Back to skill

Security audit

Agent Notebook

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate memory skill, but its persistent logging and scheduled-task setup are broad enough, and contain enough security weaknesses, that users should review it carefully before installing.

Install only if you want a workspace-local long-term memory system and are comfortable with persistent files being read in future sessions. Avoid storing secrets, personal data, customer data, or API key locations in MEMORY.md or daily notes. Do not enable cron or scheduled tasks until the command-injection path, Windows privilege requirement, and inbox review/approval model are fixed or manually constrained.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
scripts/heartbeat-check.sh:47
Finding

Unauthenticated Cross-Session Content Can Poison Persistent Agent Memory

Content
View full analysis
> "$TODAY_FILE" echo "## $(date '+%H:%M') -- Cron Inbox Processing" >> "$TODAY_FILE" # Copy FULL entries (header + body), not just headers # Extract everything from each ## [ line to the next ## [ or EOF awk ' /^## \[/ { if (buffer != "") { print buffer print "" } buffer = $0 next } buffer != "" { buffer = buffer "\n" $0 } END { if (buffer != "") print buffer } ' "$INBOX_FILE" >> "$TODAY_FILE" log "Appended inbox entries to daily notes" # Clear inbox (keep header) HEADER="# Cron Inbox\n\nCross-session message bus.\n\n---\n\n*Last processed: $(date '+%Y-%m-%d %H:%M')*\n" printf "%b" "$HEADER" > "$INBOX_FILE" log "Cleared cron inbox" else log "Inbox is empty" fi ``` The subsequent promotion into long-term memory occurs in `scripts/memory-extract.sh:50-92`: ```bash SIGNIFICANCE_KEYWORDS="decided|decision|lesson learned|important|breakthrough|milestone|completed|shipped|launched|fixed|solved|agreed|confirmed|approved|rejected|failed|error|new project|started|created|deployed|published" # Find entries (lines starting with ## HH:MM) ENTRIES=$(grep -n "^## [0-9]\{2\}:[0-9]\{2\} --" "$TODAY_FILE" || true) ...[truncated 3445 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup-cron.sh:35
Finding

Workspace Argument Injection Can Install Arbitrary Persistent Cron Commands

Content
View full analysis
> "$TEMP_CRON" << EOF # --- OpenClaw Memory System Cron Jobs --- # Nightly memory extraction (23:00 daily) 0 23 * * * cd "$WORKSPACE" && "$SKILL_ROOT/scripts/memory-extract.sh" "$WORKSPACE" >> "$WORKSPACE/memory/cron.log" 2>&1 # Daily notes reminder (09:00 daily) 0 9 * * * cd "$WORKSPACE" && echo "## $(date '+\%H:\%M') -- Daily Notes Reminder" >> "$WORKSPACE/memory/$(date '+\%Y-\%m-\%d').md" 2>> /dev/null # Heartbeat check (every 30 minutes) */30 * * * * cd "$WORKSPACE" && "$SKILL_ROOT/scripts/heartbeat-check.sh" "$WORKSPACE" >> "$WORKSPACE/memory/cron.log" 2>&1 # --- End OpenClaw Memory System --- EOF # Install crontab crontab "$TEMP_CRON" ``` ### Technical Analysis The caller-controlled workspace argument is inserted directly into a heredoc that becomes executable crontab content. The script does not canonicalize the argument, reject control characters, prevent embedded newlines, or encode it for safe use in a cron shell command. Surrounding the value with double quotes is insufficient because a malicious value can contain a double quote followed by shell metacharacters. A newline can also inject an entirely separate cron record. The resulting payload is not executed only during setup; it is installed into the user's crontab and can execute repeatedly. This is a command-injection vulnerability with a persistence consequence. The vulnerable setup script operates under the invoking user's account and does not itself request `sudo`, so the injected cron command normally inherits that user's privileges. ### Attack Path 1. An attacker controls or influences the workspace argument supplied to `setup-cron.sh`. ...[truncated 976 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/setup-cron.ps1:22
Finding

Windows Scheduled-Task Setup Violates Least Privilege and Bypasses PowerShell Policy

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly promotes persistent storage of session history and nightly extraction into durable memory, but it does not provide concrete privacy, consent, retention, minimization, or deletion guidance. In a memory skill, this creates a real risk that sensitive user prompts, credentials, personal data, or confidential workspace content will be retained longer than intended and resurfaced in future sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Describing daily notes as 'raw logs of every session' encourages indiscriminate capture of all interaction content without sensitivity boundaries. In the context of an agent memory system, that makes the skill more dangerous because its core purpose is long-term retention, so over-collection is likely and potentially systemic rather than incidental.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These sections instruct the agent to write broad session content to daily notes, process cross-session messages, extract notable material into MEMORY.md, and reload that state in later sessions. That is a genuine natural-language persistence mechanism which can propagate sensitive information across time and contexts, increasing the chance of unintended disclosure, prompt-data retention, and cross-session leakage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description is broad enough to trigger on many ordinary memory- or setup-related conversations, which can cause the agent to invoke installation and persistence behavior without sufficiently specific user intent. In this skill, unintended invocation is more concerning because the prescribed actions include creating files, seeding persistent memory, and potentially configuring automation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list uses ambiguous conditions such as mentions of MEMORY.md, daily notes, or agent forgetting, without scope limits that distinguish casual discussion from a request to modify a workspace. Because this skill leads to filesystem writes and optional cron configuration, accidental activation could produce unexpected persistent changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions direct the agent to run installer scripts, create and seed files with operator context, and configure cron jobs, but they do not require a prominent warning and explicit consent for those system changes. In a security-sensitive context, this is dangerous because it normalizes persistent filesystem modification and scheduled task creation, both of which can affect privacy, system state, and future automated behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
- `MEMORY.md` may contain operator-specific info — only load in trusted (direct) sessions
- Skip MEMORY.md in group chats or shared contexts
- Never share operator personal details externally without approval
- Keep private info private

## Customization

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The heartbeat routine expands beyond persistent-memory maintenance into recurring checks of email, calendar, and social notifications. That creates unnecessary privilege scope and ongoing access to external services unrelated to the skill’s stated purpose, increasing the risk of unauthorized data collection, privacy exposure, and misuse if the agent is invoked in a broad or unattended context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · examples/AGENTS.md (reported line 45)May include surrounding context.

md
## Safety

- Don't exfiltrate private data. Ever.
- Don't run destructive commands without asking.
- When in doubt, ask.

## Prompt Injection Defense

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 19)May include surrounding context.

sh
info "Workspace: $WORKSPACE"

# Check if crontab is available
if ! command -v crontab &> /dev/null; then
    echo "Error: crontab not found. Please install cron."
    exit 1
fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This script reads and later modifies the user's crontab to install recurring jobs, which is a real persistence mechanism. In context it appears intended for legitimate automation, but persistence is still security-relevant because it causes code to run repeatedly in the user's environment and could be abused if the workspace or referenced scripts are later tampered with.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 26)May include surrounding context.

sh
# Create temporary crontab file
TEMP_CRON=$(mktemp)
crontab -l > "$TEMP_CRON" 2> /dev/null || true

# Check if already configured
if grep -q "OpenClaw Memory System" "$TEMP_CRON"; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 63)May include surrounding context.

sh
echo "  - Daily notes reminder at 09:00"
echo "  - Heartbeat check every 30 minutes"
echo ""
echo "View with: crontab -l"
echo "Logs go to: $WORKSPACE/memory/cron.log"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to run the routine periodically every 30–60 minutes or on session start is broad enough to encourage automatic invocation outside a narrowly defined trigger. In an agent setting, this can create unintended repeated access to files and configured services, especially when paired with stateful memory and inbox-processing behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The cron inbox processing step tells the agent to write notable entries to daily notes, update MEMORY.md, and clear processed entries, which are state-changing operations including deletion-like behavior. Without a user-facing warning or confirmation model, this can silently alter persistent records and remove audit context from the inbox.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The heartbeat instructs the agent to perform recurring checks of external services such as email, calendar, weather, and social notifications, which expands the skill from memory maintenance into autonomous monitoring. This increases data-access scope, can trigger actions without fresh user intent, and may expose sensitive external account data on a standing basis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The service-check section contemplates ongoing access to external services and notifications but does not warn users that enabling heartbeat routines may repeatedly query connected accounts. That omission creates a transparency and consent problem, particularly because repeated background access can reveal sensitive personal data and expand the operational scope beyond memory persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template explicitly suggests storing sensitive operational details such as 'API keys location' in long-term memory without a nearby warning to avoid secrets, minimize sensitive data, or use a secure secret manager. In a persistent memory system, this increases the chance that credentials or credential-adjacent information are retained, surfaced in later sessions, or exposed through accidental sharing, logs, backups, or prompt/context leakage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template explicitly instructs the agent to clear processed inbox entries after reading them, but it does not require archival, verification, or recovery safeguards before deletion. In a persistent-memory workflow, this can cause silent loss of audit trail, task context, or sub-agent outputs if processing is incomplete, mistaken, or corrupted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script deletes temporary workspaces with 'rm -rf' at L212 and L226. Although this is part of test cleanup, the file itself provides no explicit warning near execution or deletion that it will remove directories it created, and there is no confirmation prompt.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.