T09 · Insecure Skill Coding Practices
- Location
SKILL.md:115- Finding
Unfiltered Conversation and Memory Data Disclosure to a Third-Party API
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real memory skill, but it recommends broad automatic persistence and third-party processing of conversation data without enough user-facing controls.
Review this carefully before installing. Use it only if you want an agent to keep durable memory, and avoid enabling SkillBoss chat, embedding, or cloud backup for sensitive projects unless you understand exactly what conversation content may leave your machine. Prefer pinned installs, do not store API keys in shell startup files unless necessary, and review or clear saved memory regularly.
SKILL.md:115Unfiltered Conversation and Memory Data Disclosure to a Third-Party API
The code’s actual behavior is much narrower than the description. It creates and inspects markdown files and directories for a lightweight local memory workflow. Although it mentions LanceDB in output and checks whether a LanceDB directory exists, it does not implement vector search or database operations. There is no WAL logic, git-notes interaction, cloud sync/backup, or assistant integration shown in this chunk. Therefore the declared description materially overstates the implemented capabilities and primary purpose.
The cloud backup and auto-extraction sections describe external storage and API processing without a clear warning that conversation data may leave the local environment. This is especially risky in an agent memory skill because users may assume storage is local and bounded.
The command rm -rf ~/.openclaw/memory/lancedb/ irreversibly deletes stored vector memory and is presented as a maintenance action. In agent-assisted contexts, destructive shell snippets are risky because they may be copied or executed automatically without adequate user review.
memory_recall query="*" limit=50
# Clear all vectors (nuclear option)
rm -rf ~/.openclaw/memory/lancedb/
openclaw gateway restart
# Export Git-Notes
The command rm -rf ~/.openclaw/memory/lancedb/ irreversibly deletes stored vector memory and is presented as a maintenance action. In agent-assisted contexts, destructive shell snippets are risky because they may be copied or executed automatically without adequate user review.
memory_recall query="*" limit=50
# Clear all vectors (nuclear option)
rm -rf ~/.openclaw/memory/lancedb/
openclaw gateway restart
# Export Git-Notes
Using npx elite-longterm-memory without pinning a specific version causes users to execute whatever package version is current at install time. For an agent skill that is intended to be run directly in a workspace, a compromised maintainer account, typo-squatted package replacement, or malicious future release could lead to arbitrary code execution on the user's machine.
This command again instructs users to execute an unpinned package via npx, which delegates trust to the latest published artifact. In practice this creates a supply-chain execution path where any malicious or vulnerable new release is immediately pulled and run in local development environments.
The today example has the same unpinned npx risk: it encourages immediate execution of a mutable remote package in a context with filesystem access. Because this skill is explicitly marketed for persistent memory and workspace integration, exploitation could affect source code, local secrets, or stored conversation history.
The README promotes automatic fact extraction and optional cloud sync of conversation-derived memory but does not prominently warn that chat content and derived facts may be transmitted to a third-party service. In a long-term memory skill, users may store sensitive prompts, source code, credentials, business decisions, or personal data, so silent or underexplained external transmission creates meaningful confidentiality and compliance risk.
The README contains code that posts data to https://api.heybossai.com/v1, which is expected functionality for a cloud-backed memory feature, but it still represents external transmission of potentially sensitive conversation data. In the context of an agent memory system, the transmitted payload can include messages, extracted facts, and semantic queries, increasing privacy, data governance, and prompt confidentiality concerns if users are not fully informed.
const API_KEY = process.env.SKILLBOSS_API_KEY
const API_BASE = 'https://api.heybossai.com/v1'
async function pilot(body) {
const r = await fetch(`${API_BASE}/pilot`, {
The skill requests access to an environment variable (SKILLBOSS_API_KEY) but does not declare an explicit tool scope or allowed-tools boundary. In agent ecosystems, missing scope declarations can cause overly broad execution or ambiguous trust assumptions, especially when the skill also documents external network use.
The 'write before responding' rule establishes default persistence of user input into session state, which is a form of session retention with privacy implications. In context, the danger is higher because the rule is universal and not limited to non-sensitive task metadata.
**Rule:** Write BEFORE responding. Triggered by user input, not agent memory.
### Layer 2: WARM STORE (LanceDB Vectors)
**From: lancedb-memory**
The WAL rule tells the agent to save user-provided details before responding, but the skill provides no user-facing privacy notice or consent mechanism. This creates implicit collection of potentially sensitive information simply through normal conversation flow.
The documented fetch call targets an external API endpoint, creating a path for data exfiltration from local conversation or memory content to a third party. In a memory skill, external transmission is materially security-relevant because the data is likely to include accumulated context rather than isolated inputs.
const API_KEY = process.env.SKILLBOSS_API_KEY
const API_BASE = 'https://api.heybossai.com/v1'
async function pilot(body) {
const r = await fetch(`${API_BASE}/pilot`, {
The skill recommends sending conversation content to an external chat/embedding API for automatic fact extraction, which can expose sensitive user data outside the local memory system. Because the examples encourage broad extraction of facts, preferences, and decisions, users may unknowingly transmit private or proprietary context to a third party.
This section directs the system to broadly extract, deduplicate, embed, and retain conversation-derived facts across multiple memory layers, including optional cloud-backed services. Such broad persistence increases privacy risk and the chance of storing sensitive, regulated, or proprietary content without adequate minimization.
This is another external API transmission point for conversation-derived content used in auto-extraction. Repeated network integration amplifies the privacy and confidentiality risk because it normalizes sending memory-related data off-device.
const API_KEY = process.env.SKILLBOSS_API_KEY
const API_BASE = 'https://api.heybossai.com/v1'
async function pilot(body) {
const r = await fetch(`${API_BASE}/pilot`, {
Persisting SKILLBOSS_API_KEY in shell startup files increases the exposure window of a sensitive credential and may cause it to be inherited by unrelated processes. In shared or compromised environments, that broadens the blast radius if the key is leaked.
export SKILLBOSS_API_KEY="your-key"
# Add to ~/.zshrc for persistence
The agent instructions require immediate persistence of user details before responding and include storing preferences and decisions as a standard workflow. In context, this creates a broad, default surveillance-style memory pattern rather than selective, user-approved storage.
The example workflow shows a user preference and project decision being copied into multiple persistence layers, including long-term stores. This increases over-collection risk and makes accidental retention or later disclosure more likely.
User: "Let's use Tailwind for this project, not vanilla CSS"
Agent (internal):
1. Write to SESSION-STATE.md: "Decision: Use Tailwind, not vanilla CSS"
2. Store in Git-Notes: decision about CSS framework
3. memory_store: "User prefers Tailwind over vanilla CSS" importance=0.9
4. THEN respond: "Got it — Tailwind it is..."
The maintenance section includes a destructive rm -rf command to wipe vector memory, but the guide does not provide a strong warning about irreversible data loss. Users or agents could execute it casually and destroy stored memory unintentionally.
The later example again uses the same external API, reinforcing that off-platform transmission is part of the recommended design. While not inherently malicious, it becomes dangerous when paired with broad memory capture and absent disclosure.
const API_KEY = process.env.SKILLBOSS_API_KEY
const API_BASE = 'https://api.heybossai.com/v1'
async function pilot(body) {
const r = await fetch(`${API_BASE}/pilot`, {
The help text instructs users to run the package via npx elite-longterm-memory without pinning an exact version. npx resolves and executes whatever version is current at runtime, which creates a supply-chain risk if a future release is compromised, typosquatted, or unexpectedly changed. In a developer tool that manages persistent memory and may be run in project directories, this is more dangerous because it can execute with access to local files and developer context.
This second help example also recommends invoking the package through unpinned npx, carrying the same risk of executing an unreviewed future package version. Because this skill is positioned as an agent memory system for tools like Cursor, Claude, ChatGPT, and Copilot, users may run it in sensitive repositories, increasing the blast radius of a compromised package.
The instruction to store decisions 'silently' encourages persistence of user-derived data without informing the user. Silent retention weakens informed consent and can cause sensitive project or personal preferences to be recorded unexpectedly.
The optional dependency mem0ai is specified with a caret range (^1.0.0), allowing newer minor and patch releases to be installed without review. This creates supply-chain risk because a compromised or malicious upstream release could be pulled in automatically, and in the context of an AI memory skill that may handle sensitive context and cloud-backed storage, a dependency compromise could expose stored data or execute unwanted code during installation or runtime.
"typescript"
],
"optionalDependencies": {
"mem0ai": "^1.0.0"
},
"author": "NextFrontierBuilds",
"license": "MIT",
Detected: suspicious.destructive_delete_command