Back to skill

Security audit

Openclaw Sulcus Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent memory skill with clearly disclosed local and cloud modes, but users should be careful before enabling automatic cloud capture because conversation-derived memory and recall data can be persisted remotely.

Install only if you trust the openclaw-sulcus plugin and the Sulcus server you configure. Prefer local-only mode for sensitive work, keep autoCapture and captureFromAssistant disabled unless you explicitly want conversation content stored, and use a scoped API key and namespace if enabling cloud mode.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:614
Finding

Recommended Cloud Configuration Enables Broad Conversation Capture and Server-Side Recall Telemetry

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Required Plugin Installation Is Not Version-Pinned or Integrity-Verified

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly supports cloud mode that sends memory text, metadata, search queries, session events, and embedding requests to a configured remote server, but it does not present this as a prominent privacy/sensitivity warning at the point of feature description or configuration. In a memory plugin, those payloads can easily include secrets, personal data, internal prompts, or operational details, so understated disclosure materially increases the risk of unintentional exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic context injection and auto-capture are described as convenience features, but the document does not clearly foreground that they can automatically persist conversation content and derived summaries without a deliberate per-use action by the operator. Because this is memory infrastructure, users may unknowingly retain sensitive chats, preferences, decisions, or assistant outputs longer than intended, especially when combined with cloud mode.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages broad auto-capture of conversation data and, elsewhere, cloud transmission of stored memories and recall-related signals, which creates a real data leakage surface in natural-language form. Since users commonly place credentials, personal information, business context, and internal procedures into chat, automatic collection and onward storage/sharing substantially increase exposure if misconfigured, overused, or connected to third-party infrastructure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Logging every recall session to a server, including query text, selected memory IDs, scores, and usage data, is a genuine privacy and data-governance risk because recall queries often directly encode sensitive intent, names, incidents, or proprietary tasks. Even if meant for training, centralizing this telemetry creates an additional repository of semantically rich user activity that could be exposed, over-retained, or accessed beyond user expectations.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
74% confidence
Finding

The document explicitly instructs operators to turn on a setting named allowPromptInjection so injected context can be inserted before prompt build. Even though intended for benign context injection, this phrasing and mechanism semantically weaken prompt-boundary protections and normalize an instruction path that can redirect model behavior through injected text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The API key description specifically says it is used for "BGE-small-en-v1.5 embeddings," which implies an English-oriented embedding model. The document does not offer language/locale opt-in or clearly justify an English-only limitation, creating a potential language-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.