T03 · Remote Payload Retrieval and Execution
- Location
merged-docs.md:2169- Finding
Unpinned Remote Installation Scripts Are Piped Directly into a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real memory-management skill, but it should go to Review because it persistently stores and replays private memories while also exposing broad install, sync, backup, plugin, and automation risks.
Install only after reviewing the publisher and package contents. Treat stored memories as sensitive data, avoid cloud backup or sync unless endpoints and credentials are trusted, require confirmation before export/delete/restore/plugin/cron actions, and do not use the curl-to-shell installer path.
merged-docs.md:2169Unpinned Remote Installation Scripts Are Piped Directly into a Shell
merged-src.js:76526Untrusted Persistent Memory Is Injected Directly into the Agent Prompt
merged-src.js:8313Cloud Credentials Are Stored in Plaintext and May Be Transmitted over Insecure Endpoints
package.json:31Unauditable Crontab Generation Creates Cross-Session Execution Persistence
package.json:39npm Installation Automatically Invokes an Installer Missing from the Reviewed Artifact
The auto-activation triggers are extremely broad, including common terms like "memory," "remember," "我想知道," and "记忆." This can cause the skill to activate during ordinary conversation without clear user intent, increasing the chance of unintended storage, retrieval, export, or other sensitive memory operations.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
| `STORAGE_MODE` | `json` | Storage backend: `json` or `sqlite` |
| `OPENCLAW_WORKSPACE_DIR` | `~/.openclaw/workspace` | Workspace directory |
<!-- zh -->
| 变量 | 默认值 | 说明 |
|------|--------|------|
| `OLLAMA_HOST` | `http://localhost:11434` | Ollama API 地址 |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
| `memory_noise` | Filter noise — skip generic or meaningless queries. |
| `memory_intent` | Detect user intent and route to appropriate handler. |
<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_search` | 混合搜索:BM25 + 向量检索,支持范围过滤,返回排序结果和摘要高亮。 |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
| `memory_noise` | Filter noise — skip generic or meaningless queries. |
| `memory_intent` | Detect user intent and route to appropriate handler. |
<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_search` | 混合搜索:BM25 + 向量检索,支持范围过滤,返回排序结果和摘要高亮。 |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
| `memory_gitnotes_restore` | Restore git notes. |
| `memory_cloud_backup_api` | Cloud backup API management. |
<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_stats` | 记忆统计:数量、分类、标签、分布。 |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
| `memory_gitnotes_restore` | Restore git notes. |
| `memory_cloud_backup_api` | Cloud backup API management. |
<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_stats` | 记忆统计:数量、分类、标签、分布。 |
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
mcporter call unified-memory memory_version '{"memoryId": "mem_xxx"}'
<!-- zh -->
```bash
# 健康检查
mcporter call unified-memory memory_health '{}'
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
e --version
curl -fsSL https://rpm.nodesource.com/setup_18.x | sudo bash - sudo apt install -y nodejs
nvm install 18 nvm use 18
### "EACCES: permission denied"
**Cause:** npm global directory not writable
**Solution:**
```bash
# Create npm global directory
mkdir ~/.npm-global
# Configure npm
npm config set prefix '~/.npm-global'
# Add to PATH
echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc
source ~/.bashrc
# Install again
npm install -g unified-memory
Cause: Cannot create/read storage directory
Solution:
# Create directory manually
mkdir -p ~/.unified-memory
# Fix permissions
chmod 755 ~/.unified-memory
# Reinitialize
unified-memory init
Cause: Another process using port 3851
Solution:
# Find process
lsof -i :3851
# Kill process or use different port
unified-memory serve --port 3852
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
ve_learner.py
*
* 在每次重要交互后自动:
* 1. 提取关键信息存入 unified-memory
* 2. 推送到 OpenClaw 索引
* 3. 保持记忆新鲜度
*/
import { readFileSync, writeFileSync, existsSync, mkdirSync } from 'fs';
import { join, dirname } from 'path';
import { fileURLToPath } from 'url';
import { extractImportantInfo } from '../tools/autostore.js';
import { addMemory, getAllMemories, saveMemories } from '../storage.js';
import { config } from '../config.js';
const __dirname = dirname(fileURLToPath(import.meta.url));
const HOME = process.env.HOME || '/root';
const WORKSPACE = join(HOME, '.openclaw', 'workspace');
const MEMORY_DIR = join(WORKSPACE, 'memory');
const JSON_FILE = join(MEMORY_DIR, 'active_memories.json');
// Ensure memory dir exists
if (!existsSync(MEMORY_DIR)) {
mkdirSync(MEMORY_DIR, { recursive: true });
}
/**
* ActiveLearner - 主动学习器
*/
export class ActiveLearner {
constructor() {
/** @type {Array<object>} */
this.memorie
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
{string} text - 要学习的文本
* @param {object} [metadata] - 元数据
* @returns {Promise<object|null>} 提取的记忆条目,如果没有新信息则返回 null
*/
async learn(text, metadata = null) {
const extractions = [];
// 1. 项目/工具名 (贪婪匹配)
const toolMatches = text.match(/(?:使用|安装|提到|关于)\s+([A-Za-z0-9\-]+)/g) || [];
const tools = [...new Set(toolMatches.map(m => m.replace(/^(?:使用|安装|提到|关于)\s+/, '')))];
for (const tool of tools) {
if (tool.length > 2 && !['the', 'and', 'for', 'with'].includes(tool.toLowerCase())) {
extractions.push(`工具相关: ${tool}`);
}
}
// 2. 偏好模式: "喜欢X" / "不喜欢X"
const likes = text.match(/喜欢\s*([^\s,,。!?]+)/g) || [];
for (const like of likes) {
extractions.push(`偏好(喜欢): ${like.replace(/喜欢\s*/, '')}`);
}
const dislikes = text.match(/不喜欢\s*([^\s,,。!?]+)/g) || [];
The declared env permissions list only OLLAMA_HOST, OLLAMA_EMBED_MODEL, and STORAGE_MODE, but the documentation also relies on LLM_MODEL, LLM_PROVIDER, VECTOR_ENGINE, and OPENCLAW_WORKSPACE_DIR. This discrepancy weakens least-privilege guarantees because the skill's documented behavior depends on undeclared environment inputs that may influence network endpoints, model selection, storage mode, or file locations.
The skill exposes destructive and privacy-impacting capabilities such as delete, export, cloud backup, restore, and sync, but the documentation does not present warnings, confirmations, or consent guidance. In a memory-management skill handling personal and team data, that omission materially increases the risk of accidental data loss or disclosure.
The skill declares filesystem write access only under ~/.openclaw/workspace/memory/, but the documentation states benchmark results are saved under ~/.openclaw/skills/unified-memory/src/benchmark/results/. That mismatch means the implementation either cannot perform as documented or would require broader file writes than declared, undermining permission transparency and creating risk of writes into the skill installation area.
The plugin system and registry path indicate persistent extensibility state under ~/.openclaw/workspace/memory/plugins/registry.json, allowing behavior changes to survive across sessions. In a memory skill with hooks on beforeSearch, afterSearch, beforeWrite, and afterWrite, persistent plugin state raises the risk that a previously enabled or registered plugin continues to influence sensitive data flows, searches, and writes without fresh user awareness.
beforeSearch → [实际搜索] → afterSearch
↓
beforeWrite → [实际写入] → afterWrite
插件注册表位置:
One section says crash recovery will replay uncommitted STORE operations by applying them, while the later crash-recovery flow states STORE operations are completed on recovery and DELETE operations are reverted. Elsewhere, incomplete prepared transactions are described as requiring a commit-or-rollback decision, so the recovery intent is not consistent across the file.
The design-principles section states memory operations provide ACID properties with atomicity via two-phase commit and durability via fsync, implying fully atomic multi-store writes. However, the same document later says storage writes are synchronous while vector index updates are asynchronous and search results may be stale, which directly contradicts the earlier guarantee for the same operation class.
The installation instructions recommend curl ... | bash, which executes remote code directly without integrity verification. If the source, transport, repository, or DNS path is compromised, users may immediately run attacker-controlled shell code.
This markdown documents memory_delete as deleting a memory by ID, but does not warn that the operation removes stored user data and may be irreversible from the user's perspective. Under the markdown criteria, descriptions of behaviors affecting user data should include an explicit warning or recovery note.
The documentation normalizes prompt-context injection from stored memories without any privacy warning or minimization guidance. In an agent skill context, this can cause sensitive stored user data to be replayed into downstream model prompts or external providers, increasing disclosure risk.
Export features are documented as ordinary operations with no warning that they write potentially sensitive memory contents to files outside the protected runtime. This can lead to accidental persistence in insecure locations, backup systems, or shared directories.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
```bash
curl "http://localhost:3851/api/memories/search?q=quarterly%20reports&mode=hybrid&topK=5"
The connector example fetches from an external API and maps returned data into local memory records. While not malicious, it demonstrates external data exchange in a sensitive memory context without trust-boundary warnings, validation guidance, or mention of privacy implications.
async pull() {
// Fetch from external system
const data = await fetch('https://api.example.com/memories');
return data.map(item => ({
text: item.content,
tags: item.labels,
This example pushes memory contents to an external API, creating a real data exposure pathway if copied into production plugins. Because the skill manages user memories, sending memory.text and tags externally without strong warnings materially increases privacy and exfiltration risk.
async push(memories) {
// Push to external system
for (const memory of memories) {
await fetch('https://api.example.com/memories', {
method: 'POST',
body: JSON.stringify({
content: memory.text,
This example pushes memory contents to an external API, creating a real data exposure pathway if copied into production plugins. Because the skill manages user memories, sending memory.text and tags externally without strong warnings materially increases privacy and exfiltration risk.
async push(memories) {
// Push to external system
for (const memory of memories) {
await fetch('https://api.example.com/memories', {
method: 'POST',
body: JSON.stringify({
content: memory.text,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
print(response.json())
# Store
response = requests.post(f"{BASE_URL}/memories", json={
"text": "Python preference for data work",
"category": "preference",
"tags": ["python", "data"]
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)