Back to skill

Security audit

Memory Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local memory organizer, but it needs Review because some scripts can move or rewrite user files with weak path controls and limited warnings.

Install only if you are comfortable with a shell-based memory manager that reads and writes under your OpenClaw workspace. Back up your memory directory first, avoid adding it to an automatic heartbeat until reviewed, do not pass untrusted file paths or names to categorize.sh, and treat snapshots as potentially sensitive because they copy portions of your memory files to disk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
categorize.sh:23
Finding

Unrestricted source and destination paths allow filesystem operations outside the memory workspace

Content
View full analysis
> "$DEST" echo "---" >> "$DEST" echo "# Merged from: $(basename "$SOURCE")" >> "$DEST" echo "# Date: $(date +"%Y-%m-%d %H:%M:%S")" >> "$DEST" echo "" >> "$DEST" cat "$SOURCE" >> "$DEST" echo "✅ Merged into: $DEST" else echo "❌ Cancelled" exit 1 fi else # Move to destination mv "$SOURCE" "$DEST" echo "✅ Categorized as $TYPE: $DEST" fi ``` ### Technical Analysis The script accepts both `NAME` and `SOURCE` directly from command-line arguments. Although shell quoting prevents ordinary shell command injection, the values are not restricted to the intended memory hierarchy. `NAME` is concatenated into a destination path without rejecting path separators or `..` components. A value containing traversal sequences can therefore cause the normalized destination to resolve outside `$MEMORY_DIR/episodic`, `$MEMORY_DIR/semantic`, or `$MEMORY_DIR/procedural`. `SOURCE` is only checked with `-f`. It may consequently identify any regular file accessible to the invoking user, rather than a file within the memor ...[truncated 2189 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Reject names containing `/`, backslashes, traversal components, control characters, or leading option-like values. 3. Canonicalize and validate the source path before using it. Require it to remain beneath an approved directory such as `$MEMORY_DIR/legacy`: ```bash source_real=$(realpath -- "$SOURCE") || exit 1 allowed_real=$(realpath -- "$MEMORY_DIR/legacy") || exit 1 case "$source_real" in "$allowed_real"/*) ;; *) echo "Source must be inside $allowed_real" >&2 exit 1 ;; esac ``` 4. Canonicalize the destination parent and verify that it exactly matches the selected category directory before writing. 5. Reject symbolic-link sources and destinations where symlink behavior is not explicitly required. 6. Use `mv -- "$source_real" "$DEST"` and similar `--` separators for filesystem commands. 7. Avoid appending directly to an existing file. Create a temporary file securely in the destination directory, validate the result, and atomically rename it into place. 8. Add automated tests covering `../`, absolute paths, symbolic links, whitespace, control characters, and sources outside the memory directory. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
init.sh:39
Finding

Automatic initialization silently overwrites existing memory documentation

Content
View full analysis
"$MEMORY_DIR/episodic/README.md" << 'EOF' # Episodic Memory **What happened, when.** Time-based event logs. Chronological context. ## Format File: `YYYY-MM-DD.md` Example: ```markdown # 2026-01-31 ## Launched Memory Manager - Built with semantic/procedural/episodic pattern - Published to clawdhub - 100+ installs goal ## Key decisions - Chose proper architecture over quick ship - Security via clawdhub vs bash heredoc ``` ## When to add - Daily summary of events - Significant moments - Time-sensitive context EOF cat > "$MEMORY_DIR/semantic/README.md" << 'EOF' # Semantic Memory **What I know.** Facts, concepts, knowledge. Distilled learnings. ## Format File: `topic-name.md` Example: ```markdown # Moltbook **What it is:** Social network for AI agents **Key facts:** - 30-min posting rate limit - Validation-driven development - m/agentskills = skill economy hub **Related topics:** [[agent-economy]], [[validation]] ``` ## When to add - Learned something new about a topic - Need to remember facts - Building knowledge base EOF cat > "$MEMORY_DIR/procedural/README.md" << 'EOF' # Procedural Memory **How to do things.** Workflows, patterns, processes you use repeatedly. ## Format File: `process-name.md` Example: ```markdown # Skill Launch Process **When to use:** Launching new agent skill **Steps:** 1. Validate idea (Moltbook poll, 3+ responses) 2. Build MVP (<4 hours) 3. Publish to clawdhub 4. Launch post on m/agentskills 5. 30-min engagement loop 6. 24h feedback check **Related:** [[validation-process]], [[moltbook-posting]] ``` ...[truncated 2740 chars]
Remediation
View remediation
"$MEMORY_DIR/episodic/README.md" <<'EOF' ... EOF fi ``` 2. Apply equivalent existence checks to the semantic and procedural README files. 3. If template refreshes are required, compare the existing file with the new template and require explicit user confirmation before replacement. 4. Back up existing files with a timestamp before any approved overwrite. 5. Do not make a read-oriented check such as `detect.sh` implicitly perform destructive initialization. It should report that setup is incomplete and exit safely, or invoke a non-destructive initialization mode. 6. Determine initialization status from both the state file and existing directory contents rather than treating a missing state file as authoritative. 7. Write new files through securely created temporary files followed by atomic renames to avoid partial templates if execution is interrupted. 8. Add regression tests confirming that repeated initialization and missing-state recovery preserve user-modified README files. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises several advanced memory-management capabilities: compression detection, auto-snapshots, semantic search, and memory usage tracking. The supplied code does none of these. It only validates arguments, checks that a source file exists, chooses a destination path based on a user-supplied category, and then either moves the file or appends its contents to an existing categorized file with interactive confirmation. While the script is loosely related to memory organization, its actual purpose is manual file categorization, which is materially narrower and different from the declared functionality. There are no undeclared sensitive permissions apparent, but the primary purpose and advertised capabilities do not match the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises active memory-management features: compression detection, automatic snapshots, semantic search, and tracking of memory usage patterns. The supplied code chunk does not implement those behaviors. It performs setup only: creating directories, a default state JSON file, and README files. While the created folders and printed next steps suggest a broader memory-management system may exist elsewhere, this chunk itself does not carry out the key advertised capabilities. Therefore the description materially overstates what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description promises proactive memory-management features such as compression-risk detection, automatic snapshotting, semantic search, and usage tracking. This code chunk does none of those things. Instead, it performs filesystem reorganization of markdown memory files: detecting flat files, moving date-named files into an episodic directory, copying other files into a legacy folder for manual categorization, and recording a last_organize timestamp in a state file. While this is broadly related to memory storage hygiene, its primary purpose is migration/organization rather than the advertised capabilities, so the description does not accurately represent the behavior of this code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a broader memory-management skill with multiple capabilities: compression detection, automatic snapshotting, semantic search, and usage tracking. The supplied code chunk only implements local text search using grep across markdown files under memory subdirectories. It supports searching semantic, episodic, procedural, and snapshot content, so it partially aligns with the 'search historical memories' aspect. However, it does not detect compression risk, create or manage snapshots, or analyze memory usage patterns. Because the declared purpose emphasizes several major capabilities absent from the code, the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to run a migration script that moves existing memory/*.md files into a new structure, but it does not warn that this operation modifies user data or recommend backup/review steps first. For a memory-management skill, silent or poorly explained data reorganization can lead to accidental data loss, broken workflows, or user confusion if filenames, locations, or links change unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase 'Use when agents need...' describes broad situations like detecting compression risk, saving snapshots, searching memories, or tracking usage patterns, but it does not define specific invocation triggers or exclusions. In a markdown skill description, this ambiguity can cause the skill to be selected for many generic memory-related requests beyond its intended scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a memory-management skill focused on detecting compression risk, saving snapshots, semantic search, and tracking usage patterns. This script instead implements a manual organizer that relocates or appends files into type-specific folders, which is a materially different behavior from the stated feature set.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script uses mv on the supplied source file, which removes it from its original location without an explicit destructive-operation warning or confirmation in the non-merge path. In a memory-management context, that can unexpectedly disrupt other tools or workflows that still reference the original file, causing apparent data loss or broken context tracking.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script creates a persistent snapshot file and copies recent episodic, semantic, and procedural memory contents into it without any consent prompt, sensitivity warning, retention control, or permission hardening. In this skill context, those memory files are likely to contain user prompts, agent context, secrets, or other sensitive operational data, so silently duplicating them to disk increases exposure and makes later compromise or unintended disclosure more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script updates the memory manager state by rewriting .memory-manager-state.json via a temporary file and mv, but there is no user-facing disclosure before this write occurs. The surrounding output describes memory status only after the operation, so users are not warned that running the detector changes on-disk state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs persistent filesystem modifications by creating directories and writing several files under the workspace path. While it does print progress messages, those messages occur as part of execution and do not clearly warn the user in advance that the script will create and populate files in their home/workspace area.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The jq command rewrites the JSON state file by updating the last snapshot timestamp and incrementing warnings. While the script logs snapshot creation, it does not tell the user that an internal state file will also be changed, so the file-write side effect is not clearly disclosed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.