T02 · Agent Memory Poisoning
- Location
references/observer.md:3- Finding
Persistent Prompt Injection Through Automatically Recalled Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed persistent memory plugin, but it asks users to install code with safety checks bypassed and broadly stores and reinjects chat/tool history by default.
Install only if you intentionally want long-lived agent memory. Pin and verify the npm package, avoid the manual bypass path unless you trust the source and environment, disable prompt injection or make memory CLI-only for sensitive deployments, expand skipTools to exclude file/command outputs that may contain secrets, set retention pruning, and do not pair with on-chain/P2P backup for private or regulated data without strong encryption and deletion planning.
references/observer.md:3Persistent Prompt Injection Through Automatically Recalled Memory
references/cli.md:57Safety-Scan Bypass and Unverified Third-Party Package Installation
` | Dump observations + summaries + sessions to a JSON file. Flag: `--agent <id>` to scope. |
| `mem import <file>` | Load a previously exported file. Uses snake_case field names (matches SQLite schema). |
```
The default observer exclusion list is narrow:
```json
{
"enabled": true,
"dataDir": "~/.claw-mem",
"tokenBudget": 8000,
"maxObservations": 50,
"maxSummaries": 10,
"dedupWindowMs": 30000,
"skipTools": ["TodoWrite", "AskUserQuestion", "Skill"]
}
```
### Technical Analysis
The skill's
...[truncated 2777 chars]:3Broad Plaintext Retention and Export of Potentially Sensitive Agent Data
The core behavior is to capture conversations and tool-call chains into persistent storage and replay them into future prompts. That creates a substantial data-leak surface: sensitive content can be retained longer than intended, surfaced to later tasks via prompt injection of historical context, exposed through local DB access/export, or unintentionally transferred across sessions and users if tenancy boundaries are weak.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
Two flags are needed in practice — neither is "skip safety checks for fun":
The skill explicitly instructs storage of every user message and optionally assistant messages as long-lived memory for later retrieval. This broad capture model increases the chance that credentials, private instructions, proprietary code, personal data, or security-sensitive tool outputs will be indexed and later resurfaced to unrelated prompts or users, especially in shared-agent or poorly segmented deployments.
The documentation promotes optional on-chain/P2P backup and cross-device recovery without an equally prominent warning that memory snapshots may leave the local machine, become broadly replicated, and be difficult or impossible to delete completely. If sensitive conversation history is uploaded to decentralized or immutable systems, confidentiality, data minimization, and deletion obligations may be irreversibly undermined.
The documentation explicitly instructs users to bypass OpenClaw's normal plugin installation pipeline and its static child_process scan. That removes a security control intended to detect dangerous behavior before installation, increasing the chance that a malicious or tampered plugin is installed unchecked.
This is a concrete destructive shell command embedded in the documentation. Even though the path is more specific than rm -rf ~, documentation that normalizes irreversible deletion can be misused or mistakenly adapted, especially when paired with instructions to bypass the platform's install safeguards.
npm pack --pack-destination /tmp # → /tmp/chainofclaw-claw-mem-<v>.tgz
# 2. Wipe the existing extension dir and extract the tarball in place
rm -rf ~/.openclaw/extensions/claw-mem
mkdir -p ~/.openclaw/extensions/claw-mem
tar -xzf /tmp/chainofclaw-claw-mem-<v>.tgz \
-C ~/.openclaw/extensions/claw-mem --strip-components=1
This is a concrete destructive shell command embedded in the documentation. Even though the path is more specific than rm -rf ~, documentation that normalizes irreversible deletion can be misused or mistakenly adapted, especially when paired with instructions to bypass the platform's install safeguards.
npm pack --pack-destination /tmp # → /tmp/chainofclaw-claw-mem-<v>.tgz
# 2. Wipe the existing extension dir and extract the tarball in place
rm -rf ~/.openclaw/extensions/claw-mem
mkdir -p ~/.openclaw/extensions/claw-mem
tar -xzf /tmp/chainofclaw-claw-mem-<v>.tgz \
-C ~/.openclaw/extensions/claw-mem --strip-components=1
L003 says the skill 'works fully on its own with no chain interaction and no external services.' However, the same file later states session summaries default to spawning openclaw infer model run and can also be configured to call Anthropic directly with an API key. That is an active contradiction in the documented behavior, not merely an omitted detail.
The skill persistently stores all chat and tool-call history by default, but the documentation does not present a prominent privacy warning or consent-oriented guidance up front. In practice, this can cause operators or users to unknowingly retain secrets, credentials, personal data, or regulated information in long-lived storage, increasing exposure in case of host compromise, debugging, export, or later retrieval.
Encouraging backup, recovery, and 'digital immortality' for captured memory increases the persistence and distribution of sensitive historical data beyond the original host. Even if optional, this framing normalizes broad retention and replication of conversation history, which magnifies the blast radius of accidental capture or compromise.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
|---|---|
| `config list` | Print the full effective config. Flags: `--from-disk`, `--section <name>`. |
| `config get <path>` | Read a dotted key (e.g. `tokenBudget`, `summarizer.mode`). Flags: `--json`, `--from-disk`. |
| `config set <path> <value>` | Write a key to `~/.claw-mem/config.json`. String-coercion is careful not to stringify hex keys or URLs. Flag: `--json` (treat value as JSON). |
| `config path` | Print the config file location. |
## `openclaw mem version`
The instructions tell the operator to delete the existing extension directory before reinstalling, but the destructive nature of the step is not prominently warned at the point of action. This can cause loss of local modifications, break the plugin state, and make rollback harder if the replacement package is invalid or malicious.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 2. Wipe the existing extension dir and extract the tarball in place
rm -rf ~/.openclaw/extensions/claw-mem
mkdir -p ~/.openclaw/extensions/claw-mem
tar -xzf /tmp/chainofclaw-claw-mem-<v>.tgz \
-C ~/.openclaw/extensions/claw-mem --strip-components=1
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
Observer ignores these tool names entirely — they produce no observation. Useful for:
- Meta-tools that don't produce domain knowledge (`TodoWrite`, `AskUserQuestion`, `Skill`)
- Read-only exploration that would flood memory (`Read`, `Glob` — consider adding these for large codebases)
## Umbrella composition (for the full claw-mem binary)
The document describes automatic capture of per-tool-call structured data and storage into persistent tables and an FTS index, but it does not mention user notice, consent, minimization, or retention controls at the point of collection. This creates a real privacy and security risk because tool-call content may contain sensitive prompts, file paths, code details, or secrets that are retained and searchable beyond the immediate session.
The skill states that stored memory context is injected as a system-message-level prefix for future prompts, but does not warn that prior session content can silently influence later model behavior. This is dangerous because persisted content can become a privileged instruction source, enabling cross-session prompt injection, stale or misleading context, and unintended propagation of sensitive information into future interactions.
The end-of-session summarization stores user requests, investigation details, outcomes, and notes in a persistent summaries table without any explicit retention warning. Because these summaries are higher-priority memory for future sessions, they can preserve sensitive user intent and operational details long-term and increase the blast radius of accidental disclosure or misuse.
This section states that stored memory is literally prepended to future prompts, but provides no warning that untrusted or sensitive stored content can be reinjected into model context. In an agent setting, this increases the risk of prompt injection persistence, unintended disclosure of prior data, and propagation of malicious instructions across sessions if memory is not sanitized and scoped carefully.
The example builds an observation from a tool call including toolInput and toolResult and then inserts it into storage. The documentation does not warn that potentially sensitive file paths or file contents from tool output may be stored for later retrieval.
L081-L085 present the skill as requiring no further setup and only one relevant environment variable. But L089 later documents an ANTHROPIC_API_KEY environment variable and direct Anthropic SDK mode, which means the earlier statement is not universally true. This creates a documentation-level divergence about the skill's configuration surface.
This markdown file documents opening a database at a filesystem path and states that db.open() runs pending migrations on first call, which can modify local state. The section does not include any user warning or disclosure that using these examples will create or alter a local database file.
Detected: suspicious.destructive_delete_command