Back to skill

Security audit

Unified Memory V5

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real memory-management skill, but it should go to Review because it persistently stores and replays private memories while also exposing broad install, sync, backup, plugin, and automation risks.

Install only after reviewing the publisher and package contents. Treat stored memories as sensitive data, avoid cloud backup or sync unless endpoints and credentials are trusted, require confirmation before export/delete/restore/plugin/cron actions, and do not use the curl-to-shell installer path.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
merged-docs.md:2169
Finding

Unpinned Remote Installation Scripts Are Piped Directly into a Shell

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
merged-src.js:76526
Finding

Untrusted Persistent Memory Is Injected Directly into the Agent Prompt

Content
View full analysis
0) { const memoryContext = results.map(r => r.memory.text).join('\n'); return { injectedContext: `相关记忆:\n${memoryContext}`, }; } } catch (err) { log.error('[Hook] before_prompt_build error:', err); } return {}; } ``` ### Technical Analysis The `before_prompt_build` hook retrieves persistent memory records and concatenates their raw text directly into the Agent's prompt context. The implementation does not: - Quote or structurally isolate memory as untrusted data. - Distinguish factual memory from executable instructions. - Apply the exported `looksLikePromptInjection` detector. - Preserve and display source provenance. - Require confirmation for memories imported through synchronization or restore. - Restrict the recalled content to a safe schema. A memory record can therefore contain instructions such as requests to ignore current policies, invoke tools, disclose data, or alter future behavior. Because the record is persistent, the malicious instruction can affect later sessions whenever semantic or hybrid search retrieves it. The Skill also exposes synchronization, restoration, storage, and automatic capture features. These increase the number of channels through which attacker-controlled text can enter persistent memory. ### Attack Path 1. An attacker causes crafted text to be stored as memory through a normal memory operation, imported backup, synchronization source, shared memory, or captured conversation. 2. The text includes in ...[truncated 1169 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
merged-src.js:8313
Finding

Cloud Credentials Are Stored in Plaintext and May Be Transmitted over Insecure Endpoints

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
package.json:31
Finding

Unauditable Crontab Generation Creates Cross-Session Execution Persistence

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:39
Finding

npm Installation Automatically Invokes an Installer Missing from the Reviewed Artifact

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (59)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The auto-activation triggers are extremely broad, including common terms like "memory," "remember," "我想知道," and "记忆." This can cause the skill to activate during ordinary conversation without clear user intent, increasing the chance of unintended storage, retrieval, export, or other sensitive memory operations.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 451)May include surrounding context.

md
| `STORAGE_MODE` | `json` | Storage backend: `json` or `sqlite` |
| `OPENCLAW_WORKSPACE_DIR` | `~/.openclaw/workspace` | Workspace directory |

<!-- zh -->
| 变量 | 默认值 | 说明 |
|------|--------|------|
| `OLLAMA_HOST` | `http://localhost:11434` | Ollama API 地址 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 596)May include surrounding context.

md
| `memory_noise` | Filter noise — skip generic or meaningless queries. |
| `memory_intent` | Detect user intent and route to appropriate handler. |

<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_search` | 混合搜索:BM25 + 向量检索,支持范围过滤,返回排序结果和摘要高亮。 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 596)May include surrounding context.

md
| `memory_noise` | Filter noise — skip generic or meaningless queries. |
| `memory_intent` | Detect user intent and route to appropriate handler. |

<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_search` | 混合搜索:BM25 + 向量检索,支持范围过滤,返回排序结果和摘要高亮。 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 733)May include surrounding context.

md
| `memory_gitnotes_restore` | Restore git notes. |
| `memory_cloud_backup_api` | Cloud backup API management. |

<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_stats` | 记忆统计:数量、分类、标签、分布。 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 733)May include surrounding context.

md
| `memory_gitnotes_restore` | Restore git notes. |
| `memory_cloud_backup_api` | Cloud backup API management. |

<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_stats` | 记忆统计:数量、分类、标签、分布。 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 802)May include surrounding context.

mcporter call unified-memory memory_version '{"memoryId": "mem_xxx"}'

text

<!-- zh -->
```bash
# 健康检查
mcporter call unified-memory memory_health '{}'

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · merged-docs.md (reported line 7463)May include surrounding context.

e --version

Update Node.js

macOS/Linux

curl -fsSL https://rpm.nodesource.com/setup_18.x | sudo bash - sudo apt install -y nodejs

Or use nvm

nvm install 18 nvm use 18

text

### "EACCES: permission denied"

**Cause:** npm global directory not writable

**Solution:**
```bash
# Create npm global directory
mkdir ~/.npm-global

# Configure npm
npm config set prefix '~/.npm-global'

# Add to PATH
echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.bashrc
source ~/.bashrc

# Install again
npm install -g unified-memory

Startup Issues

"Failed to initialize storage"

Cause: Cannot create/read storage directory

Solution:

bash
# Create directory manually
mkdir -p ~/.unified-memory

# Fix permissions
chmod 755 ~/.unified-memory

# Reinitialize
unified-memory init

"Port already in use"

Cause: Another process using port 3851

Solution:

bash
# Find process
lsof -i :3851

# Kill process or use different port
unified-memory serve --port 3852

"Con

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · merged-src.js (reported line 15)May include surrounding context.

js
ve_learner.py
 * 
 * 在每次重要交互后自动:
 * 1. 提取关键信息存入 unified-memory
 * 2. 推送到 OpenClaw 索引
 * 3. 保持记忆新鲜度
 */

import { readFileSync, writeFileSync, existsSync, mkdirSync } from 'fs';
import { join, dirname } from 'path';
import { fileURLToPath } from 'url';
import { extractImportantInfo } from '../tools/autostore.js';
import { addMemory, getAllMemories, saveMemories } from '../storage.js';
import { config } from '../config.js';

const __dirname = dirname(fileURLToPath(import.meta.url));
const HOME = process.env.HOME || '/root';
const WORKSPACE = join(HOME, '.openclaw', 'workspace');
const MEMORY_DIR = join(WORKSPACE, 'memory');
const JSON_FILE = join(MEMORY_DIR, 'active_memories.json');

// Ensure memory dir exists
if (!existsSync(MEMORY_DIR)) {
  mkdirSync(MEMORY_DIR, { recursive: true });
}

/**
 * ActiveLearner - 主动学习器
 */
export class ActiveLearner {
  constructor() {
    /** @type {Array<object>} */
    this.memorie

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · merged-src.js (reported line 64)May include surrounding context.

js
{string} text - 要学习的文本
   * @param {object} [metadata] - 元数据
   * @returns {Promise<object|null>} 提取的记忆条目,如果没有新信息则返回 null
   */
  async learn(text, metadata = null) {
    const extractions = [];

    // 1. 项目/工具名 (贪婪匹配)
    const toolMatches = text.match(/(?:使用|安装|提到|关于)\s+([A-Za-z0-9\-]+)/g) || [];
    const tools = [...new Set(toolMatches.map(m => m.replace(/^(?:使用|安装|提到|关于)\s+/, '')))];
    for (const tool of tools) {
      if (tool.length > 2 && !['the', 'and', 'for', 'with'].includes(tool.toLowerCase())) {
        extractions.push(`工具相关: ${tool}`);
      }
    }

    // 2. 偏好模式: "喜欢X" / "不喜欢X"
    const likes = text.match(/喜欢\s*([^\s,,。!?]+)/g) || [];
    for (const like of likes) {
      extractions.push(`偏好(喜欢): ${like.replace(/喜欢\s*/, '')}`);
    }

    const dislikes = text.match(/不喜欢\s*([^\s,,。!?]+)/g) || [];

Scope Creep

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The declared env permissions list only OLLAMA_HOST, OLLAMA_EMBED_MODEL, and STORAGE_MODE, but the documentation also relies on LLM_MODEL, LLM_PROVIDER, VECTOR_ENGINE, and OPENCLAW_WORKSPACE_DIR. This discrepancy weakens least-privilege guarantees because the skill's documented behavior depends on undeclared environment inputs that may influence network endpoints, model selection, storage mode, or file locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill exposes destructive and privacy-impacting capabilities such as delete, export, cloud backup, restore, and sync, but the documentation does not present warnings, confirmations, or consent guidance. In a memory-management skill handling personal and team data, that omission materially increases the risk of accidental data loss or disclosure.

Content

No source excerpt is available for this finding.

Scope Creep

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares filesystem write access only under ~/.openclaw/workspace/memory/, but the documentation states benchmark results are saved under ~/.openclaw/skills/unified-memory/src/benchmark/results/. That mismatch means the implementation either cannot perform as documented or would require broader file writes than declared, undermining permission transparency and creating risk of writes into the skill installation area.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The plugin system and registry path indicate persistent extensibility state under ~/.openclaw/workspace/memory/plugins/registry.json, allowing behavior changes to survive across sessions. In a memory skill with hooks on beforeSearch, afterSearch, beforeWrite, and afterWrite, persistent plugin state raises the risk that a previously enabled or registered plugin continues to influence sensitive data flows, searches, and writes without fresh user awareness.

Content

Scanner excerpt · SKILL.md (reported line 1280)May include surrounding context.

text
beforeSearch → [实际搜索] → afterSearch
                   ↓
beforeWrite → [实际写入] → afterWrite

插件注册表位置:

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

One section says crash recovery will replay uncommitted STORE operations by applying them, while the later crash-recovery flow states STORE operations are completed on recovery and DELETE operations are reverted. Elsewhere, incomplete prepared transactions are described as requiring a commit-or-rollback decision, so the recovery intent is not consistent across the file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The design-principles section states memory operations provide ACID properties with atomicity via two-phase commit and durability via fsync, implying fully atomic multi-store writes. However, the same document later says storage writes are synchronous while vector index updates are asynchronous and search results may be stale, which directly contradicts the earlier guarantee for the same operation class.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installation instructions recommend curl ... | bash, which executes remote code directly without integrity verification. If the source, transport, repository, or DNS path is compromised, users may immediately run attacker-controlled shell code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown documents memory_delete as deleting a memory by ID, but does not warn that the operation removes stored user data and may be irreversible from the user's perspective. Under the markdown criteria, descriptions of behaviors affecting user data should include an explicit warning or recovery note.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation normalizes prompt-context injection from stored memories without any privacy warning or minimization guidance. In an agent skill context, this can cause sensitive stored user data to be replayed into downstream model prompts or external providers, increasing disclosure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Export features are documented as ordinary operations with no warning that they write potentially sensitive memory contents to files outside the protected runtime. This can lead to accidental persistence in insecure locations, backup systems, or shared directories.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · merged-docs.md (reported line 6425)May include surrounding context.

text

```bash
curl "http://localhost:3851/api/memories/search?q=quarterly%20reports&mode=hybrid&topK=5"

List Memories

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The connector example fetches from an external API and maps returned data into local memory records. While not malicious, it demonstrates external data exchange in a sensitive memory context without trust-boundary warnings, validation guidance, or mention of privacy implications.

Content

Scanner excerpt · merged-docs.md (reported line 6668)May include surrounding context.

md
async pull() {
    // Fetch from external system
    const data = await fetch('https://api.example.com/memories');
    return data.map(item => ({
      text: item.content,
      tags: item.labels,

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This example pushes memory contents to an external API, creating a real data exposure pathway if copied into production plugins. Because the skill manages user memories, sending memory.text and tags externally without strong warnings materially increases privacy and exfiltration risk.

Content

Scanner excerpt · merged-docs.md (reported line 6679)May include surrounding context.

md
async push(memories) {
    // Push to external system
    for (const memory of memories) {
      await fetch('https://api.example.com/memories', {
        method: 'POST',
        body: JSON.stringify({
          content: memory.text,

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This example pushes memory contents to an external API, creating a real data exposure pathway if copied into production plugins. Because the skill manages user memories, sending memory.text and tags externally without strong warnings materially increases privacy and exfiltration risk.

Content

Scanner excerpt · merged-docs.md (reported line 6679)May include surrounding context.

md
async push(memories) {
    // Push to external system
    for (const memory of memories) {
      await fetch('https://api.example.com/memories', {
        method: 'POST',
        body: JSON.stringify({
          content: memory.text,

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · merged-docs.md (reported line 6739)May include surrounding context.

md
print(response.json())

# Store
response = requests.post(f"{BASE_URL}/memories", json={
    "text": "Python preference for data work",
    "category": "preference",
    "tags": ["python", "data"]

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
merged-src.js:16446

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
merged-src.js:19

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
merged-docs.md:6106

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
merged-src.js:89862