Back to skill

Security audit

Shared Memory for Multi-Agent OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent shared-memory purpose, but it makes persistent cross-workspace agent-instruction and memory changes without enough consent, scoping, or rollback controls.

Review before installing. Use this only if you deliberately want multiple workspaces to share persistent memory. Ask the agent to show exact file changes first, quote and validate all paths, avoid seeding personal information by default, define what may never be shared, and keep a removal plan for the symlinks, shared directory, and AGENTS.md protocol blocks.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:106
Finding

Persistent Cross-Agent Instruction and Memory Modification

Content
View full analysis
-latest.md`. 2. At the end of every conversation, update `sync/-latest.md` with the key points discussed with the user. ``` From `SKILL.md:166`: ```markdown - ✅ User info, preferences, decisions ``` ### Technical Analysis The skill directs the agent to make persistent changes to every participating agent's `AGENTS.md`. These changes cause future sessions to automatically read shared memory and other agents' synchronization files, then write conversation-derived information back to shared storage. Because the shared directory is writable by multiple agents and exposed through workspace symlinks, its contents cross individual workspace trust boundaries. An agent or process that can modify a synchronization or shared-memory file can insert false context or instruction-like content that other agents will automatically consume during later sessions. The skill does prohibit sharing credentials, but it does not specify that shared files must be treated solely as untrusted data. It also lacks schema validation, instruction filtering, integrity verification, access controls, retention limits, and safeguards against one agent inserting behavioral directives into another agent's context. This behavior is consistent with the skill's advertised shared-memory purpose, so it is not evidence of a covert malicious payload. Nevertheless, automatically persisting and propagating writable content across agents creates a memory-pois ...[truncated 1662 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:99
Finding

Shell Command Injection Through Unquoted Workspace Paths

Content
View full analysis
/shared-knowledge /shared-knowledge ``` ### Technical Analysis The workspace directory values originate from user-provided information. The documented macOS/Linux command inserts those values into a shell command without quoting, validation, or an end-of-options delimiter. A path containing whitespace will be split into multiple arguments. More critically, if an agent directly substitutes a value containing shell metacharacters such as semicolons, command substitutions, backticks, pipes, redirections, or newline characters, the shell can interpret those characters as executable syntax rather than as part of a filesystem path. For example, a maliciously supplied path containing a command substitution could cause that command to execute when the generated `ln -s` command is run. A path beginning with a hyphen may also be interpreted as an option unless option parsing is explicitly terminated. ### Attack Path 1. An attacker supplies a crafted host or destination workspace path when the skill asks for workspace locations. 2. The path contains shell syntax, such as command substitution or a command separator. 3. The agent replaces the documented placeholder with the attacker-controlled value without validation or shell-safe argument handling. 4. The agent executes the resulting command in a shell. 5. The shell evaluates the injected syntax and runs the attacker's command with the same operating-system privileges as the agent process. ### Impa ...[truncated 758 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation guidance is broad enough that the skill may activate on general discussion of multi-agent workflows or repeated context, even when the user did not clearly request filesystem changes or cross-agent memory sharing. This increases the chance of unintended setup actions affecting multiple workspaces and user data flows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prerequisite explanation is written directly in Chinese with no indication that the user requested that language or was given a language choice. This is a natural-language policy issue because it imposes a specific locale on user-facing output without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the agent to 'do everything automatically' and later perform filesystem changes, symlink creation, and modifications to AGENTS.md without an upfront user-facing warning describing these persistent system changes. This can surprise users, alter multiple workspaces, and create durable links between environments with security and privacy implications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs agents to collect, persist, and propagate user information, preferences, decisions, and conversation context across multiple workspaces. Even if framed as convenience, this creates cross-agent long-term memory and broadens the exposure of potentially sensitive user data beyond the original interaction boundary.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The initialization step tells the agent to pre-populate shared memory with known user basic information and work context, causing immediate replication of user data into a shared repository. This is risky because it encourages copying personal or contextual information before clear data classification, minimization, or consent boundaries are established.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill modifies other agents' AGENTS.md files to impose persistent behavior at every session start and end, effectively rewriting their operating instructions without a narrowly scoped one-time setup boundary. This creates durable cross-agent data flows and can silently change future agent behavior in ways the user may not fully understand or expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The block to append to AGENTS.md is entirely in Chinese and is presented as the default text to install for each agent. The skill does not offer language selection or justify a Chinese-only protocol, so it effectively forces a locale without user opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The protocol makes persistent cross-workspace storage and sharing of user context and conversation summaries the default operating mode. Default persistence of user-provided context increases privacy risk, expands the blast radius of any workspace compromise, and may violate user expectations around data minimization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The protocol rules normalize routine cross-agent reading and writing of shared context but do not include a privacy warning about the fact that user context, decisions, and summaries will be accessible from multiple workspaces. Omitting that warning undermines informed consent and may cause users to disclose information they did not expect to be replicated.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill claims some information should stay private, but its definition of shareable content includes user preferences and decisions, which are often privacy-sensitive and may overlap with private memory in practice. This ambiguity can lead agents to over-share personal context because the boundary is underspecified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.