Back to skill

Security audit

Unified Memory V5

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real memory-management skill, but it needs Review because it includes unsafe install guidance, reachable shell-command injection, automatic memory capture and recall, and broad persistent/network-exposed memory controls.

Install only after reviewing this skill carefully. It can persist and inject memories automatically, expose memory data through local/network services, run git shell commands through MCP tools, load external plugin code, and store cloud backup credentials locally. Avoid the curl-to-shell install paths, do not enable cloud backup or HTTP/API features unless you understand the exposure, and treat git/plugin/sync tools as high-risk until command execution and permission scoping are fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
merged-docs.md:2169
Finding

Recommended installation executes a mutable remote payload without verification

Content
View full analysis
Remediation
View remediation
install.sh" | sha256sum --check - less install.sh bash install.sh ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
merged-src.js:21832
Finding

MCP Git tools permit shell command injection through untrusted string parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
merged-src.js:8304
Finding

Cloud storage credentials are persisted in plaintext with unspecified file permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (136)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The auto-activation triggers include very common words such as "memory," "remember," and especially the Chinese phrase "我想知道" ("I want to know"), which are likely to appear in ordinary conversation. This can cause the skill to activate unexpectedly and perform retrieval or writes without clear user intent, increasing the chance of privacy leakage or unintended state changes.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 451)May include surrounding context.

md
| `STORAGE_MODE` | `json` | Storage backend: `json` or `sqlite` |
| `OPENCLAW_WORKSPACE_DIR` | `~/.openclaw/workspace` | Workspace directory |

<!-- zh -->
| 变量 | 默认值 | 说明 |
|------|--------|------|
| `OLLAMA_HOST` | `http://localhost:11434` | Ollama API 地址 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 596)May include surrounding context.

md
| `memory_noise` | Filter noise — skip generic or meaningless queries. |
| `memory_intent` | Detect user intent and route to appropriate handler. |

<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_search` | 混合搜索:BM25 + 向量检索,支持范围过滤,返回排序结果和摘要高亮。 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 596)May include surrounding context.

md
| `memory_noise` | Filter noise — skip generic or meaningless queries. |
| `memory_intent` | Detect user intent and route to appropriate handler. |

<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_search` | 混合搜索:BM25 + 向量检索,支持范围过滤,返回排序结果和摘要高亮。 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 733)May include surrounding context.

md
| `memory_gitnotes_restore` | Restore git notes. |
| `memory_cloud_backup_api` | Cloud backup API management. |

<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_stats` | 记忆统计:数量、分类、标签、分布。 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 733)May include surrounding context.

md
| `memory_gitnotes_restore` | Restore git notes. |
| `memory_cloud_backup_api` | Cloud backup API management. |

<!-- zh -->
| 工具 | 说明 |
|------|------|
| `memory_stats` | 记忆统计:数量、分类、标签、分布。 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 802)May include surrounding context.

mcporter call unified-memory memory_version '{"memoryId": "mem_xxx"}'

text

<!-- zh -->
```bash
# 健康检查
mcporter call unified-memory memory_health '{}'

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · merged-docs.md (reported line 1493)May include surrounding context.

getMemory(id) // Get by ID getAllMemories(options) // List with filters updateMemory(id, updates) // Update fields deleteMemory(id) // Delete memory saveMemories(memories) // Bulk save

text

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · merged-docs.md (reported line 3169)May include surrounding context.

getMemory(id) // Get by ID getAllMemories(options) // List with filters updateMemory(id, updates) // Update fields deleteMemory(id) // Delete memory saveMemories(memories) // Bulk save

text

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · merged-docs.md (reported line 6384)May include surrounding context.

getMemory(id) // Get by ID getAllMemories(options) // List with filters updateMemory(id, updates) // Update fields deleteMemory(id) // Delete memory saveMemories(memories) // Bulk save

text

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · merged-docs.md (reported line 1905)May include surrounding context.

rank_i = rank from algorithm i

text

## Delete Memory Flow

Client: memory_delete({ id })

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · merged-docs.md (reported line 6465)May include surrounding context.

rank_i = rank from algorithm i

text

## Delete Memory Flow

Client: memory_delete({ id })

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Piping the Unified Memory install script directly from the network into bash creates a one-command arbitrary code execution path. Users are encouraged to trust and execute remote content without review.

Content

Scanner excerpt · merged-docs.md (reported line 2169)May include surrounding context.

bash
# Install
curl -fsSL https://raw.githubusercontent.com/mouxangithub/unified-memory/main/install.sh | bash

# Store a memory
unified-memory add "Remember to review quarterly reports" --tags work,reminder

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 6467)May include surrounding context.

Delete Memory

text
DELETE /api/memories/:id
bash

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

This quick install example chains network retrieval and shell execution, which is a classic unsafe pattern. If the source is compromised, copied users immediately execute attacker code.

Content

Scanner excerpt · merged-docs.md (reported line 6810)May include surrounding context.

Quick install:

bash
curl -fsSL https://raw.githubusercontent.com/mouxangithub/unified-memory/main/install.sh | bash

Or via npm:

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

Piping Ollama's remote install script to sh executes unaudited network content immediately. A compromise of the hosting endpoint or upstream account would give attackers arbitrary code execution on the host.

Content

Scanner excerpt · merged-docs.md (reported line 6823)May include surrounding context.

Yes, but you'll only have BM25 search. Vector search requires Ollama:

bash
# Install Ollama
curl -fsSL https://ollama.com/install.sh | sh

# Pull embedding model
ollama pull nomic-embed-text

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The Ollama installer example chains remote download into sh, enabling arbitrary code execution from a fetched script. Because it appears in setup guidance, users may run it with little scrutiny.

Content

Scanner excerpt · merged-docs.md (reported line 6823)May include surrounding context.

Yes, but you'll only have BM25 search. Vector search requires Ollama:

bash
# Install Ollama
curl -fsSL https://ollama.com/install.sh | sh

# Pull embedding model
ollama pull nomic-embed-text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 7021)May include surrounding context.

Vector store initialization failed

bash
rm -rf ~/.unified-memory/vector.lance
unified-memory init

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 7543)May include surrounding context.

Vector store initialization failed

bash
rm -rf ~/.unified-memory/vector.lance
unified-memory init

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 7546)May include surrounding context.

Vector store initialization failed

bash
rm -rf ~/.unified-memory/vector.lance
unified-memory init

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 7620)May include surrounding context.

Vector store initialization failed

bash
rm -rf ~/.unified-memory/vector.lance
unified-memory init

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 8523)May include surrounding context.

Vector store initialization failed

bash
rm -rf ~/.unified-memory/vector.lance
unified-memory init

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 11970)May include surrounding context.

Vector store initialization failed

bash
rm -rf ~/.unified-memory/vector.lance
unified-memory init

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 11971)May include surrounding context.

Vector store initialization failed

bash
rm -rf ~/.unified-memory/vector.lance
unified-memory init

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · merged-docs.md (reported line 12006)May include surrounding context.

Vector store initialization failed

bash
rm -rf ~/.unified-memory/vector.lance
unified-memory init

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
merged-src.js:16446

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
merged-src.js:19

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
merged-docs.md:6106

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
merged-src.js:89862