produces inaccurate persistent records. Although no direct attacker-controlled input reaches the log in the reviewed implementation, the defect can undermine the integrity of future Agent decisions that rely on the optimization history.

Attack Path

  1. The diagnostic phase identifies an issue involving MEMORY.md or PROJECTS.md.
  2. The planning phase creates a high-priority action for the issue.
  3. execute_optimization() prints the action and adds ...[truncated 861 chars]
Remediation
View remediation

Remediation Suggestions

  1. Implement each optimization action as a concrete operation rather than recording its description as executed.
  2. Return structured execution results containing the action identifier, success state, errors, and changed files.
  3. Verify action-specific postconditions before assigning a successful status.
  4. Mark unimplemented actions as recommended, planned, or not implemented rather than completed.
  5. Require confirmation before modifying MEMORY.md, PROJECTS.md, or other persistent Agent state.
  6. Use atomic file updates and preserve backups when implementing actual modifications.
  7. Record failures and partial completion accurately in the optimization log.
  8. Add tests confirming that a success marker cannot be written unless the corresponding state change occurred and was verified.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documentation describes behavior that reads and writes memory-related files, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because users and enforcement layers cannot easily tell what filesystem access the skill requires, increasing the chance of overbroad or unexpected modification of user memory data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises automatic optimization, rebuilding, and logging of memory files but provides no warning that it may modify or persist user data. In a memory-management context, unattended writes can alter long-term notes, daily logs, or project state in ways the user did not explicitly review, creating integrity and privacy risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Documenting scheduled execution for daily automatic optimization without warning about unattended changes creates a real risk of silent filesystem modifications over time. Because this skill targets a persistent memory system, scheduled runs could repeatedly rewrite or expand sensitive records without contemporaneous user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description and feature strings are written entirely in Chinese, which implies a fixed language for the skill's user-facing behavior or documentation. Because the file does not state that the skill is China-specific or that language selection is optional, this creates a natural-language policy concern around forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s docstring and all visible user-facing messages are written in Chinese, indicating the skill is designed to operate in a single language without offering user opt-in or locale selection. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a持续自我进化 system that optimizes and evolves memory, yet execute_optimization only records high-priority actions in a list and log_optimization merely writes those planned actions to a markdown log. No code updates MEMORY.md, PROJECTS.md, daily logs, or graph.json to perform the claimed optimization or evolution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and description force Chinese-language interaction/documentation without indicating that users can opt into another language. Under the stated policy, a fixed language requirement without user choice or clear regional justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.