T01 · Skill Instruction Hijacking
- Location
SKILL.md:13- Finding
Mandatory Persistent Collection of Personal Information
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent with its stated NotNative integration purpose, but it asks for broad persistent memory and remote tool authority without enough consent, scoping, or transport safeguards.
Review this before installing if you are comfortable with a NotNative server receiving and retaining personal facts, preferences, notes, profile data, task/calendar data, and Python code. Prefer a local or authenticated wss:// endpoint, avoid remote ws:// URLs, inspect what memory is stored, and be prepared to remove the .bashrc entry and $HOME/.local/bin/notnative symlink if uninstalling.
SKILL.md:13Mandatory Persistent Collection of Personal Information
scripts/mcp-client.js:5Sensitive MCP Data Can Be Transmitted to an Arbitrary Plaintext WebSocket Endpoint
install.sh:56Installer Creates Persistent Shell Configuration and Executable Hook
package.json:8Dependency Installation Is Not Reproducibly Locked
The natural-language instructions repeatedly require the assistant to permanently record user facts and recall them across all conversations, creating a durable data retention and cross-session leakage risk. This is especially dangerous in a memory-integrated skill because the assistant may over-collect sensitive details and later surface them in unrelated contexts or to the wrong user/session.
The skill embeds strong imperative instructions such as 'ALWAYS' and 'MUST' that attempt to steer agent behavior independently of higher-level safety and privacy policy. Even if not overtly malicious, this is prompt-injection-like behavior because it pressures the agent to prioritize persistent memory actions, including storing personal information, over safer contextual judgment and consent checks.
---
name: notnative
description: Use Notnative MCP server for complete AI assistant integration with notes, calendar, tasks, Python, canvas, and permanent memory. This skill provides persistent memory across conversations - ALWAYS use memory tools to remember user preferences, facts they share, and important context. Connects via WebSocket to local or remote Notnative instance.
homepage: https://github.com/k4ditano/notnative-memory
metadata:
openclaw:
emoji: "🧠"
requires:
bins: ["node", "curl"]
---
# NotNative - Complete AI Integration
**⚠️ CRITICAL: This skill provides PERMANENT MEMORY. You MUST use memory tools to remember user preferences
The skill explicitly mandates permanent storage of user personal information across conversations and instructs the assistant to do so automatically, without requiring informed user consent or describing retention limits. This creates a privacy and compliance risk because sensitive personal data may be collected, retained, and later retrieved or exposed beyond the user's expectation.
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
Referenced artifact was not completely inspected
node scripts/mcp-client.js store "User prefers responses in Spanish"
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
R/scripts/mcp-client.js"
# Save config
mkdir -p "$SCRIPT_DIR/.config"
echo "NOTNATIVE_WS_URL=$WS_URL" > "$SCRIPT_DIR/.config/env"
# Add to PATH in .bashrc if not already
BIN_DIR="$HOME/.local/bin"
mkdir -p "$BIN_DIR"
if [ ! -L "$BIN_DIR/notnative" ]; then
ln -sf "$SCRIPT_DIR/scripts/mcp-client.js" "$BIN_DIR/notnative"
fi
if ! grep -q "NOTNATIVE_WS_URL" "$HOME/.bashrc" 2>/dev/null; then
echo "export NOTNATIVE_WS_URL=\"$WS_URL\"" >> "$HOME/.bashrc"
fi
echo ""
echo "✅ NotNative skill installed!"
echo ""
echo "Usage:"
echo " node scripts/mcp-client.js search <query> # Search notes"
echo " node scripts/mcp-client.js store <text> # Store memory"
echo " node scripts/mcp-client.js recall <query> # Search memory"
echo " node scripts/mcp-client.js tasks # List tasks"
echo " node scripts/mcp-client.js events # Calendar events"
echo " node scripts/mcp-client.js run-python <code> # Execute Python"
echo ""
echo "Or use directly: notnative <command> [
The skill exposes shell and environment-dependent behavior via Node and curl requirements plus command examples, but it does not declare any explicit tool scope or permission boundaries. In an agent setting, missing scope constraints increases the chance of unintended command execution or access to sensitive local/remote resources through the MCP client.
The skill advertises create, update, append, forget/delete, calendar/task creation, web access, and Python execution capabilities without prominent safety guardrails, confirmation requirements, or warnings about side effects. In practice, this can lead to destructive data modification, unauthorized state changes, or risky code execution if the agent follows ambiguous or malicious prompts.
The installer modifies the user's shell environment persistently by creating a command symlink and appending an export to .bashrc without explicit warning or confirmation. Persistent profile changes can affect future shells, expose sensitive connection details, and create long-lived trust in a tool that connects to local or remote services.
The installer advertises a run-python <code> capability, which materially expands the skill from note/calendar integration into arbitrary code execution. Even though this line is only a usage message, exposing code execution through the installed client increases the chance that users or downstream agents invoke dangerous functionality that is not clearly emphasized in the skill framing.
Advertising arbitrary Python execution without clear justification or warning is risky because it can normalize use of a powerful remote/local execution feature under an integration-oriented skill. In the context of a tool with persistent memory and external connectivity, this makes misuse or unintended execution more dangerous.
No suspicious patterns detected.