Back to skill

Security audit

memory-attention-router

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it can store and reuse long-term agent memory in future sessions without strong confirmation, isolation, or trust boundaries.

Review before installing. Use this only with an isolated database per user/project, require explicit user approval before saving or replacing durable preferences, avoid global memories by default, and invoke the Python script with argument arrays or stdin rather than interpolated shell strings.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
scripts/memory_router.py:333
Finding

Untrusted Input Can Be Promoted to Persistent Global Agent Instructions

Content
View full analysis
= 2 OR role_scope = 'global') ORDER BY importance DESC, updated_at DESC LIMIT 40 """, [*allowed_types], ).fetchall() ingest(durable_rows) recent_rows = conn.execute( f""" SELECT * FROM memories WHERE is_active = 1 AND memory_type IN ({placeholders}) ORDER BY updated_at DESC LIMIT 50 """, [*allowed_types], ).fetchall() ingest(rece ...[truncated 4338 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:60
Finding

Documented Shell Invocation Allows Command Injection Through JSON Content

Content
View full analysis
' ``` ```text python3 {baseDir}/scripts/memory_router.py add --input-json '' ``` ```text python3 {baseDir}/scripts/memory_router.py reflect --input-json '' ``` ```text python3 {baseDir}/scripts/memory_router.py refresh --input-json '' ``` ### Technical Analysis The Skill instructs agents to place serialized JSON inside a single-quoted shell argument. JSON strings can legitimately contain apostrophes, and attacker-controlled memory text can contain shell metacharacters. If an agent constructs this command as text and executes it through a shell, an apostrophe inside the JSON terminates the quoted argument. The attacker can then append a shell command and comment out the remaining text. JSON serialization does not make a value safe for shell interpolation. For example, attacker-controlled content structurally resembling the following can break the shell quoting when inserted into the documented template: ```text '; attacker_command; # ``` The Python script itself does not invoke a shell. Exploitation depends on the calling agent or integration executing the documented command through a shell, which is the usage pattern presented by `SKILL.md`. ### Attack Path 1. An attacker provides a goal, preference, failure description, lesson, title, summary, or other field containing an apostrophe followed by shell syntax. 2. The agent serializes that content as JSON. 3. The agent substitutes the serialized JSON into the documented `--input-json ''` command. 4. The integration executes the resulting command through a shell. 5. The apostrophe closes the intended quoted JSON argument. 6. The shell interprets the remaining attacker-controlled text as a separate comma ...[truncated 660 chars]
Remediation
View remediation
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
95% confidence
Finding

This skill is explicitly designed to preserve, replace, refresh, and retire long-term memory, which creates a real memory-manipulation surface. Even if intended for legitimate preference management, an attacker could phrase instructions as durable rules or replacements to poison stored memory, override prior constraints, or cause stale-but-malicious preferences to persist across sessions.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
## Trigger cues

Trigger immediately when the user states a durable rule or asks to preserve or replace memory, especially with phrases like:

- from now on
- remember this

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to invoke local Python scripts and describes filesystem-backed database behavior, but it declares no explicit tool scope or permissions. That mismatch can cause agents or platforms to grant broader-than-expected access, reducing auditability and increasing the chance of unintended file or environment access during skill execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes common terms like 'always' and 'prefer' that appear in ordinary conversation, making accidental activation likely. Because this skill can read, write, refresh, and retire long-term memory, spurious activation can persist unintended preferences or route sensitive context into durable storage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instruction to trigger whenever a step 'needs compact memory state' is subjective and underspecified, leaving broad discretion to the agent. In a memory-writing skill, ambiguous routing criteria can lead to overuse, unnecessary memory retrieval, and contamination of future tasks with irrelevant or sensitive prior context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The string "Use English only." imposes a fixed language requirement. This is a natural-language policy concern because it removes user language choice and does not indicate any opt-in or justified locale restriction.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/TESTING.md (reported line 16)May include surrounding context.

If you are using this Git repo directly, copy the repo's skills/ directory so that:

text
<your-openclaw-workspace>/skills/memory-attention-router/SKILL.md

exists exactly at that path.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The testing instructions include rm -f "$MAR_DB_PATH" and then initialize a new database, which is a destructive file operation. The section does not explicitly warn users that running these commands will delete any existing database at that path, even though this could remove prior test data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The add/reflect/refresh flows persist user-supplied memory content and can retire prior memories, but the code provides no built-in disclosure, consent check, or policy gate at the moment those durable changes occur. In an agent setting, this can silently store sensitive preferences, task history, or failures across sessions and alter future behavior without the user's awareness, creating privacy and integrity risks even though the writes are otherwise intentional application logic.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Reflections and working-memory packets intentionally convert user-provided inputs into plain-language summaries and the list/inspect/packets commands expose those stored records in clear form. In a multi-user or shared-agent environment, this broadens the blast radius of sensitive data by making preferences, failures, goals, and other context easy to retrieve, inspect, and reuse beyond the original interaction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The route operation writes a working_memory_packets record containing goal, session_id, task_id, and a synthesized packet derived from user constraints, failures, and open questions. Because this persistence happens automatically during routing with no disclosure or opt-in, task context that may have been expected to remain ephemeral becomes durable and retrievable later, increasing privacy exposure and data minimization concerns.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JSON file appears to describe skill/session routing context, but it provides no explicit invocation conditions, trigger phrases, or exclusion boundaries. For a manifest-scoped file type, the absence of trigger specificity can lead to unclear or overly broad activation behavior if this data is used to select or route a skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.