Back to skill

Security audit

Structured Vector Memory (SVM)

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is purpose-aligned but installs scheduled jobs that repeatedly inspect conversation history and modify persistent agent memory/control files without enough user control.

Review carefully before installing. Only use this if you intentionally want automated local memory maintenance, recurring cron jobs, conversation-history review, and long-term summaries. Consider running it manually first, disabling autoCapture/autoRecall until needed, adding retention and deletion procedures, and removing authority to update SYSTEM_GUIDE.md without explicit review.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T06 · System Persistence

Error
Location
SKILL.md:84
Finding

Recurring Cron Jobs Establish Cross-Session Persistence

Content
View full analysis
> ~/.openclaw/logs/micro-sync.log 2>&1 0 1 * * * ~/.openclaw/shared/daily-wrapup.sh >> ~/.openclaw/logs/daily-wrapup.log 2>&1 0 3 * * 0 ~/.openclaw/shared/weekly-compound.sh >> ~/.openclaw/logs/weekly-compound.log 2>&1 ``` ### Technical Analysis The installation instructions copy three scripts into a persistent user directory, grant them executable permissions, and register recurring user-level cron jobs. These tasks survive the original Skill run and continue executing under the installing user's account. Scheduling is directly related to the declared automatic memory-maintenance functionality and is not concealed. Nevertheless, persistent cron registration exceeds the privileges required for an on-demand memory-management operation. The configuration also lacks an on-demand default, explicit lifecycle controls, an uninstall procedure, integrity checks, and protections against subsequent replacement of the installed scripts. Because cron executes scripts by path, any process able to modify files under `~/.openclaw/shared/` could alter what the recurring jobs execute. ### Attack Path 1. A user follows the Skill installation instructions. 2. The three scripts are copied into `~/.openclaw/shared/` and made executable. 3. The user installs the supplied crontab entries. 4. Cron invokes the scripts repeatedly after the installation session has ended. 5. Each execution modifies persistent OpenClaw state through `HEARTBEAT.md`. 6. If an installed script is later replaced or modified, cron executes the changed content with the user's priv ...[truncated 439 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
scripts/micro-sync.sh:16
Finding

Scheduled Scripts Inject Persistent Instructions into Agent Control State

Content
View full analysis
> "$HEARTBEAT" << EOF # MICRO_SYNC @ $TIMESTAMP - [ ] Scan sessions active during the last three hours using sessions_list and sessions_history - [ ] Record only confirmed decisions, new rules, architecture changes, and explicit remember instructions - [ ] Do not record routine questions, casual conversation, or unresolved discussions - [ ] Deduplicate with memory_recall; if similarity is above 70 percent, use memory_update - [ ] Assign finance, content, ecommerce, or technology agent scopes; use global for shared content - [ ] Use the format: reason, finding, conclusion - [ ] Append to the current daily memory file without overwriting it - [ ] Review recent LanceDB auto-captures and delete obvious noise or casual conversation - [ ] Remove this MICRO_SYNC section after completion EOF ``` The other two scripts use the same persistent append mechanism: ```bash cat >> "$HEARTBEAT" << EOF ``` ### Technical Analysis Rather than performing narrowly defined maintenance directly, each scheduled script appends natural-language instructions to `HEARTBEAT.md`. This file acts as persistent Agent control state, so later Agent sessions may interpret and execute package-authored instructions. The tasks direct the Agent to inspect conversation histories, write durable memory, delete captured records, archive information, and modify other workspace state. There is no cryptographic provenance check, approval gate, expiration mechanism, or duplicate-task guard. If a prior task remains unfinished, another scheduled execution can append another copy. The Skill also instructs users to add package-provided beh ...[truncated 1159 chars]
Remediation
View remediation

other

Warning
Location
SKILL.md:133
Finding

Overbroad Conversation-History Collection and Durable Summarization

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
scripts/weekly-compound.sh:14
Finding

Weekly Memory Compaction Can Modify Persistent System Guidance

Content
View full analysis
> "$HEARTBEAT" << EOF # WEEKLY_COMPOUND @ $TIMESTAMP - [ ] Current MEMORY.md size: ${MEMORY_SIZE} bytes - [ ] Sources: daily memory files and second-brain summaries - [ ] Steps: 1. Back up MEMORY.md to memory/archive/MEMORY-backup-$(date '+%Y%m%d').md 2. Compare this week's daily memory and summary content 3. Distill information worth retaining into MEMORY.md 4. Move completed items, obsolete settings, and excessive details to the archive 5. Archived content remains searchable 6. If architectural changes such as new agents or workflows occurred, update SYSTEM_GUIDE.md 7. Keep MEMORY.md at or below 8 KB 8. Never modify SOUL.md 9. Record the size before and after the update - [ ] Remove this WEEKLY_COMPOUND section after completion EOF ``` ### Technical Analysis The weekly memory-compaction task authorizes the Agent to update `SYSTEM_GUIDE.md` when it infers that an architectural change occurred. A memory-compaction process should not have authority to modify persistent system guidance, particularly when its evidence comes from user conversations and automatically generated summaries. There is no requirement to verify architectural changes against a trusted configuration source, present a patch for review, or obtain explicit approval. Consequently, untrusted or ambiguous conversational content can be promoted into authoritative guidance. ### Attack Path 1. Conversation content states or implies that a new Agent, workflow, or architectural rule has been adopted. 2. Daily processing stores that statement in memory or a summary. 3. The weekly task compares the stored material and identifies it as an architectural change. 4. The Agent updates `SYSTEM_GUIDE.md` base ...[truncated 591 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This duplicate finding points to the same persistence-enabling directory creation used for archives and summaries. In the context of a memory skill, that storage scaffolding materially supports retention of session-derived data and therefore carries the same privacy risk when no notice or lifecycle controls are provided.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

1. 创建目录结构

bash
mkdir -p ~/.openclaw/workspace/memory/archive
mkdir -p ~/.openclaw/workspace/second-brain/summaries

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This duplicate finding points to the same persistence-enabling directory creation used for archives and summaries. In the context of a memory skill, that storage scaffolding materially supports retention of session-derived data and therefore carries the same privacy risk when no notice or lifecycle controls are provided.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

1. 创建目录结构

bash
mkdir -p ~/.openclaw/workspace/memory/archive
mkdir -p ~/.openclaw/workspace/second-brain/summaries

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The installation instructions explicitly enable autoCapture and autoRecall, causing ongoing collection and resurfacing of conversation-derived memory without any user-facing consent, notice, or retention limits. In a memory skill, this means sensitive user/project data may be stored and later injected into prompts unexpectedly, creating privacy and data-minimization risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cron setup creates unattended periodic processing of session data and persistent logs, but the skill does not warn users that their session history will be continuously scanned and summarized. This increases the chance of silent long-term retention of sensitive information and reduces meaningful user awareness or consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

The cron configuration establishes automatic recurring session persistence and processing, which turns transient interactions into durable artifacts without any guardrails described in the skill. This increases privacy exposure and can preserve sensitive content in both memory files and operational logs beyond the user's expectations.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

4. 配置 cron

bash
crontab -e
0 10,13,16,19,22 * * * ~/.openclaw/shared/micro-sync.sh >> ~/.openclaw/logs/micro-sync.log 2>&1
0 1 * * * ~/.openclaw/shared/daily-wrapup.sh >> ~/.openclaw/logs/daily-wrapup.log 2>&1
0 3 * * 0 ~/.openclaw/shared/weekly-compound.sh >> ~/.openclaw/logs/weekly-compound.log 2>&1

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs broad retention of user/session content into daily memories and summaries, including architectural decisions, user preference changes, milestones, and key conversations, without clear data-minimization boundaries or user consent language. In a memory-management context this is especially risky because the feature's purpose is persistence, making overcollection and later unintended disclosure more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Micro Sync workflow instructs the system to scan recent sessions, inspect captured memories, write to persistent memory files, and delete portions of HEARTBEAT content, all without a user-facing warning or confirmation model. That combination creates privacy risk from broad session inspection and integrity risk from automated modification/deletion of memory-related artifacts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The backup step preserves MEMORY.md and AGENTS.md snapshots, which can be operationally useful but also extends the lifetime and multiplicity of sensitive stored information. Without retention limits or secure handling guidance, backups can become an additional source of unintended disclosure.

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

Step 2: 备份(铁律)

bash
mkdir -p _backup/$(date +%Y-%m-%d)
cp MEMORY.md AGENTS.md _backup/$(date +%Y-%m-%d)/

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire template is written as prescriptive guidance in Chinese, including mandatory instructions such as '以下内容应加入 workspace 的 AGENTS.md' and repeated '必須' requirements. This imposes a specific language/locale on the skill content without documenting user choice, opt-in, or a justified region-specific need.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script writes a task into HEARTBEAT.md that instructs an agent to create summary files and delete the DAILY_WRAPUP block after completion, but it provides no user-facing notice or consent gate before modifying workspace state. In an agentic environment, indirect file-modification triggers are security-relevant because they can cause autonomous creation and deletion of files based on scheduled execution rather than explicit user approval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script's human-readable comments and the generated HEARTBEAT task content are written in Chinese, with no indication that language choice is configurable or user-selected. This can violate language/locale policy when a skill imposes a specific language on user-visible output without opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The task text explicitly instructs downstream agents or operators to scan recent sessions and persist 'remember X' user content into long-term memory files. That creates a data-governance and privacy risk because sensitive, adversarial, or policy-violating content from prior conversations may be retained without explicit per-item consent, review enforcement, or minimization controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The top-level description is presented in Chinese with some English terms and trigger phrases, but there is no statement that users may choose their preferred language or locale. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language instructions in comments and the generated HEARTBEAT content are written in Chinese, which effectively constrains the skill's operational language. There is no indication that the user can choose another language or that the locale restriction is documented as an explicit, justified requirement.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This shell script appends a new task block to $HOME/.openclaw/workspace/HEARTBEAT.md, which modifies user workspace data. While there is a final echo statement, it appears only after the write and does not disclose the behavior beforehand or ask for confirmation, and the script comments are not user-facing warnings.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.