Back to skill

Security audit

Three Layer Memory + LanceDB Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed memory-automation system, but it sets up recurring jobs that can scan conversations and persist or change agent memory without enough user review controls.

Install only if you intentionally want recurring local automation that reviews conversation history and writes long-term agent memory. Before enabling cron or autoCapture/autoRecall, pin and verify the memory plugin, restrict file permissions, add review/approval before memory or guidance-file changes, define retention and deletion rules, and avoid storing secrets or sensitive personal data in captured summaries.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T06 · System Persistence

Error
Location
SKILL.md:82
Finding

Persistent Scheduled Execution Through User Crontab

Content
View full analysis
> ~/.openclaw/logs/micro-sync.log 2>&1 0 1 * * * ~/.openclaw/shared/daily-wrapup.sh >> ~/.openclaw/logs/daily-wrapup.log 2>&1 0 3 * * 0 ~/.openclaw/shared/weekly-compound.sh >> ~/.openclaw/logs/weekly-compound.log 2>&1 ``` ### Technical Analysis The installation procedure copies executable scripts into the user's persistent OpenClaw directory and instructs the user to register three recurring cron jobs. These jobs survive the installation session and repeatedly modify the Agent's heartbeat state. Scheduled execution is related to the declared automatic memory-maintenance functionality. However, it exceeds the privileges required for on-demand memory management and creates an enduring execution channel. The scripts are executed with the permissions of the user who owns the crontab. The cron commands execute mutable files under `~/.openclaw/shared/` without integrity verification. If another process, compromised Skill, or account actor can modify those files after installation, the next scheduled invocation will execute the replacement content with the user's permissions. ### Attack Path 1. The user follows the installation instructions and copies the scripts into `~/.openclaw/shared/`. 2. The user grants execute permission to all shell scripts in that directory through the wildcard command. 3. The user registers the three cron entries. 4. The jobs continue executing across sessions at their configured intervals. 5. An actor capable of modifying a scheduled script can replace or append shell commands to it. 6. Cron sub ...[truncated 570 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
scripts/micro-sync.sh:17
Finding

Untrusted Session Content Can Be Promoted Into Persistent Agent Memory

Content
View full analysis
> "$HEARTBEAT" << EOF # MICRO_SYNC @ $TIMESTAMP - [ ] 掃描最近 3 小時的 session(用 sessions_list + sessions_history) - [ ] 只記錄:確定的決策、新規則、架構變更、明確的「記住 XXX」指令 - [ ] 不記錄:日常問答、閒聊、懸而未決的討論 - [ ] 去重:memory_recall 查重,相似 >70% 則 memory_update 不新建 - [ ] Scope:按內容分配 agent:finance/content/ecommerce/tech,跨 agent 用 global - [ ] 格式:原因→發現→結論 - [ ] 寫入 memory/$(date '+%Y-%m-%d').md(APPEND,不覆蓋) - [ ] LanceDB 審核:檢查 autoCapture 最近抓的記憶,刪除明顯的垃圾/閒聊 - [ ] 完成後刪除此 MICRO_SYNC 段落 EOF ``` The instructions direct the Agent to scan recent sessions, retain explicit “remember” requests and new rules, and append the resulting material to persistent memory. ### Technical Analysis Conversation content is an untrusted input boundary. The workflow explicitly treats session statements framed as decisions, rules, architectural changes, or “remember” requests as eligible for long-term persistence. The duplicate check only determines whether similar content already exists. Scope classification controls where the content is stored but does not establish its trustworthiness. Neither control prevents malicious behavioral instructions from being persisted. Because the memory system also enables automatic recall, poisoned content can later be injected into unrelated sessions. This converts a single-session prompt-injection attempt into a cross-session influence mechanism. ### Attack Path 1. An attacker or untrusted participant places a message in an accessible session that is phrased as a new rule, architectural decision, or explicit request to remember an instruction. 2. The scheduled Micro Sync script appends a task to `HEARTBEAT.md`. 3. The Agent follows that task and scans recent session histories. 4. The malicious statement passes the content-type filter because it resembles an eligible memory item. 5. Deduplic ...[truncated 899 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/weekly-compound.sh:16
Finding

Scheduled Workflow Requests Broad Conversation Access and Modification of Control Files

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:56
Finding

Unpinned Third-Party Memory Dependency Receives Automatic Capture and Recall Access

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description promises a fairly comprehensive memory-management system with LanceDB Pro integration, automatic multi-tier memory handling, and several maintenance workflows. This code chunk, however, is only a weekly shell script that writes a task/checklist into HEARTBEAT.md and creates an archive directory. It records intended steps such as backing up MEMORY.md, comparing memory sources, distilling content, archiving stale items, and possibly updating SYSTEM_GUIDE.md, but it does not actually carry out those operations. The primary behavior is therefore much narrower and more administrative than the declared purpose. Because the declared purpose emphasizes substantial implemented capabilities—especially LanceDB/vector functionality, automated memory management, deduplication, and scope isolation—that are absent from the supplied code, this is a material description/behavior mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like '记忆系统', 'memory system', and 'lancedb', which can easily appear in normal conversation and unintentionally activate the skill. In a memory/persistence skill, accidental activation is more dangerous because it can lead to unwanted setup guidance, data capture workflows, or persistence-related actions without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description omits a clear warning that the skill is designed to enable automatic capture, scheduled scanning of session data, and modification of memory files via cron jobs and plugin configuration. In this context, the lack of upfront disclosure can cause users to enable persistent collection and summarization of conversation content without understanding the privacy and retention implications.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Creating persistent directories for memory archives and summaries is part of a stateful storage design and therefore constitutes real session persistence risk. While directory creation alone is not malicious, in this skill's context it supports long-term retention of user-derived content, making privacy and data minimization concerns more significant.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

1. 创建目录结构

bash
mkdir -p ~/.openclaw/workspace/memory/archive
mkdir -p ~/.openclaw/workspace/second-brain/summaries

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Creating persistent directories for memory archives and summaries is part of a stateful storage design and therefore constitutes real session persistence risk. While directory creation alone is not malicious, in this skill's context it supports long-term retention of user-derived content, making privacy and data minimization concerns more significant.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

1. 创建目录结构

bash
mkdir -p ~/.openclaw/workspace/memory/archive
mkdir -p ~/.openclaw/workspace/second-brain/summaries

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

The cron configuration establishes recurring automated processing of session content, which is a true persistence mechanism rather than a one-time local note-taking action. In a memory-management skill, scheduled background jobs materially increase risk because they can continue collecting, transforming, and retaining user-derived data without ongoing awareness.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

4. 配置 cron

bash
crontab -e
0 10,13,16,19,22 * * * ~/.openclaw/shared/micro-sync.sh >> ~/.openclaw/logs/micro-sync.log 2>&1
0 1 * * * ~/.openclaw/shared/daily-wrapup.sh >> ~/.openclaw/logs/daily-wrapup.log 2>&1
0 3 * * 0 ~/.openclaw/shared/weekly-compound.sh >> ~/.openclaw/logs/weekly-compound.log 2>&1

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions direct the system to persist, summarize, and structure user/session content across conversations, including decisions, key conversations, and pending items. This creates privacy and cross-session data handling risk, especially if sensitive information is captured into long-lived markdown files or vector memory without explicit consent and review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire template is written as a prescriptive ruleset in Chinese, including mandatory instructions such as '以下内容应加入 workspace 的 AGENTS.md' and repeated '必須' requirements, but it provides no language-choice or opt-in mechanism. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable locale-policy issue unless the constraint is explicitly justified, which it is not here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script appends operational instructions into HEARTBEAT.md, a workspace file explicitly used to trigger downstream agent execution. This creates an indirect prompt-injection/control channel: anyone who can run or schedule the script can cause the agent to perform file reads/writes and memory-management actions without an explicit interactive approval step, and the script provides no warning, validation, or containment around that trigger.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script's natural-language content is written entirely in Traditional Chinese, including operational comments and the task block appended to HEARTBEAT.md, with no indication that language selection is configurable or intentionally region-specific. This can violate language or locale policy where skills must not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script instructs an agent to scan recent sessions and persist user decisions, rules, and explicit 'remember X' directives into long-term memory files. That creates a real data retention risk: sensitive information, internal decisions, or personal data from prior sessions may be stored beyond the user's immediate expectation, increasing exposure through later retrieval, cross-context reuse, or compromise of the memory store.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language instructions and headings are written entirely in Chinese and imply the skill operates in that locale by default. There is no indication that users can opt into another language or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs a file write to the user's HEARTBEAT.md via shell redirection, but there is no confirmation prompt or prior warning comment explaining that the script modifies a persistent workspace file. The final echo only reports completion after the write and does not disclose the action before it occurs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.