Back to skill

Security audit

Memory system for claws

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed persistent memory plugin, but it asks users to install code with safety checks bypassed and broadly stores and reinjects chat/tool history by default.

Install only if you intentionally want long-lived agent memory. Pin and verify the npm package, avoid the manual bypass path unless you trust the source and environment, disable prompt injection or make memory CLI-only for sensitive deployments, expand skipTools to exclude file/command outputs that may contain secrets, set retention pruning, and do not pair with on-chain/P2P backup for private or regulated data without strong encryption and deletion planning.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
references/observer.md:3
Finding

Persistent Prompt Injection Through Automatically Recalled Memory

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/cli.md:57
Finding

Safety-Scan Bypass and Unverified Third-Party Package Installation

Content
View full analysis
.tgz # 2. Wipe the existing extension dir and extract the tarball in place rm -rf ~/.openclaw/extensions/claw-mem mkdir -p ~/.openclaw/extensions/claw-mem tar -xzf /tmp/chainofclaw-claw-mem-.tgz \ -C ~/.openclaw/extensions/claw-mem --strip-components=1 # 3. Install runtime deps only (skips dev/build tooling) cd ~/.openclaw/extensions/claw-mem npm install --omit=dev # 4. Restart the gateway and verify openclaw mem status # → JSON with observation/summary/session counts ``` To download the tarball from npm without a source clone: `npm pack @chainofclaw/claw-mem@ --pack-destination /tmp` works as long as you have npm registry access; the rest of the steps are identical. ``` ### Technical Analysis The audited directory contains documentation only and does not contain the npm implem ...[truncated 2583 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
` | Dump observations + summaries + sessions to a JSON file. Flag: `--agent <id>` to scope. | | `mem import <file>` | Load a previously exported file. Uses snake_case field names (matches SQLite schema). | ``` The default observer exclusion list is narrow: ```json { "enabled": true, "dataDir": "~/.claw-mem", "tokenBudget": 8000, "maxObservations": 50, "maxSummaries": 10, "dedupWindowMs": 30000, "skipTools": ["TodoWrite", "AskUserQuestion", "Skill"] } ``` ### Technical Analysis The skill's ...[truncated 2777 chars]:3
Finding

Broad Plaintext Retention and Export of Potentially Sensitive Agent Data

Content
View full analysis
` | FTS5 full-text search over observations. Flags: `--limit `, `--type `, `--agent `, `--json`. | | `mem status` | Counts of observations / summaries / sessions / agents, plus DB path and `tokenBudget`. Quick sanity check. | | `mem forget ` | Delete all observations for a specific session. | | `mem peek` | Dump the memory context that would be injected on the next prompt (respects `tokenBudget`). Flags: `--agent `, `--json`. | | `mem prune` | Delete old observations. `--older-than ` keeps the last N days; `--before ` for explicit cutoff. | | `mem export ` | Dump observations + summaries + sessions to a JSON file. Flag: `--agent ` to scope. | | `mem import ` | Load a previously exported file. Uses snake_case field names (matches SQLite schema). | ``` The default observer exclusion list is narrow: ```json { "enabled": true, "dataDir": "~/.claw-mem", "tokenBudget": 8000, "maxObservations": 50, "maxSummaries": 10, "dedupWindowMs": 30000, "skipTools": ["TodoWrite ...[truncated 2727 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (21)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The core behavior is to capture conversations and tool-call chains into persistent storage and replay them into future prompts. That creates a substantial data-leak surface: sensitive content can be retained longer than intended, surfaced to later tasks via prompt injection of historical context, exposed through local DB access/export, or unintentionally transferred across sessions and users if tenancy boundaries are weak.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
Two flags are needed in practice — neither is "skip safety checks for fun":

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs storage of every user message and optionally assistant messages as long-lived memory for later retrieval. This broad capture model increases the chance that credentials, private instructions, proprietary code, personal data, or security-sensitive tool outputs will be indexed and later resurfaced to unrelated prompts or users, especially in shared-agent or poorly segmented deployments.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation promotes optional on-chain/P2P backup and cross-device recovery without an equally prominent warning that memory snapshots may leave the local machine, become broadly replicated, and be difficult or impossible to delete completely. If sensitive conversation history is uploaded to decentralized or immutable systems, confidentiality, data minimization, and deletion obligations may be irreversibly undermined.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly instructs users to bypass OpenClaw's normal plugin installation pipeline and its static child_process scan. That removes a security control intended to detect dangerous behavior before installation, increasing the chance that a malicious or tampered plugin is installed unchecked.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

This is a concrete destructive shell command embedded in the documentation. Even though the path is more specific than rm -rf ~, documentation that normalizes irreversible deletion can be misused or mistakenly adapted, especially when paired with instructions to bypass the platform's install safeguards.

Content

Scanner excerpt · references/cli.md (reported line 67)May include surrounding context.

md
npm pack --pack-destination /tmp        # → /tmp/chainofclaw-claw-mem-<v>.tgz

# 2. Wipe the existing extension dir and extract the tarball in place
rm -rf ~/.openclaw/extensions/claw-mem
mkdir -p ~/.openclaw/extensions/claw-mem
tar -xzf /tmp/chainofclaw-claw-mem-<v>.tgz \
    -C ~/.openclaw/extensions/claw-mem --strip-components=1

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

This is a concrete destructive shell command embedded in the documentation. Even though the path is more specific than rm -rf ~, documentation that normalizes irreversible deletion can be misused or mistakenly adapted, especially when paired with instructions to bypass the platform's install safeguards.

Content

Scanner excerpt · references/cli.md (reported line 67)May include surrounding context.

md
npm pack --pack-destination /tmp        # → /tmp/chainofclaw-claw-mem-<v>.tgz

# 2. Wipe the existing extension dir and extract the tarball in place
rm -rf ~/.openclaw/extensions/claw-mem
mkdir -p ~/.openclaw/extensions/claw-mem
tar -xzf /tmp/chainofclaw-claw-mem-<v>.tgz \
    -C ~/.openclaw/extensions/claw-mem --strip-components=1

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

L003 says the skill 'works fully on its own with no chain interaction and no external services.' However, the same file later states session summaries default to spawning openclaw infer model run and can also be configured to call Anthropic directly with an API key. That is an active contradiction in the documented behavior, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill persistently stores all chat and tool-call history by default, but the documentation does not present a prominent privacy warning or consent-oriented guidance up front. In practice, this can cause operators or users to unknowingly retain secrets, credentials, personal data, or regulated information in long-lived storage, increasing exposure in case of host compromise, debugging, export, or later retrieval.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Encouraging backup, recovery, and 'digital immortality' for captured memory increases the persistence and distribution of sensitive historical data beyond the original host. Even if optional, this framing normalizes broad retention and replication of conversation history, which magnifies the blast radius of accidental capture or compromise.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli.md (reported line 33)May include surrounding context.

md
|---|---|
| `config list` | Print the full effective config. Flags: `--from-disk`, `--section <name>`. |
| `config get <path>` | Read a dotted key (e.g. `tokenBudget`, `summarizer.mode`). Flags: `--json`, `--from-disk`. |
| `config set <path> <value>` | Write a key to `~/.claw-mem/config.json`. String-coercion is careful not to stringify hex keys or URLs. Flag: `--json` (treat value as JSON). |
| `config path` | Print the config file location. |

## `openclaw mem version`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions tell the operator to delete the existing extension directory before reinstalling, but the destructive nature of the step is not prominently warned at the point of action. This can cause loss of local modifications, break the plugin state, and make rollback harder if the replacement package is invalid or malicious.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cli.md (reported line 68)May include surrounding context.

md
# 2. Wipe the existing extension dir and extract the tarball in place
rm -rf ~/.openclaw/extensions/claw-mem
mkdir -p ~/.openclaw/extensions/claw-mem
tar -xzf /tmp/chainofclaw-claw-mem-<v>.tgz \
    -C ~/.openclaw/extensions/claw-mem --strip-components=1

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/config.md (reported line 35)May include surrounding context.

md
Observer ignores these tool names entirely — they produce no observation. Useful for:
- Meta-tools that don't produce domain knowledge (`TodoWrite`, `AskUserQuestion`, `Skill`)
- Read-only exploration that would flood memory (`Read`, `Glob` — consider adding these for large codebases)

## Umbrella composition (for the full claw-mem binary)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document describes automatic capture of per-tool-call structured data and storage into persistent tables and an FTS index, but it does not mention user notice, consent, minimization, or retention controls at the point of collection. This creates a real privacy and security risk because tool-call content may contain sensitive prompts, file paths, code details, or secrets that are retained and searchable beyond the immediate session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that stored memory context is injected as a system-message-level prefix for future prompts, but does not warn that prior session content can silently influence later model behavior. This is dangerous because persisted content can become a privileged instruction source, enabling cross-session prompt injection, stale or misleading context, and unintended propagation of sensitive information into future interactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The end-of-session summarization stores user requests, investigation details, outcomes, and notes in a persistent summaries table without any explicit retention warning. Because these summaries are higher-priority memory for future sessions, they can preserve sensitive user intent and operational details long-term and increase the blast radius of accidental disclosure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This section states that stored memory is literally prepended to future prompts, but provides no warning that untrusted or sensitive stored content can be reinjected into model context. In an agent setting, this increases the risk of prompt injection persistence, unintended disclosure of prior data, and propagation of malicious instructions across sessions if memory is not sanitized and scoped carefully.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example builds an observation from a tool call including toolInput and toolResult and then inserts it into storage. The documentation does not warn that potentially sensitive file paths or file contents from tool output may be stored for later retrieval.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

L081-L085 present the skill as requiring no further setup and only one relevant environment variable. But L089 later documents an ANTHROPIC_API_KEY environment variable and direct Anthropic SDK mode, which means the earlier statement is not universally true. This creates a documentation-level divergence about the skill's configuration surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents opening a database at a filesystem path and states that db.open() runs pending migrations on first call, which can modify local state. The section does not include any user warning or disclosure that using these examples will create or alter a local database file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
references/cli.md:67