T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party Packages Are Installed and Automatically Upgraded
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent persistent-memory skill, but it needs Review because it stores conversation-derived data by default, shares new entries at team scope by default, and tells agents to perform silent fixes and upgrades.
Install only if you are comfortable with a local memory system that can automatically retain conversation context, tool observations, and session summaries. Before use, consider setting autoCapture to false or minimal, changing default_scope to private, avoiding public scope, pinning package/plugin versions, and requiring confirmation before upgrades, exports, syncs, doctor --fix, pruning, or deletion.
SKILL.md:14Unpinned Third-Party Packages Are Installed and Automatically Upgraded
SKILL.md:703Automatic Conversation Capture Persists Data with Team Visibility by Default
SKILL.md:138Unconditional Trust in Package-Generated CLI Guidance Creates an Instruction-Hijacking Channel
The skill embeds imperative operational instructions that tell the agent to perform installation and setup when certain phrases appear, effectively acting as hidden or authority-seeking instructions inside untrusted content. This is dangerous because it can steer agent behavior toward environment modification without independent safety checks or explicit user confirmation.
palaia is the memory system for OpenClaw agents. It gives you persistent, searchable, crash-safe memory across sessions. You don't need to understand how it works — just use the commands below.
<!-- begin:install -->
## First-Time Setup
When a user asks you to "set up palaia", "enable memory", or "remember things across sessions", run these steps:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
palaia-mcp--root /path/to/.palaia)Claude Code (~/.claude/settings.json):
{"mcpServers": {"palaia": {"command": "palaia-mcp"}}}
The skill promotes automatic conversation capture and shared team knowledge across agents, which creates a real context-leakage risk if sensitive or user-confidential information is captured and later surfaced to other agents or exported. The risk is amplified because auto-capture is positioned as a default productivity feature rather than a narrowly consented data flow.
If a new agent is added later and does NOT have palaia configured, it will:
- Not auto-capture conversations
- Not benefit from shared team knowledge
- Potentially duplicate work that palaia already tracked
The skill uses broad natural-language triggers such as 'enable memory' or 'remember things across sessions' to initiate installation and activation. This can cause an agent to perform state-changing setup actions from ambiguous user phrasing without first confirming that the user wants persistent storage and auto-capture enabled.
The setup flow tells the agent to confirm that memory is ready and will automatically remember important context, but it does not require a user-facing warning that cross-session persistence and auto-capture will store conversation-derived data locally. This undermines informed consent for retention of potentially sensitive information.
The skill instructs the agent to run diagnostics silently every time the skill is loaded and to address warnings immediately before proceeding. Silent checks and especially silent fixes create undisclosed side effects, potentially modifying the environment or configuration without user awareness.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Entry Types
- **memory** — Facts, decisions, learnings (default)
- **process** — Workflows, checklists, SOPs (team runbooks)
- **task** — Sticky notes / reminders for future sessions. Tasks are ephemeral: when marked done, they are automatically deleted. Never auto-captured — only created by explicit `palaia write --type task`.
---
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Entry Types
- **memory** — Facts, decisions, learnings (default)
- **process** — Workflows, checklists, SOPs (team runbooks)
- **task** — Sticky notes / reminders for future sessions. Tasks are ephemeral: when marked done, they are automatically deleted. Never auto-captured — only created by explicit `palaia write --type task`.
---
Subtle instructions detected that may alter agent decision-making or introduce hidden biases.
palaia upgrade
Auto-detects the install method (pip/uv/pipx/brew), preserves all installed extras (fastembed, mcp, sqlite-vec, curate), runs `palaia doctor --fix`, and upgrades the OpenClaw npm plugin if present. Always use this instead of manual pip commands.
### `palaia ui` — Local memory explorer (NEW in v2.7)
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Session continuity gives agents automatic context restoration across sessions. These features work out of the box with the OpenClaw plugin -- no manual setup needed.
### Session Briefings
Session briefings are injected automatically at session start. They contain your last session summary and any open tasks (sticky notes). Read the briefing carefully — it is your primary context for continuing previous work. Do not ask the user "where did we leave off?" when a briefing is present. Instead, acknowledge the context and continue seamlessly.
### Session Summaries
When a session ends or resets, palaia auto-saves a summary of what happened. These are stored as entries with the `session-summary` tag and can be queried:
No suspicious patterns detected.