Back to skill

Security audit

Self Memory Manager

Security checks for vulnerabilities and agentic risk

Overview

This memory-management skill is understandable in purpose, but it asks the agent to persist account/API information and copy an OpenClaw config file into a Desktop archive without safeguards.

Review before installing. This skill should only be used if you are comfortable with the agent writing long-lived local memory files. Do not let it archive raw config files, tokens, credentials, account details, or API keys; use redacted task summaries only and require explicit confirmation before any write or recall from the archive.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Plaintext Persistence of Potentially Sensitive Configuration and Account Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the agent to persist account information, API-related changes, task progress, and project state into local memory files for future retrieval. In a memory-management skill, this is especially risky because it normalizes long-term retention of potentially sensitive data and makes later disclosure more likely, whether through accidental recall, local compromise, or overbroad reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs archiving account information and configuration-related material without any warning, minimization, or secret-handling safeguards. That is dangerous because persistent storage of sensitive operational data increases the attack surface and can expose credentials or private account details through later access, sync, or local compromise.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The example command copies a local configuration file directly into the work folder, encouraging durable storage of a file that may contain tokens, credentials, or other sensitive settings. Providing this as a ready-to-use command materially increases the likelihood of unsafe secret persistence and later exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation conditions are broad enough that the skill could be invoked in many ordinary conversations without clear user consent or scope boundaries. Because this skill writes to persistent local storage and handles prior-session memory, ambiguous triggering increases the chance of unintended data retention or access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

All user-facing instructions, triggers, and workflow text are in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can constitute a language/locale policy issue when a skill imposes one language by default without opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow tells the agent to consult stored files when answering questions about prior conversations, creating a mechanism to retrieve previously archived sensitive data outside the original context. When combined with the archival instructions, this increases the chance of privacy leakage and unauthorized resurfacing of old user information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger table uses broad conditions like completing important tasks or being asked about prior matters, without limiting scope or requiring user approval. In this skill context, those triggers can cause automatic persistence or retrieval of user data from local files, which raises privacy and over-collection risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs copying a local configuration file into a persistent archive directory, which expands the skill from benign memory management into handling potentially secret-bearing configuration material. Config files commonly contain tokens, endpoints, or user-specific secrets, so persisting them for later retrieval creates an unnecessary disclosure and retention risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The phrase 'every so often check context usage' is vague because it provides no concrete interval, event hook, or stopping condition. This ambiguity can lead to inconsistent or overly frequent invocation of the skill's checking behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.