Back to skill

Security audit

ClawMem Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed persistent-memory system, but it also sets up recurring background jobs and can promote untrusted inbox content into long-term agent memory without enough scoping or review.

Install only in a private, trusted workspace. Do not store secrets, tokens, API keys, secret locations, regulated data, or confidential third-party information in MEMORY.md, daily notes, or cron-inbox.md. Treat cron inbox entries as untrusted notes, review MEMORY.md before future sessions rely on it, and avoid enabling cron or Windows scheduled tasks unless you understand and accept the recurring background behavior; on Windows, avoid running the scheduler setup as Administrator unless the package is fixed to use least privilege.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
scripts/heartbeat-check.sh:47
Finding

Untrusted cross-session messages can be promoted into authoritative long-term agent memory

Content
View full analysis
> "$TODAY_FILE" echo "## $(date '+%H:%M') -- Cron Inbox Processing" >> "$TODAY_FILE" # Copy FULL entries (header + body), not just headers # Extract everything from each ## [ line to the next ## [ or EOF awk ' /^## \[/ { if (buffer != "") { print buffer print "" } buffer = $0 next } buffer != ...[truncated 4609 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/setup-cron.ps1:20
Finding

Windows scheduled-task setup requires administrator privileges beyond the declared need

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup-cron.sh:8
Finding

Caller-controlled workspace paths are embedded into persistent command strings

Content
View full analysis
/dev/null; then echo "Error: crontab not found. Please install cron." exit 1 fi # Create temporary crontab file TEMP_CRON=$(mktemp) crontab -l > "$TEMP_CRON" 2> /dev/null || true # Check if already configured if grep -q "OpenClaw Memory System" "$TEMP_CRON"; then warn "OpenClaw Memory System cron jobs already configured." warn "Remove existing entries and re-run to update." rm "$TEMP_CRON" exit 0 fi # Add cron jobs cat >> "$TEMP_CRON" << EOF # --- OpenClaw Memory System Cron Jobs --- # Nightly memory extraction (23:00 daily) 0 23 * * * cd "$WORKSPACE" && "$SKILL_ROOT/scripts/memory-extract.sh" "$WORKSPACE" >> "$WORKSPACE/memory/cron.log" 2>&1 # Daily notes reminder (09:00 daily) 0 9 * * * cd "$WORKSPACE" && echo "## $(date '+\%H:\%M') -- Daily Notes Reminder" >> "$WORKSPACE/memory/$(date '+\%Y-\%m-\%d').md" 2>> /dev/null # Heartbeat check (every 30 minutes) */30 * * * * cd "$WORKSPACE" && "$SKILL_ROOT/scripts/heartbeat-check.sh" "$WORKSPACE" >> "$WORKSPACE/memory/cron.log" 2>&1 # --- End OpenClaw Memory System --- EOF # Install crontab crontab "$TEMP_CRON" ``` `scripts/setup-cron.ps1:40-64`: ```powershell $NightlyAction = New-ScheduledTaskAction -Execute "powershell.exe" -Argument "-ExecutionPolicy Bypass -File `"$SkillRoot\scripts\memory-extract.ps1`" -Workspac ...[truncated 4515 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README promotes persistent daily logs and automated extraction into long-term memory, but the privacy warning is limited and appears later, after setup and usage guidance. This creates a real risk that users or agents will store sensitive session content by default without clear upfront constraints on secrets, personal data, or retention.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The architecture advertises raw logs of every session plus nightly promotion into durable memory, which creates a semantic retention pipeline for potentially sensitive information. Even without executable code, this documentation encourages a design that can accumulate and propagate confidential data across time, increasing leakage, over-collection, and misuse risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These sections explicitly instruct broad persistence and replay of prior session context across runs, including raw notes and cross-session messages. In a memory skill, that context fit makes the behavior intentional, but it is still dangerous because it can normalize retention of sensitive user content and cause later sessions or sub-agents to access information that should not persist.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description uses very broad activation criteria such as any mention of persistent memory, daily notes, cron inbox, heartbeat routines, agent identity, or setting up a new workspace. This can cause the skill to trigger in conversations that are merely informational, leading an agent to propose or perform filesystem changes and persistence setup in contexts where the user did not clearly request it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list lacks specificity and contains no guardrails or negative examples, so ordinary phrases like "my agent forgets everything" or mentions of MEMORY.md could invoke the skill even when the user only wants advice. In this skill, unintended invocation is more dangerous because the instructions immediately steer the agent toward executing installer scripts and configuring scheduled tasks in the user's workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installation section instructs the agent to run installer scripts, create persistent files, seed long-term memory with operator context, and optionally configure cron jobs, but it does not prominently warn that these actions modify the workspace and create automated background behavior. Because the skill also encourages storing personal and project context, users may unknowingly persist sensitive data and enable recurring jobs without fully informed consent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
- `MEMORY.md` may contain operator-specific info — only load in trusted (direct) sessions
- Skip MEMORY.md in group chats or shared contexts
- Never share operator personal details externally without approval
- Keep private info private

## Customization

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The routine explicitly instructs the agent to clear processed entries from memory/cron-inbox.md, which is a state-changing and potentially destructive action, but it provides no user warning, approval gate, or retention policy. In a persistent-memory skill, silent deletion is especially risky because it can remove auditability, erase user-provided context, or cause irreversible loss if entries were misprocessed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The nightly routine directs the agent to extract facts from daily notes, append them to MEMORY.md, and mark notes as extracted, all without any notice that persistent long-term memory will be altered automatically. In this skill's context, that increases the risk of silently storing sensitive, incorrect, or over-retained information across sessions, making privacy and integrity issues more likely.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · examples/AGENTS.md (reported line 45)May include surrounding context.

md
## Safety

- Don't exfiltrate private data. Ever.
- Don't run destructive commands without asking.
- When in doubt, ask.

## Prompt Injection Defense

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This shell script creates and modifies workspace files such as MEMORY.md and later appends extracted content to both MEMORY.md and the daily notes file. Although it emits operational log messages, there is no explicit warning or confirmation that running the script will permanently change user data in the workspace.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a memory system for persistence across sessions and mentions configuring memory extraction crons, but this script escalates to requiring Administrator rights and installs Windows Scheduled Tasks at the system level. That level of privileged system configuration is not clearly justified by the manifest's user-facing memory purpose, especially since the tasks themselves appear workspace-oriented.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 19)May include surrounding context.

sh
info "Workspace: $WORKSPACE"

# Check if crontab is available
if ! command -v crontab &> /dev/null; then
    echo "Error: crontab not found. Please install cron."
    exit 1
fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

This script reads and later updates the user's crontab to install recurring jobs, which is a real persistence mechanism. In the context of an agent skill, automatically adding scheduled execution increases risk because it causes code to run repeatedly outside the user's immediate session and may continue operating on workspace data indefinitely.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 26)May include surrounding context.

sh
# Create temporary crontab file
TEMP_CRON=$(mktemp)
crontab -l > "$TEMP_CRON" 2> /dev/null || true

# Check if already configured
if grep -q "OpenClaw Memory System" "$TEMP_CRON"; then

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/setup-cron.sh (reported line 63)May include surrounding context.

sh
echo "  - Daily notes reminder at 09:00"
echo "  - Heartbeat check every 30 minutes"
echo ""
echo "View with: crontab -l"
echo "Logs go to: $WORKSPACE/memory/cron.log"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The routine instructs the agent to run periodically every 30–60 minutes or on session start, which is broad enough to trigger autonomous actions without a fresh user request. In a memory-management skill, that can lead to repeated reads and writes across persistent files, increasing the chance of unintended data retention, modification, or action chaining from stale instructions in memory artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cron inbox processing step tells the agent to write to daily notes, update MEMORY.md, and clear processed entries, but it does not warn the user that persistent files will be modified or deleted. In this skill's context, that is more dangerous because the entire purpose is cross-session persistence, so silent mutation of memory files can cause data loss, privacy issues, or durable corruption of agent state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template explicitly suggests storing sensitive operational details such as 'API keys location' in long-term memory. In a persistent memory system, this increases the chance that secrets or secret-adjacent information are retained longer than necessary, surfaced in later sessions, or exposed through prompt leakage, workspace sharing, backups, or indexing. The note to avoid group chats helps somewhat, but it does not warn users not to store secrets and may create false confidence that local placement alone is sufficient.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file instructs the skill to write notable events to daily notes, MEMORY.md, and memory/YYYY-MM-DD.md, then clear processed entries from the inbox. Those actions affect user data and can remove information, but the description provides no warning about these modifications or deletions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This is a markdown file, so SQP-2 applies to omissions in descriptions of behaviors that could affect privacy or system integrity. The notes state that a Stripe account was created and API keys were obtained and used for checkout testing, but there is no accompanying warning or caution about handling credentials or payment-related operations safely.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The service-check section allows open-ended periodic monitoring such as email, calendar, weather, social media, and 'any other periodic monitoring' without specifying exact boundaries. This creates scope for the agent to access external systems or sensitive accounts more broadly than necessary, especially when combined with recurring heartbeat execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.