Back to skill

Security audit

Agent Memory Protocol

Security checks for vulnerabilities and agentic risk

Overview

This memory-management skill is mostly coherent, but it can persist personal, project, and agent-behavior data too automatically and with too little user control.

Review this before installing in any workspace with sensitive conversations or project data. Use it only if you want durable agent memory, narrow the triggers to explicit commands, require approval before writes, avoid storing secrets or regulated personal data, pin and review external tools, and define deletion and audit procedures for memory, blackboard, lcm.db, and .learnings records.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
MEMORY-STACK.md:50
Finding

Unpinned Global Installation of Third-Party Memory Components

Content
View full analysis

Vulnerability Details

File Location: MEMORY-STACK.md:50-57 and MEMORY-STACK.md:148-152
Vulnerability Type: Supply-chain exposure through mutable, globally installed dependencies
Risk Level: Medium

Vulnerable Code

bash
### Installation

# Install via bun (recommended)
bun install -g @tobilu/qmd

# Or via npm
npm install -g @tobilu/qmd
bash
### Installation

# Install via OpenClaw plugin system
openclaw plugins install @martian-engineering/lossless-claw

Equivalent unpinned commands also appear in MEMORY-STACK.zh-CN.md:50-57 and MEMORY-STACK.zh-CN.md:148-152.

Technical Analysis

The installation instructions retrieve mutable package versions without specifying an audited version, lockfile, integrity hash, or immutable source revision. The qmd package is installed globally, while LosslessClaw is installed as an OpenClaw plugin.

These components operate on security-sensitive data:

  • qmd indexes files under memory/ and blackboard/.
  • LosslessClaw processes historical conversations and stores summaries in ~/.openclaw/lcm.db.
  • The plugin executes within the OpenClaw environment and therefore inherits the permissions granted to that environment.

The project does not itself contain a malicious dependency. The vulnerability is that following the documented commands resolves whatever package release is current at installation time. A registry compromise, maintainer-account compromise, or malicious future release could therefore change the code executed after this Skill was reviewed.

Attack Path

  1. An attacker compromises the registry package, its publisher account, or the upstream release process.
  2. The attacker publishes a malicious release under the legitimate package name.
  3. A user follows the documented unversioned installation command.
  4. The package manager resolves and installs the attacker-controlled release.
  5. The malicious package ex ...[truncated 1083 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every package to a reviewed exact version, for example package@x.y.z.
  2. Publish expected package integrity hashes or use a lockfile that records integrity metadata.
  3. Pin plugin installation to an immutable release or commit when the plugin system supports it.
  4. Avoid global package installation where possible. Run the indexer in a dedicated environment with access only to explicitly selected directories.
  5. Document the exact filesystem and network permissions required by each component.
  6. Run third-party plugins under a restricted service account or sandbox without access to unrelated OpenClaw configuration and credentials.
  7. Establish an upgrade-review procedure rather than automatically consuming the latest package release.
  8. Verify package ownership, provenance, signatures, and registry namespace before installation.

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:187
Finding

Untrusted Conversation Content Can Be Promoted into Persistent Agent Behavior

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:187-218, with mandatory persistence rules at SKILL.md:13-15 and SKILL.md:253-257
Vulnerability Type: Persistent memory poisoning through insufficient trust and provenance controls
Risk Level: Medium

Vulnerable Code

markdown
### Session Reflection

At session end (/new, idle reset, or user actively switches), if the session contained any of the following, **extract one pattern**:

| Trigger | Reflection content | Write to |
|---------|-------------------|----------|
| User corrected a behavior | "Next time X occurs, do Y" | `memory/agent/patterns/` or `.learnings/` |
| A plan failed and was replaced | "Plan X failed because A; switched to Y" | `memory/agent/patterns/` |
| Discovered a hidden tool/config gotcha | "When using X, watch out for Y" | `memory/agent/patterns/` or TOOLS.md |
| Found a better approach than what docs say | "Better approach for X is Y" | `memory/agent/patterns/` |

**Format**:
```markdown
## [YYYY-MM-DD] Title
- **Trigger**: what situation was encountered
- **Lesson**: one-sentence conclusion
- **Next time**: specific action guidance

When reflection is NOT needed: pure execution tasks, no corrections, no surprises, routine CRUD.

Relationship to Instinct: Reflection written to patterns/ is low-barrier recording. When the same entry is triggered ≥3 times, promote to a YAML instinct in .learnings/instincts/ (see AGENTS.md §4).

text

The scope is expanded by the all-agent rule at `SKILL.md:13-15`:

```markdown
> ⚠️ **All-Agent Protocol**: This protocol applies to all agents in the system.
> Any agent completing a subtask that produces persistable information must write it according to this spec. Do not create memory files outside this structure.

Sub-agents are also directed to write persistent information directly at SKILL.md:253-257:

markdown
## Sub-Agent Write Rules

When any sub
...[truncated 3210 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat all conversational, retrieved, and document-derived text as untrusted unless it is explicitly authenticated as an authorized user instruction.
  2. Require explicit user confirmation before persisting behavioral rules or promoting patterns into instincts.
  3. Never use repetition alone as a trust signal. Require independent validation and security review.
  4. Record provenance for every entry, including source session, source type, author identity, trust level, and supporting evidence.
  5. Separate descriptive memories from executable behavioral guidance. Do not automatically interpret stored prose as instructions.
  6. Restrict direct writes by sub-agents. Route proposed patterns through an orchestrator-controlled review queue.
  7. Add allowlisted schemas for instinct files and reject entries that request credential access, security-control changes, external execution, or expanded permissions.
  8. Add expiration, versioning, rollback, and audit-log support for patterns and instincts.
  9. Deduplicate by trusted source identity and semantic content so an attacker cannot trigger promotion through superficial repetition.
  10. Provide users with commands to inspect, approve, reject, and permanently delete stored behavioral records.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (21)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The configuration instructs operators to use an external summarization provider for conversation compaction, which can transmit conversation content off-host to a third party. Without an explicit warning, data-classification guidance, or consent requirement, sensitive prompts, personal data, secrets, or proprietary information could be disclosed to the external provider unintentionally.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger set is overly broad for a persistence-capable skill, making activation likely during normal conversation rather than only during deliberate memory operations. Overbroad auto-activation increases the risk of unintended data capture, persistence, and cross-scope side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The phrase 'remember this' is common natural language and can easily appear in ordinary conversation, causing accidental activation of a skill that writes persistent state. In a memory-management context, that makes unintended retention of sensitive or low-quality information more likely.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
pdate to existing info | Append to end of file with date stamp |
| Conflicts with existing | Add "updated" note after existing entry, append new version |
| Entirely new info | Create new file or append to appropriate category |
| events / cases | Always create new file, never modify existing |

### Prohibited Actions
- ⚠️ The `memory/` root dir may hold current-week session logs (≤7 days); crontab auto-archives to `memory/archive/YYYY-MM/` on the 1st of each month. Non-log files (profile/preferences/entities/events/cases/patterns) must go in their L2 category directories
- ❌ Do not write stream-of-consciousness directly to MEMORY.md
- ❌ Do not modify existing files under events/ or cases/

---

## L0 Sync Rules (MEMORY.md)

MEMORY.md is the L0 index; keep it under 30 lines.

**When to update MEMORY.md:**
1. New events or cases file added → add a one-line pointer in the relevant block
2. Key patterns have major changes → update the summary sentence
3. User basic info has

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document explicitly describes retaining structured memory files and compressed conversation history, but it does not warn operators that user content may be persisted, indexed, and later retrieved. In a memory-management skill, that omission is security-relevant because users and deployers may unknowingly store sensitive data long-term, increasing privacy, retention, and unauthorized access risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explains that conversation history is compressed and stored in a local SQLite database, but it does not clearly warn users that potentially sensitive session content will be retained on disk. In a memory-management skill, this omission is more dangerous because the feature is specifically designed to capture and preserve user interactions, increasing the risk of unnoticed long-term storage of secrets, personal data, or confidential project information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes structured storage of user identity, habits, projects, and decisions but does not warn about privacy, retention, or consent implications. This omission is dangerous because operators may deploy the skill in ways that persist sensitive data indefinitely without user awareness, minimization, or deletion procedures.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The write specification explicitly instructs agents to persist user identity, preferences, entities, events, and agent patterns across sessions, creating durable session memory. In the context of an auto-activating memory skill, this increases the chance of silent accumulation of sensitive behavioral and personal data, especially when combined with broad triggers and no privacy safeguards.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

Retrieval cost scales with need: L0 is always fast; only drill to L2 when you need the detail.

Six-Category Write Spec

text
New information → classify

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares automatic activation for any memory-related operation, which is overly broad for a capability that can persist user and agent data. In practice this can cause the protocol to trigger on ambiguous prompts and normalize storage of information without clear user intent, increasing the risk of unwanted persistence and privacy-sensitive writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Trigger phrases like 'remember this' and 'update memory' are generic conversational language and can easily appear in normal dialogue, causing accidental activation. Because this skill governs persistent memory operations, unintended invocation can lead to unauthorized retention of personal, project, or behavioral data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes structured memory writes, file updates, and long-term retention of user-related information, but it does not clearly warn that this data will be stored persistently on disk. Users may disclose sensitive personal, behavioral, or project information without understanding it will be retained and later retrieved, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states the skill auto-activates for memory-related operations, but it does not define strict triggers, scope limits, or consent boundaries. In a memory-management skill, ambiguous activation can cause the agent to persist or update memory during ordinary conversation without clear user intent, increasing the risk of unauthorized retention of sensitive data.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
84% confidence
Finding

The trigger phrase 'update memory' can overlap with built-in or adjacent command semantics around 'update', creating ambiguity about which handler should execute. In a write-capable skill, command shadowing can cause unintended activation and persistent changes in the wrong context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document establishes a constrained memory structure, then later instructs writes to .learnings/ and TOOLS.md, contradicting its own boundary rules. Contradictory storage rules make it easier for an attacker or faulty workflow to justify writes outside approved locations, undermining containment and auditability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to Trigger' section uses vague terms like 'or similar' and broad session/event conditions, leaving substantial room for interpretation. Ambiguous activation criteria are dangerous here because the skill performs persistent writes, so unclear triggering directly translates into over-collection and unintended state changes.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages immediate persistence of user, project, tool, and preference information during normal conversation flow, not just after explicit consent. This creates a substantial risk of storing sensitive natural-language content in long-term memory by default, including data the user may not expect to be retained.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill’s declared scope is memory management, but it also instructs agents to update separate blackboard project-tracking files. This expands the skill’s authority beyond its manifest and can cause unintended writes to other state stores, increasing the chance of integrity issues and unauthorized persistence.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The classification flow explicitly directs storage of user identity, background, habits, and other personal data in persistent memory files. That is risky because it normalizes long-term retention of personal information without clearly requiring necessity, consent, minimization, or retention controls.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The archival/compression and session-transition behavior goes beyond simple memory management and introduces additional persistence and summarization actions. That broader behavior can capture and retain more conversation state than expected, creating privacy and integrity risks through silent scope expansion.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The flush checklist instructs the agent to scan the conversation and extract preferences, decisions, project details, entities, and corrections into persistent storage. That kind of systematic end-of-session scraping is especially dangerous because it can silently transform broad conversational content into long-term memory without a clear user request each time.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Directing the agent to write behavioral corrections into .learnings/LEARNINGS.md extends the skill into behavioral modification and persistent agent steering, which is outside the stated memory-manager purpose. Persistent storage of corrections can be abused to plant long-lived instructions or preferences that influence future behavior without proper review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.