Back to skill

Security audit

Memory Pipeline

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent memory system, but it can automatically send private notes, transcripts, profile files, and extracted facts to external LLM providers and inject stored memory into future agent system prompts without strong consent or trust-boundary controls.

Install only if you are comfortable with a cross-session memory system that can retain conversation history and send selected notes, transcripts, profile data, todos, and extracted facts to OpenAI, Anthropic, or Gemini. Review and prune memory files first, avoid storing secrets in notes, prefer explicit environment/workspace scoping, and do not enable heartbeat automation until you have decided which sources and providers may be used.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/memory-extract.py:78
Finding

Automatic Transmission of Sensitive Memory Data to External LLM Providers

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
src/index.ts:13
Finding

Persistent Prompt Injection Through Verbatim Memory-File Insertion

Content
View full analysis
{ const workspaceRoot = ctx.workspaceRoot ?? api.config?.agents?.defaults?.workspace; const files = (briefingCfg.memoryFiles ?? []).map((p: string) => path.isAbsolute(p) ? p : path.join(workspaceRoot, p) ); const memoryText = await loadMemoryFiles(files); const packet = buildBriefingPacket({ checklist: briefingCfg.checklist ?? [], memoryText, maxChars: briefingCfg.maxChars ?? 6000, taskHint: ctx.input?.message ?? "", }); ctx.systemPromptAppend?.(`\n${packet}\n`); ctx.systemPromptParts?.push(packet); return ctx; }); ``` `src/briefing.ts:1-14`: ```typescript export function buildBriefingPacket(opts: { checklist: string[]; memoryText: string; maxChars: number; taskHint: string; }) { const header = `# Pre-Game Routine\n` + `Task hint: ${truncate(opts.taskHint, 240)}\n\n` + `## Checklist\n` + opts.checklist.map((x) => `- ${x}`).join("\n") + `\n\n## Retrieved Memory (bounded)\n`; const body = truncate(opts.memoryText, Math.max(0, opts.maxChars - header.length)); return truncate(header + body, opts.maxChars); } ``` `src/memory.ts:4-14`: ```typescript export async function loadMemoryFiles(files: string[]) { const parts: string[] = []; for (const f of files) { try { const txt = await fs.readFile(f, "utf8"); parts.push(`## ${f}\n${txt}\n`); } catch { // Missing files are fine. Keep routine resilient. } } return parts.join("\n"); } ``` ### Technical Analysis The `before_agent_start` hook loads persistent memory files, places their contents ...[truncated 2663 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (49)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description overstates the functionality of this specific code chunk. The script reads existing workspace files such as extracted facts, notes, identity/personality files, and todo files, then composes a daily briefing. Its only substantial behavior is briefing generation, either via an external LLM API (OpenAI/Anthropic/Gemini) or a local template fallback. Although it references files like extracted.jsonl and knowledge-graph.json, it does not extract facts, build or update a knowledge graph, ingest external data, or enforce agent execution policies. Therefore the declared description does not accurately represent this code chunk’s actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code only implements one subset of the declared system: extracting structured facts from local memory notes or session transcripts and saving deduplicated results. It does not build knowledge graphs, generate briefings, enforce execution discipline, apply tool policies, compress results, run after-action reviews, or ingest external knowledge sources like ChatGPT exports. Additionally, it accesses external network APIs for LLM-based extraction, which is not reflected in the declared permissions. While fact extraction is consistent with part of the description, the declared purpose substantially overstates the implemented functionality, making the description materially inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad, end-to-end memory plus performance framework. The supplied code only implements one subsystem: linking already-extracted facts into a knowledge graph and generating a summary. It reads from memory/extracted.jsonl, computes keyword or embedding similarity, detects simple contradictions, and saves graph artifacts. It does not extract facts, ingest external exports, create briefings beyond a simple summary, or enforce execution-discipline behaviors described in the declaration. Additionally, it makes outbound HTTP requests to OpenAI for embeddings, which is an accessed resource not reflected in the declared permissions. While the knowledge-graph portion aligns with part of the description, the overall declared purpose materially overstates what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code does implement parts of the description: briefing generation from memory files, execution-discipline enforcement via tool deny policies, tool-result compression, and after-action review persistence. However, several prominent declared capabilities are not present in this chunk. There is no logic for extracting structured facts, building knowledge graphs, ingesting external knowledge exports, or creating searchable memory. The actual code is a narrower lifecycle-hook plugin focused on injecting briefing text, restricting tools, compressing persisted tool output, and writing end-of-run notes. Because the description presents a much broader memory and knowledge-consolidation system than the code demonstrates, this is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · openclaw.plugin.json (reported line 4)May include surrounding context.

json
{
  "id": "memory-pipeline",
  "name": "Memory Pipeline + Performance Routine",
  "description": "Complete agent memory system: fact extraction, knowledge graph, daily briefings, pre-game routine hooks, tool discipline, and after-action review.",
  "kind": "memory",
  "version": "0.1.0",
  "configSchema": {
    "type": "object",
    "additionalProperties": false,
    "properties": {
      "enabled": { "type": "boolean", "default": true },
      "briefing": {
        "type": "object",
        "additionalProperties": false,
        "properties": {
          "maxChars": { "type": "number", "default": 6000 },
          "checklist": {
            "type": "array",
            "it

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The automation section instructs users to run the pipeline periodically while the skill is configured around external LLM providers, yet it does not clearly warn that workspace notes and session transcripts may be transmitted to third-party APIs. Automating such transfers amplifies the privacy risk because sensitive content may be sent repeatedly without fresh user review or consent.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · scripts/ingest-chatgpt.py (reported line 29)May include surrounding context.

python
def extract_conversations_json(source_path: str) -> list:
    """Extract conversations.json from a zip or read directly."""
    path = Path(source_path)
    
    if path.suffix == ".zip":

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code constructs outbound prompts from raw workspace memory without any explicit warning, consent flow, or indication that local notes and identity files will be shared externally. Because this skill is specifically designed to consolidate memory and context across sessions, the undisclosed upload behavior is more dangerous than in a generic summarizer: users are likely to assume these files remain local.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script reads daily memory notes or session transcripts, then sends that content to third-party LLM APIs for extraction without any consent gate, warning, redaction, or policy check. Because the source material includes user and assistant conversation history plus persistent notes, this creates a real privacy and data-governance risk, especially if transcripts contain secrets, personal data, or proprietary information.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises scripts that read and write workspace files, inspect environment/API-key locations, and make outbound calls to LLM providers, but the manifest does not declare any tool scope or permissions. That gap prevents informed consent and weakens policy enforcement because operators cannot clearly see that local data and secrets may be accessed and sent off-box.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The setup and pipeline are designed to create a persistent memory store and briefing artifacts across sessions, which can retain sensitive user data, decisions, transcripts, and imported conversations. Persistent storage is contextually central to this skill, so the risk is not that persistence exists, but that it may occur by default without clear retention limits, minimization, or consent boundaries.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

bash skills/memory-pipeline/scripts/setup.sh

text

The setup script will detect your workspace, check dependencies (Python 3 + any LLM API key), create the `memory/` directory, and run the full pipeline.

### Requirements

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly encourages importing ChatGPT export archives into local searchable memory, but it does not prominently warn that these exports can contain highly sensitive personal, business, and credential-adjacent content that will be persisted and re-surfaced later. In a memory-oriented skill, this is more dangerous because the whole purpose is durable retention and retrieval of past conversations, increasing exposure and accidental disclosure risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup.md (reported line 38)May include surrounding context.

export OPENAI_API_KEY="sk-..."

Via config file

mkdir -p ~/.config/openai echo "sk-..." > ~/.config/openai/api_key chmod 600 ~/.config/openai/api_key

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 40)May include surrounding context.

Via config file

mkdir -p ~/.config/openai echo "sk-..." > ~/.config/openai/api_key chmod 600 ~/.config/openai/api_key

text

**Anthropic:**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 49)May include surrounding context.

Via config file

mkdir -p ~/.config/openai echo "sk-..." > ~/.config/openai/api_key chmod 600 ~/.config/openai/api_key

text

**Anthropic:**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 58)May include surrounding context.

Via config file

mkdir -p ~/.config/openai echo "sk-..." > ~/.config/openai/api_key chmod 600 ~/.config/openai/api_key

text

**Anthropic:**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide states that session transcripts are read automatically and that derived memory artifacts are written persistently, but it does not warn users that potentially sensitive conversation content may be ingested, retained, and propagated into multiple files. In a memory-management skill, that omission materially increases the chance of accidental collection and long-term exposure of secrets, personal data, or confidential project details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script writes raw ChatGPT conversation content to persistent markdown files with no consent prompt, sensitivity detection, redaction, or warning that exports may contain secrets, personal data, or proprietary information. In a memory-ingestion skill, this is especially risky because the whole purpose is to retain and reuse context, increasing the chance that sensitive data is stored long-term and later surfaced to other tools or prompts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script automatically discovers API keys from environment variables and local config files, then uses those credentials to enable external LLM calls over workspace-derived memory data. This is a real security/privacy issue because it expands trust boundaries without explicit opt-in and may silently cause sensitive local data to be sent to third parties when credentials happen to be present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script accesses credentials from environment variables and user config files without any notice to the operator, which can surprise users and bypass expected approval boundaries. While merely reading keys is not exploitation by itself, in this script it is directly tied to external transmission logic, making the hidden credential access security-relevant.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script packages identity, user profile, todos, extracted facts, and recent notes into a prompt and transmits that raw context to OpenAI, Anthropic, or Gemini. In a memory-management skill, that context is especially likely to contain sensitive personal, organizational, or historical information, so external transmission creates a meaningful confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The OpenAI endpoint usage confirms intentional network egress to a third-party service using a bearer credential. Even though HTTPS is used, the security issue is not transport encryption but the undisclosed externalization of potentially sensitive local memory content.

Content

Scanner excerpt · scripts/memory-briefing.py (reported line 177)May include surrounding context.

python
try:
        if provider == "openai":
            response = requests.post(
                "https://api.openai.com/v1/chat/completions",
                headers={
                    "Content-Type": "application/json",

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The OpenAI endpoint usage confirms intentional network egress to a third-party service using a bearer credential. Even though HTTPS is used, the security issue is not transport encryption but the undisclosed externalization of potentially sensitive local memory content.

Content

Scanner excerpt · scripts/memory-briefing.py (reported line 177)May include surrounding context.

python
try:
        if provider == "openai":
            response = requests.post(
                "https://api.openai.com/v1/chat/completions",
                headers={
                    "Content-Type": "application/json",

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The hardcoded OpenAI API hostname confirms a direct third-party dependency for handling local memory content. This is not malicious code, but it does represent a real security-relevant data egress path inside a memory-focused skill where users may reasonably expect local-only processing.

Content

Scanner excerpt · scripts/memory-briefing.py (reported line 178)May include surrounding context.

python
try:
        if provider == "openai":
            response = requests.post(
                "https://api.openai.com/v1/chat/completions",
                headers={
                    "Content-Type": "application/json",
                    "Authorization": f"Bearer {api_key}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The Anthropic endpoint usage similarly confirms third-party transmission of local agent memory context. In this skill, the context is intentionally aggregated and therefore likely richer and more sensitive than typical single-file prompts, increasing the exposure from any upload.

Content

Scanner excerpt · scripts/memory-briefing.py (reported line 192)May include surrounding context.

python
timeout=90
            )
        elif provider == "anthropic":
            response = requests.post(
                "https://api.anthropic.com/v1/messages",
                headers={
                    "Content-Type": "application/json",

Static analysis

No suspicious patterns detected.