Back to skill

Security audit

Openclaw Memory Transfer

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent memory-migration purpose, but it asks agents to read broad local AI files automatically and uses an unsafe ZIP parser for sensitive ChatGPT exports.

Install only if you are comfortable reviewing sensitive memory imports carefully. Do not upload untrusted ZIP files, review and redact exports before use, avoid local auto-scan unless you have selected the exact files, and remove any imported rules that could change future agent behavior.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/parse-chatgpt-export.js:31
Finding

Shell Command Injection Through an Attacker-Controlled ZIP Path

Content
View full analysis
'); console.error('Parses a ChatGPT data export ZIP and outputs structured JSON.'); process.exit(zipPath === '--help' ? 0 : 1); } if (!fs.existsSync(zipPath)) { console.error(`File not found: ${zipPath}`); process.exit(1); } const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'chatgpt-export-')); try { // Extract ZIP with path traversal protection execSync(`unzip -o -q "${zipPath}" -d "${tmpDir}"`, { stdio: 'pipe' }); ``` ### Technical Analysis The ZIP path is accepted directly from `process.argv[2]` and interpolated into a command string passed to `execSync`. By default, `execSync` executes the string through a system shell. Surrounding the path with double quotes is not sufficient shell escaping. A path containing a double quote, command substitution, or other shell syntax can terminate or alter the intended argument and cause the shell to execute additional commands. The preceding `fs.existsSync(zipPath)` check does not sanitize the path and does not prevent exploitation if a file with a crafted name exists. The parser is explicitly invoked on user-uploaded ZIP files, so the filename or path may be attacker-controlled. Calling an external extractor is reasonable for the declared function, but invoking it through a shell is unnecessary and exceeds the minimum risk needed for extraction. ### Attack Path 1. An attacker creates a valid ZIP file whose local filename or supplied path contains shell-significant characters. 2. The file is uploaded for ChatGPT memory migration. 3. The Agent invokes the documented parser with the uploaded path. 4. The parser interpolates that path into the `unzip` shell command. 5. The shell ...[truncated 752 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/parse-chatgpt-export.js:42
Finding

Archive Safety Validation Occurs Only After Extraction

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/parse-chatgpt-export.js:42
Finding

Unbounded ZIP Expansion and Full In-Memory JSON Parsing Enable Denial of Service

Content
View full analysis
500 * 1024 * 1024) { console.error(`Warning: conversations.json is ${Math.round(stat.size / 1024 / 1024)}MB — parsing may be slow`); } try { const rawData = fs.readFileSync(convoFile, 'utf8'); const conversations = JSON.parse(rawData); // Safety cap const convoSlice = conversations.slice(0, MAX_CONVERSATIONS); ``` ### Technical Analysis No limit is imposed on: - Compressed archive size. - Total expanded archive size. - Number of entries. - Per-entry size. - Compression ratio. - Extraction duration. A highly compressed archive can therefore consume all available temporary-disk capacity before parsing begins. The script only warns when `conversations.json` exceeds 500 MB and then immediately loads the entire file as a UTF-8 string and parses the entire JSON document. This can require several times the source file’s size in memory due to the input buffer, JavaScript string representation, parsed object graph, and derived arrays. The `MAX_CONVERSATIONS` limit is applied only after complete parsing and therefore does not protect extraction, file reading, or JSON parsing. The script header also states that large exports are streamed, but the implementation uses `readFileSync` and `JSON.parse`. ### Attack Path 1. An attacker uploads a ZIP bomb or an export containing a very large `conversations.json`. 2. `unzip` expands the archive without ...[truncated 949 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:170
Finding

Local-Agent Migration Performs Broad Home-Directory Reconnaissance Without Explicit Scan Approval

Content
View full analysis
/dev/null # All project memories find ~/.claude/projects -name "*.md" -path "*/memory/*" 2>/dev/null | head -20 | while read f; do echo "=== $f ===" cat "$f" done # Project instructions find ~/.claude/projects -name "CLAUDE.md" 2>/dev/null | head -20 | while read f; do echo "=== $f ===" cat "$f" done ``` **Cursor:** ```bash cat ~/.cursor/rules/*.md 2>/dev/null find . -maxdepth 3 -name ".cursorrules" 2>/dev/null | head -10 | while read f; do echo "=== $f ===" cat "$f" done ``` **Windsurf:** ```bash cat ~/.windsurf/rules/*.md 2>/dev/null find . -maxdepth 3 -name ".windsurfrules" 2>/dev/null | head -10 | while read f; do echo "=== $f ===" cat "$f" done ``` **Generic (AGENT.md / CLAUDE.md / rules files):** ```bash find ~ -maxdepth 4 \( -name "AGENT.md" -o -name "CLAUDE.md" -o -name ".cursorrules" -o -name ".windsurfrules" \) 2>/dev/null | head -20 | while read f; do echo "=== $f ===" cat "$f" done ``` ``` ### Technical Analysis The Skill directs the Agent to read local configuration and memory files automatically, explicitly stating that no user action is needed. The generic fallback searches the user’s entire home directory to a depth of four and reads matching files immediately. Reading source-specific settings may be necessary for migration, but searching the entire home directory and ingesting unrelated projects is broader than the minimum privilege required. Filenames such as `CLAUDE.md` or `AGENT.md` do not establish that a file belongs to the requested migration scope. The existing credential-filtering guidance applies during later categorization and does n ...[truncated 1341 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:221
Finding

Untrusted Imported Instructions Can Be Written Into Persistent Agent Memory

Content
View full analysis
` - **Use the user's language** — write entries in the language the user communicates in ``` ### Technical Analysis The Skill accepts data from ChatGPT exports, responses generated by other AI systems, and local Agent instruction files. These sources are not trusted security principals and may contain attacker-authored text. The categorization rules explicitly preserve “don’t do this” rules, corrections, behavior ...[truncated 2216 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (42)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The 'Auto-Scan' entries imply that local AI tool data can be collected automatically, with no user action required, which creates a strong risk of unauthorized or unexpected access to conversation history, preferences, and project context stored on disk. In a migration skill specifically designed to harvest memory-like data, this context makes the behavior more dangerous because the likely scan targets are deeply personal and broad in scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

La description présente le transfert comme “sans friction” et automatique sans avertissement visible sur les risques de confidentialité, de minimisation des données ou de persistance d’informations personnelles. Pour un skill conçu pour importer identité, habitudes et connaissances depuis d’autres assistants, cette omission peut amener les utilisateurs à partager des données très sensibles sans consentement éclairé.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Les modes “scan automatique” sont décrits comme ne nécessitant aucune action de l’utilisateur, sans préciser quelles zones locales seront inspectées ni quels types de fichiers ou secrets peuvent être lus. Dans un contexte de migration mémoire depuis des agents locaux, cela crée un risque important d’accès trop large à des données locales sensibles et d’exfiltration involontaire.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README promotes extracting 'everything your old AI knows about you' and states that some local-agent sources are scanned automatically with 'nothing' required from the user, but it does not prominently warn about privacy, scope, sensitive files, consent, retention, or review before import. In the context of a memory-migration skill, this omission materially increases the risk of over-collection and transfer of personal, confidential, or third-party data without informed user consent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

Claiming the skill can extract 'everything the old AI knows about you' encourages indiscriminate collection and transfer of user data far beyond what is necessary for personalization. In this skill context, that language normalizes overcollection of sensitive personal, professional, and historical conversational data into a persistent memory system, increasing privacy and breach impact.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document instructs users to send a prompt to a previous AI so it outputs 'all information about you' and then paste that aggregate back into the current agent. This creates a high-risk bulk exfiltration path for personal data, confidential work context, and sensitive behavioral history, while bypassing data minimization and making accidental disclosure very likely.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The English export prompt asks another AI to disclose all stored memories, custom instructions, identity details, behavioral patterns, and corrections in exhaustive verbatim form for direct import. This encourages bulk exfiltration of highly sensitive personal profiling data and may transfer inaccurate, over-retained, or policy-sensitive information into a new system.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Chinese export prompt mirrors the same behavior by requesting exhaustive verbatim disclosure of all known user data for direct migration. The multilingual support broadens reach and makes the same privacy and over-collection risk applicable to a larger user base.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill describes automatic local file scanning but does not require a user-facing warning about filesystem access, privacy scope, or the kinds of files that may be read. This materially increases the risk of silent or poorly understood collection of personal, project, or organizational data from the local environment.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
99% confidence
Finding

This command reads the user's global Claude configuration file from the home directory. Such files can contain private instructions, workflow details, internal project context, or other sensitive information unrelated to the current migration request, making direct access risky without explicit consent and scope limitation.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

Claude Code:

bash
# Global config
cat ~/.claude/CLAUDE.md 2>/dev/null

# All project memories
find ~/.claude/projects -name "*.md" -path "*/memory/*" 2>/dev/null | head -20 | while read f; do

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
99% confidence
Finding

This instruction searches through ~/.claude/projects for markdown files in memory paths and reads their contents. That is broad access into potentially many projects and can expose unrelated proprietary, personal, or confidential data far beyond what the user intended to migrate.

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
cat ~/.claude/CLAUDE.md 2>/dev/null

# All project memories
find ~/.claude/projects -name "*.md" -path "*/memory/*" 2>/dev/null | head -20 | while read f; do
  echo "=== $f ==="
  cat "$f"
done

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
98% confidence
Finding

This command recursively finds project-level CLAUDE.md files and reads them, which may disclose project-specific instructions, internal processes, or confidential development context. Because it operates across the user's project space, it expands data collection beyond a clearly bounded migration target.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
done

# Project instructions
find ~/.claude/projects -name "CLAUDE.md" 2>/dev/null | head -20 | while read f; do
  echo "=== $f ==="
  cat "$f"
done

Context Leakage

High
Category
Data Exfiltration
Confidence
90% confidence
Finding

The code extracts conversation titles as topics, which can leak sensitive context such as projects, medical issues, legal matters, employers, or personal interests. In a memory-transfer skill, this is especially dangerous because the feature is explicitly designed to ingest and preserve prior assistant context, so leakage of topic metadata is a core risk rather than an incidental one.

Content

Scanner excerpt · scripts/parse-chatgpt-export.js (reported line 165)May include surrounding context.

js
];

      for (const convo of convoSlice) {
        // Extract conversation title as topic
        if (convo.title && convo.title !== 'New chat' && convo.title !== 'ChatGPT') {
          topicCounts[convo.title] = (topicCounts[convo.title] || 0) + 1;
        }

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script intentionally includes representative user messages in the output JSON under writingStyle.sampleMessages, exposing raw conversation content. Those messages may contain credentials, health data, internal business information, or other secrets, making this a significant privacy and data leakage issue during migration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly promises to extract 'everything' a prior assistant knows about the user and import it into memory, but provides no privacy warning, scope limitation, consent checkpoint, or guidance on handling sensitive data. In a memory-migration skill, this omission is dangerous because users may upload or expose highly personal, behavioral, and account-linked information without understanding the sensitivity or retention implications.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The text describes extracting all information a prior AI assistant knows about the user, including identity, preferences, habits, and knowledge, which is inherently sensitive profile data. Without minimization or boundaries, the skill encourages over-collection and transfer of personal and behavioral information that could be misused, leaked, or imported into another system without adequate review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Presenting local sources as 'Auto-Scan' with 'Nothing — automatically' normalizes silent access to local assistant data without warning the user that files, histories, or configuration data may be inspected. In this skill's context, that materially increases risk because the feature targets sensitive memory data from other tools and suggests collection can occur without an affirmative user action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

El README describe una migración de memoria que "extrae todo" lo que otros asistentes saben del usuario y lo importa a OpenClaw, pero no advierte de forma explícita que esto puede incluir datos personales, historiales sensibles, secretos, credenciales expuestas en conversaciones o información de terceros. En un skill cuyo propósito es precisamente recolectar e importar memoria desde múltiples fuentes, la ausencia de un aviso y de límites claros aumenta el riesgo de consentimiento insuficiente y de transferencia excesiva de datos.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Las entradas marcadas como "Escaneo automático" indican que herramientas locales como Claude Code, Cursor y Windsurf serán inspeccionadas sin acción del usuario, pero no presentan una advertencia clara sobre acceso al sistema local, lectura de archivos o posible recolección de datos sensibles. Dado el contexto del skill —migrar memoria mediante descubrimiento automático de datos locales— esto es especialmente riesgoso porque puede abarcar historiales, notas, código, tokens o información privada sin que el usuario entienda el alcance.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Le README encourage explicitement l’extraction de “tout ce que votre ancien AI sait de vous”, ce qui implique une collecte large de mémoire personnelle, de préférences et de contexte de projet. Cette formulation favorise une sur-collecte de données sensibles et augmente l’impact potentiel en cas de mauvaise manipulation, stockage excessif ou accès non autorisé.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Les phrases d’activation proposées sont génériques et plausibles dans une conversation ordinaire, ce qui peut déclencher involontairement un flux de migration de données sensibles. Dans le contexte d’un skill qui traite de mémoire personnelle et peut lancer des scans ou demandes d’export, ce chevauchement augmente le risque d’activation non intentionnelle et de collecte excessive.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Les instructions de type “copiez un prompt, collez le résultat” pour des services tiers peuvent pousser l’utilisateur à transférer en clair des résumés ou historiques contenant informations personnelles, données de projet ou secrets. Même sans automatisation locale, ce workflow augmente le risque de divulgation involontaire entre plateformes.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

La section “Ce qui est migré” mentionne explicitement l’identité, les patterns comportementaux et les préférences d’outils, c’est-à-dire des données de profilage personnel persistantes. Ce type de collecte centralisée peut accroître les risques d’atteinte à la vie privée, de corrélation d’identité et d’exposition de contexte professionnel sensible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly says the skill extracts everything a prior AI assistant knows about the user and imports it into OpenClaw, but it provides no privacy warning, consent language, or guidance about sensitive data in those exports. This is dangerous because users may upload archives or pasted content containing highly sensitive personal, professional, or confidential information without understanding the exposure or retention implications.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is designed to collect and transfer a user's accumulated 'memory' from other AI systems into a new platform, which is inherently a bulk personal-data migration workflow. In this skill context that makes the behavior more dangerous, not less, because the central feature encourages aggregation of personal context across systems without visible safeguards, minimization, or trust-boundary explanation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/parse-chatgpt-export.js:46