Back to skill

Security audit

Pieces Long-Term Memory (MCP)

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent purpose, but it asks users to expose sensitive long-term memory through a public tunnel and make persistent tool changes without enough access-control guidance.

Only install this if you intentionally want OpenClaw connected to Pieces long-term memory. Use a private or authenticated tunnel rather than a bare public URL, review the MCPorter config change before saving it, avoid global npm installation where possible, and treat Pieces results as sensitive context that should be queried and written only when needed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:82
Finding

Unauthenticated Public Exposure of Sensitive Long-Term Memory Services

Content
View full analysis
ngrok http 39300 ``` ```bash curl -i "MCP_URL_MCP" ``` The data returned by the exposed service may include highly sensitive activity: ```markdown - `events[]` — Raw activity events (browser, clipboard, audio, etc.) ``` The skill also explicitly permits arbitrary HTTPS reverse proxies: ```markdown | **Any HTTPS proxy** | `https://your-domain.com` | As long as it forwards to 39300 | ``` ### Technical Analysis The skill instructs users to expose the PiecesOS MCP service running on local port `39300` through ngrok or another public HTTPS proxy. It does not require or describe any substantive access-control mechanism such as: - Tunnel-level authentication - MCP bearer-token authorization - Mutual TLS - Source IP restrictions - Identity-aware proxy enforcement - Per-tool authorization - Read-only access controls The documented `mcp-session-id` is session state rather than an authorization credential. The initialization procedure allows a client to submit an arbitrary initial session identifier and receive a server-assigned identifier. Consequently, possession or discovery of the tunnel URL may be sufficient to initiate a session. This risk is particularly significant because the service can return long-term-memory content and raw events involving browser, clipboard, and audio activity. It also exposes a memory-creation tool, meaning unauthorized access may affect both confidentiality and integrity. ### ...[truncated 1495 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:490
Finding

Global Installation of a Third-Party Executable Without Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 739)May include surrounding context.

md
**Symptoms:**

- Pieces returns "failed to extract context" or times out.
- Answers are too generic.

**What to try:**

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill instructs issuing curl requests to an externally exposed tunnel endpoint, which transmits local agent activity and connectivity metadata to a remote service. While intended for connectivity testing, it still creates outbound network interaction to infrastructure that may be user-controlled, third-party hosted, or intercepted via tunnel misconfiguration.

Content

Scanner excerpt · SKILL.md (reported line 133)May include surrounding context.

Always run this GET request first to confirm the route is alive:

bash
curl -i "MCP_URL_MCP"

Expected success response (HTTP 400):

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

Creating ~/.openclaw/workspace/config is part of establishing persistent integration state on disk, enabling the external memory connection to survive across sessions. In security terms this increases persistence and can make future automatic access to the external MCP server easier without repeated user review.

Content

Scanner excerpt · SKILL.md (reported line 428)May include surrounding context.

4.1 Ensure the config directory exists

bash
mkdir -p ~/.openclaw/workspace/config

4.2 Create or update mcporter.json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to create or modify ~/.openclaw/workspace/config/mcporter.json, which changes persistent local configuration and can alter future tool connectivity and trust boundaries. Even though the goal is legitimate integration, the instructions do not require explicit user confirmation, backup, or disclosure that this is a lasting config change that may affect other MCP servers or future sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs restarting the OpenClaw gateway after config changes, which can interrupt active sessions, temporarily disable services, or disrupt other configured integrations. This is operationally risky because there is no required warning, maintenance check, or user consent immediately before the restart.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill tells the agent to treat Pieces as 'authoritative long-term memory' and to retrieve and synthesize historical user activity, meetings, profile data, and events into responses. This expands access to sensitive external memory without strong verification, minimization, or consent boundaries, increasing the risk of privacy violations, overcollection, and disclosure of inaccurate or stale personal context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 647)May include surrounding context.

md
**Symptom:**

`curl MCP_URL_MCP` returns 404/502/HTML or times out.

**What to do:**

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 679)May include surrounding context.

  1. Use file-based JSON (avoid shell quoting issues):
    bash
    # Create init.json with your JSON payload
    curl -i -X POST "MCP_URL_MCP" \
      -H "Content-Type: application/json" \
      -H "Accept: application/json, text/event-stream" \
    

Static analysis

No suspicious patterns detected.