Back to skill

Security audit

Openclaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent persistent-memory tool, but its setup asks users or agents to run unverified remote installers and may expose a local memory server on the network.

Review this before installing. Prefer a pinned, checksum-verified Demarkus installer or inspect the downloaded script manually before running it. Use remote mode only with a server you trust, avoid storing secrets or private user data in journals, and configure any local server to bind to localhost with no firewall opening unless you explicitly need network access.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:25
Finding

Unverified Remote Installer Executed for Full-Stack Installation

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:53
Finding

Unverified Remote Installer Executed for Client-Only Installation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:81
Finding

Unpinned Package Download and Execution Through npx

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:148
Finding

Local Server Exposed on All Interfaces with Automatic Firewall Modification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (11)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to fetch and execute a remote shell installer via curl ... | bash, which gives unaudited code immediate execution on the host. This is especially risky because the capability is introduced during setup for a memory tool, making the privilege expansion unjustified and easy to abuse through upstream compromise.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash pattern chains network retrieval directly into shell execution, eliminating the opportunity for inspection and magnifying the impact of any upstream compromise. In the context of an agent skill, this is especially dangerous because it encourages automated execution of remote code on behalf of the user.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

If not found, install the full stack (client, server, MCP binary, daemon):

bash
curl -fsSL https://raw.githubusercontent.com/latebit-io/demarkus/main/install.sh | bash

Store the token and register demarkus-mcp with mcporter:

Context Leakage

High
Category
Data Exfiltration
Confidence
97% confidence
Finding

The journaling guidance tells the agent to record session notes, key decisions, and what it learned, which encourages persistence of conversation context into long-lived storage. In a memory skill, that materially increases the risk of leaking secrets, personal data, or proprietary information across sessions or to a remote server.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
### Journaling

Use `demarkus.mark_append` to record session notes, key decisions, and what you learned. Each entry should include a date and a brief summary. This is your running log — append freely, never overwrite.

### Thoughts and Reflections

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are unusually broad, including requests to remember things across sessions, store thoughts, reflections, or 'give the agent a soul.' This increases the chance the skill activates in unrelated contexts and captures or persists sensitive data that the user did not intend to store.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's stated purpose is memory/document storage, but the local setup installs and runs a full server stack exposed on all interfaces and opens a firewall port. That grants unnecessary network-facing capability and increases attack surface far beyond what is required for simple local persistence.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The Linux setup uses sudo cat /etc/demarkus/initial-token.txt, introducing privileged execution into an agent-driven flow. Even though the command is limited, normalizing sudo use in setup increases risk and can expose sensitive tokens to broader shell history, logs, or misuse in adjacent steps.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
if [ "$(uname)" = "Darwin" ]; then
  TOKEN=$(cat ~/.demarkus/initial-token.txt)
else
  TOKEN=$(sudo cat /etc/demarkus/initial-token.txt)
fi

demarkus token add mark://localhost "$TOKEN"

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

Using npx -y mcporter without pinning a version allows whatever package version is current at execution time to be fetched and run. That creates a supply-chain risk and makes behavior non-deterministic, especially in a skill that configures a bridge used for persistent memory operations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill is explicitly designed for session persistence and versioned storage, so persistence itself is intentional rather than deceptive. However, in security terms it is still a real risk because it enables accumulation of sensitive data over time and broadens the consequences of accidental or malicious writes.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
## Tools

- `demarkus.mark_fetch` — read a document
- `demarkus.mark_publish` — write or update (fetch first, use returned version as expected_version)
- `demarkus.mark_append` — append content, no fetch required
- `demarkus.mark_list` — list documents and directories
- `demarkus.mark_versions` — full version history

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The privacy section claims no data is sent to third parties, but the documented workflow downloads installer code from GitHub and supports remote servers explicitly provided by the user. This mismatch can mislead users and agents about trust boundaries, causing sensitive data to be handled under false assumptions.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

Fetching an external script from GitHub and executing it directly introduces a classic supply-chain risk. If the repository, branch, delivery path, or transit controls are compromised, arbitrary code can run on the target machine during setup.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

If not found, install the full stack (client, server, MCP binary, daemon):

bash
curl -fsSL https://raw.githubusercontent.com/latebit-io/demarkus/main/install.sh | bash

Store the token and register demarkus-mcp with mcporter:

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Even in client-only mode, the skill still uses a remote fetched installer script piped to bash. Although the attack surface is somewhat smaller than the full-stack install, it still allows arbitrary code execution from an external source without verification.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

Install the client binaries (no server, no daemon):

bash
curl -fsSL https://raw.githubusercontent.com/latebit-io/demarkus/main/install.sh | bash -s -- --client-only

Store the token and register demarkus-mcp with mcporter:

Static analysis

No suspicious patterns detected.