Back to skill

Security audit

Continuous Context Preserver

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it asks the agent to persist conversation summaries across sessions and includes a cleanup script with deletion-scope risks that users should review before installing.

Install only if you intentionally want the agent to keep concise local session-memory files. Avoid storing secrets, credentials, regulated data, or private personal details in session logs; review or delete the sessions directory regularly; and fix the cleanup script before using cron or custom environment variables.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cleanup.sh:5
Finding

Unvalidated retention value permits find expression injection and unintended file deletion

Content
View full analysis

Vulnerability Details

File Location: scripts/cleanup.sh, lines 5-18
Vulnerability Type: Unvalidated environment-variable injection into a find expression
Risk Level: Medium

bash
SESSIONS_DIR="${SESSIONS_DIR:-$HOME/.openclaw/workspace/sessions}"
RETENTION_DAYS="${RETENTION_DAYS:-7}"
LOG_FILE="${LOG_FILE:-$HOME/.openclaw/workspace/logs/session-cleanup.log}"

# Create log directory if needed
mkdir -p "$(dirname "$LOG_FILE")"
mkdir -p "$SESSIONS_DIR"

echo "[$(date '+%Y-%m-%d %H:%M:%S')] Starting session cleanup..." >> "$LOG_FILE"
echo "[$(date '+%Y-%m-%d %H:%M:%S')] Sessions dir: $SESSIONS_DIR" >> "$LOG_FILE"
echo "[$(date '+%Y-%m-%d %H:%M:%S')] Retention: $RETENTION_DAYS days" >> "$LOG_FILE"

# Count files before
BEFORE=$(find "$SESSIONS_DIR" -name "*.md" -type f 2>/dev/null | wc -l)

# Delete files older than retention period
find "$SESSIONS_DIR" -name "*.md" -type f -mtime +$RETENTION_DAYS -delete -print 2>/dev/null | while read -r file; do

Technical Analysis

RETENTION_DAYS can be supplied through the process environment and is neither validated as an integer nor safely passed as one argument. The unquoted expansion in -mtime +$RETENTION_DAYS undergoes shell word splitting. Consequently, a value containing spaces and additional find predicates is interpreted as part of the expression rather than solely as an age value.

For example, a value such as 7 -o -type f transforms the effective expression into:

bash
find "$SESSIONS_DIR" -name "*.md" -type f -mtime +7 -o -type f -delete -print

Because find evaluates conjunction before -o, the injected second branch can apply -delete to every regular file under the selected directory, bypassing the intended Markdown filename and retention-age restrictions.

The danger is amplified because SESSIONS_DIR is also environment-configurable. Although it is correctly quoted against shell injection, it is not constrained to ...[truncated 1568 chars]

Remediation
View remediation

Remediation Suggestions

  1. Validate RETENTION_DAYS before using it:

    bash
    case "$RETENTION_DAYS" in
      ''|*[!0-9]*)
        echo "Invalid RETENTION_DAYS: must be a non-negative integer" >&2
        exit 1
        ;;
    esac
    
  2. Pass the complete age expression as one quoted argument:

    bash
    find "$SESSIONS_DIR" -name '*.md' -type f -mtime "+${RETENTION_DAYS}" -delete -print
    
  3. Canonicalize SESSIONS_DIR and verify that it is the expected sessions directory or a descendant of an explicitly approved workspace before performing deletion.

  4. Reject dangerous target directories, including empty paths, /, $HOME, and the workspace root.

  5. Run cleanup as an unprivileged user and avoid installing the cron entry under root.

  6. Consider removing the environment override for SESSIONS_DIR unless configurability is required. If it is required, accept the path through a validated configuration file or explicit command-line option.

  7. Add a dry-run mode and log the candidate files before deletion, particularly for initial setup or retention-policy changes.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description emphasizes active session logging, context preservation, and intelligent summarization/compression for memory survival across sessions. The actual code only performs file housekeeping: it counts markdown files, deletes ones older than a configurable number of days, and writes cleanup logs. While cleanup of old files is one small aspect mentioned in the description, the primary declared functionality—recording and preserving conversation context—is absent from this code chunk. Therefore the code does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs continuous logging and retention of conversation-derived context but does not require a prominent privacy warning or informed consent about persistent storage. This is dangerous because users may disclose secrets, personal data, or confidential project information during normal use, which would then be silently preserved across sessions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation description is broad enough that an agent may activate this skill during ordinary conversations and begin persisting user-derived context without a narrowly scoped trigger. In a persistence-focused skill, over-broad activation increases the chance of collecting and storing sensitive data when the user did not clearly intend durable logging.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill's stated purpose is to preserve conversation context across sessions, which inherently creates a durable archive of user-provided information. Even if intended for convenience, cross-session persistence expands the exposure window for sensitive data and can violate user expectations if not tightly bounded and consented to.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

Writing context to a file throughout the conversation creates persistent session state outside the ephemeral chat boundary. This increases risk of data leakage, unauthorized local access, and accidental long-term retention of sensitive content, especially because the files are plain markdown and the process is continuous.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
## The Solution

Continuous session logging. Write to a file throughout the conversation, not at a trigger point.

## Setup

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions operationalize continuous in-session logging of key points and important information, increasing the likelihood that sensitive conversational content will be written to disk throughout the interaction. Continuous logging is especially risky because it happens before a user can review or sanitize what is being retained.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.