Back to skill

Security audit

Palaia

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent persistent-memory skill, but it needs Review because it stores conversation-derived data by default, shares new entries at team scope by default, and tells agents to perform silent fixes and upgrades.

Install only if you are comfortable with a local memory system that can automatically retain conversation context, tool observations, and session summaries. Before use, consider setting autoCapture to false or minimal, changing default_scope to private, avoiding public scope, pinning package/plugin versions, and requiring confirmation before upgrades, exports, syncs, doctor --fix, pruning, or deletion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party Packages Are Installed and Automatically Upgraded

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:703
Finding

Automatic Conversation Capture Persists Data with Team Visibility by Default

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:138
Finding

Unconditional Trust in Package-Generated CLI Guidance Creates an Instruction-Hijacking Channel

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

The skill embeds imperative operational instructions that tell the agent to perform installation and setup when certain phrases appear, effectively acting as hidden or authority-seeking instructions inside untrusted content. This is dangerous because it can steer agent behavior toward environment modification without independent safety checks or explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
palaia is the memory system for OpenClaw agents. It gives you persistent, searchable, crash-safe memory across sessions. You don't need to understand how it works — just use the commands below.

<!-- begin:install -->
## First-Time Setup

When a user asks you to "set up palaia", "enable memory", or "remember things across sessions", run these steps:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 244)May include surrounding context.

  • Command: palaia-mcp
  • Arguments: (none, or --root /path/to/.palaia)

Claude Code (~/.claude/settings.json):

json
{"mcpServers": {"palaia": {"command": "palaia-mcp"}}}

Context Leakage

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill promotes automatic conversation capture and shared team knowledge across agents, which creates a real context-leakage risk if sensitive or user-confidential information is captured and later surfaced to other agents or exported. The risk is amplified because auto-capture is positioned as a default productivity feature rather than a narrowly consented data flow.

Content

Scanner excerpt · SKILL.md (reported line 589)May include surrounding context.

text

If a new agent is added later and does NOT have palaia configured, it will:
- Not auto-capture conversations
- Not benefit from shared team knowledge
- Potentially duplicate work that palaia already tracked

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill uses broad natural-language triggers such as 'enable memory' or 'remember things across sessions' to initiate installation and activation. This can cause an agent to perform state-changing setup actions from ambiguous user phrasing without first confirming that the user wants persistent storage and auto-capture enabled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The setup flow tells the agent to confirm that memory is ready and will automatically remember important context, but it does not require a user-facing warning that cross-session persistence and auto-capture will store conversation-derived data locally. This undermines informed consent for retention of potentially sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to run diagnostics silently every time the skill is loaded and to address warnings immediately before proceeding. Silent checks and especially silent fixes create undisclosed side effects, potentially modifying the environment or configuration without user awareness.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
### Entry Types
- **memory** — Facts, decisions, learnings (default)
- **process** — Workflows, checklists, SOPs (team runbooks)
- **task** — Sticky notes / reminders for future sessions. Tasks are ephemeral: when marked done, they are automatically deleted. Never auto-captured — only created by explicit `palaia write --type task`.

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 521)May include surrounding context.

md
### Entry Types
- **memory** — Facts, decisions, learnings (default)
- **process** — Workflows, checklists, SOPs (team runbooks)
- **task** — Sticky notes / reminders for future sessions. Tasks are ephemeral: when marked done, they are automatically deleted. Never auto-captured — only created by explicit `palaia write --type task`.

---

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 446)May include surrounding context.

palaia upgrade

text

Auto-detects the install method (pip/uv/pipx/brew), preserves all installed extras (fastembed, mcp, sqlite-vec, curate), runs `palaia doctor --fix`, and upgrades the OpenClaw npm plugin if present. Always use this instead of manual pip commands.

### `palaia ui` — Local memory explorer (NEW in v2.7)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 739)May include surrounding context.

md
Session continuity gives agents automatic context restoration across sessions. These features work out of the box with the OpenClaw plugin -- no manual setup needed.

### Session Briefings
Session briefings are injected automatically at session start. They contain your last session summary and any open tasks (sticky notes). Read the briefing carefully — it is your primary context for continuing previous work. Do not ask the user "where did we leave off?" when a briefing is present. Instead, acknowledge the context and continue seamlessly.

### Session Summaries
When a session ends or resets, palaia auto-saves a summary of what happened. These are stored as entries with the `session-summary` tag and can be queried:

Static analysis

No suspicious patterns detected.