Back to skill

Security audit

VectorClaw

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed self-hosted memory database skill, but it needs Review because it persistently profiles sensitive user data and several promised safeguards are incomplete or contradicted by the artifacts.

Install only after a careful Review. Disable auto-extraction, mood tracking, engagement tracking, and heartbeat jobs until each user has recorded opt-in consent; fix setup credential handling and SQL input validation; pin and verify the container image; and add real retention, audit, and deletion enforcement before storing sensitive conversations or reasoning logs.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (9)

T09 · Insecure Skill Coding Practices

Error
Location
vector_claw_setup.sh:39
Finding

Root-Context SQL Injection in the Setup Wizard

Content
View full analysis
/dev/null ``` ### Technical Analysis The wizard interpolates the user-controlled database username, password, and database name directly into a SQL program executed by the MySQL root account. These values are checked only for emptiness. They are not escaped as SQL literals, and the database identifier is not validated against a safe identifier syntax. A single quote in `MYSQL_USER` or `MYSQL_PASSWORD` can terminate the surrounding SQL literal. The remaining input may then introduce arbitrary SQL statements. `DB_NAME` is even more directly exposed because it is inserted as an unquoted identifier. Shell quoting does not prevent this vulnerability: the shell constructs one `-e` argument, after which MySQL parses attacker-controlled content as SQL. ### Attack Path 1. An attacker gains the ability to supply or influence an interactive setup value. 2. The attacker enters a value containing SQL delimiters and additional statements. 3. The value is embedded into the root SQL program without safe quoting. 4. `docker exec` invokes the MySQL client as root. 5. MySQL executes the injected statements with full database-server privileges. ### Impac ...[truncated 620 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
vector_claw_setup.sh:74
Finding

Database Passwords Exposed in Process Arguments and Docker Metadata

Content
View full analysis
/dev/null ``` ```bash VERIFY=$(docker exec "$CONTAINER_NAME" mysql -u "$MYSQL_USER" -p"$MYSQL_PASSWORD" "$DB_NAME" -e "SELECT 1 as connected;" 2>/dev/null) ``` ```bash docker exec -i "$CONTAINER_NAME" mysql -u root -p"$MYSQL_ROOT_PASS" "$DB_NAME" < create_user_tables.sql 2>/dev/null ``` ```bash TABLE_COUNT=$(docker exec "$CONTAINER_NAME" mysql -u "$MYSQL_USER" -p"$MYSQL_PASSWORD" "$DB_NAME" -e "SELECT COUNT(*) FROM information_schema.tables WHERE table_schema='${DB_NAME}';" 2>/dev/null | tail -1) ``` ### Technical Analysis Both root and application passwords are passed as `-pPASSWORD` command-line arguments. Depending on host configuration, command arguments can be observed through process inspection, monitoring agents, audit systems, or `/proc`. The root password is additionally supplied using `MYSQL_ROOT_PASSWORD` in the Docker container environment. Container environment values are generally available to users or services with Docker inspection privileges and remain associated with the container configuration after installation. This directly contradicts the script header’s claim that passwords are never placed on the command line. ### Attack Path 1. An operator runs the setup wizard. 2. The wizard starts MySQL client processe ...[truncated 717 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
sql_safe_exec.sh:159
Finding

Regular-Expression SQL Parsing Permits Write-Allowlist Bypass

Content
View full analysis
&2 exit 1 fi ALLOWED=false for t in "${ALLOWED_WRITE_TABLES[@]}"; do if [ "$TABLE_NAME" = "$t" ]; then ALLOWED=true break fi done if ! $ALLOWED; then echo "ERROR: Table '$TABLE_NAME' is not in the write allowlist." >&2 echo "Allowed tables: ${ALLOWED_WRITE_TABLES[*]}" >&2 exit 1 fi fi ``` ```bash if echo "$SQL" | grep -iqE "\b(INSERT|UPDATE|DELETE|REPLACE)\b"; then echo "WARNING: Modifying data: $SQL" read -p "Confirm? (yes/no): " ans [ "$ans" != "yes" ] && echo "Aborted." && exit 0 fi $MYSQL_CMD "$SQL" ``` ### Technical Analysis The authorization boundary extracts only the first table-like token matched by a regular expression and compares that single value to an allowlist. SQL is not a regular language suitable for reliable authorization with this parser. MySQL supports multi-table updates, multi-table deletes, joins, nested queries, and common table expressions. Such statements can reference or modify more than one table. If the first regular-expression match names an allowlisted table, additional write targets are not validated. The database account is granted `INSERT`, `UPDATE`, and `DELETE` over the entire `mysqlclaw` schema. Therefore, the database privilege layer does not compensate for the parser weakness. ### Attack Path 1. An attacker obtains access to an agent-facing raw SQL op ...[truncated 811 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
upgrade_v5.0.0_to_v5.0.1.sql:30
Finding

Sensitive Mood and Engagement Tracking Enabled Without Recorded Consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
upgrade_v5.0.0_to_v5.0.1.sql:48
Finding

Retention and Audit Guarantees Are Defined but Not Enforced

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
rollback_user.sql:44
Finding

Promised Full User Deletion Leaves Identifiable and Inferred Data Behind

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
SETUP_GUIDE.md:9
Finding

Unnecessary Host MySQL Service Is Installed and Enabled at Boot

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
SETUP_GUIDE.md:254
Finding

Persistent Heartbeat Jobs Reference Scripts Absent from the Audited Package

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
vector_claw_setup.sh:71
Finding

Privileged Database Container Uses a Mutable Unpinned Image Tag

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (102)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SETUP_GUIDE.md (reported line 11)May include surrounding context.

bash
# Install MySQL server
sudo apt update && sudo apt install -y mysql-server

# Run secure installation (set root password, remove anonymous users, etc.)
sudo mysql_secure_installation

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The guide instructs users to place database credentials in a plaintext .env file inside the skill workspace. Even with restrictive permissions, plaintext secrets in a working directory are vulnerable to accidental disclosure through backups, logs, shell history, agent tooling, or repository mishandling.

Content

Scanner excerpt · SETUP_GUIDE.md (reported line 120)May include surrounding context.

bash
cd ~/.openclaw/workspace/skills/mysqlclaw

# Set up .env with your credentials
cat > .env << 'EOF'
MYSQL_USER=mysqlclaw
MYSQL_PASSWORD=YourStrongLeastPrivPasswordHere456!

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This line is part of the same plaintext secret creation flow and includes a sample password placement pattern that may encourage unsafe credential handling. In agent-operated environments, workspace files may be broadly readable by tools or inadvertently surfaced to other components.

Content

Scanner excerpt · SETUP_GUIDE.md (reported line 121)May include surrounding context.

md
cd ~/.openclaw/workspace/skills/mysqlclaw

# Set up .env with your credentials
cat > .env << 'EOF'
MYSQL_USER=mysqlclaw
MYSQL_PASSWORD=YourStrongLeastPrivPasswordHere456!
MYSQL_HOST=localhost

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Although chmod 600 reduces exposure, this line confirms reliance on a local .env credential file as the primary secret storage mechanism. The context lowers risk somewhat because permissions are tightened, but the underlying plaintext secret handling remains a real exposure concern.

Content

Scanner excerpt · SETUP_GUIDE.md (reported line 128)May include surrounding context.

md
MYSQL_PORT=3310
DATABASE=mysqlclaw
EOF
chmod 600 .env

# Run the setup wizard
./setup_wizard.sh

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

Telling users to export database credentials in .bashrc or similar shell startup files can leak secrets to local account compromise, debugging output, process environments, and long-lived shell history or dotfile sync workflows. Persisting credentials in shell config is especially risky because it broadens exposure duration and scope.

Content

Scanner excerpt · SETUP_GUIDE.md (reported line 310)May include surrounding context.

Set up your environment:

bash
# Add to your .bashrc or .env file
export MYSQL_USER=mysqlclaw
export MYSQL_PASSWORD=<your_least_priv_password>
export MYSQL_HOST=127.0.0.1

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill is designed to persistently collect and infer a broad set of highly sensitive personal data, including health, emotional state, relationships, behavioral profiling, and inferred traits. Even with consent language, this level of surveillance and profiling greatly expands the attack surface and potential harm from misuse, breach, over-collection, or inaccurate inference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill documentation directly states that internal agent reasoning / chain-of-thought is stored with user data. This is dangerous because chain-of-thought may include latent secrets, private user-derived conclusions, and sensitive system reasoning that should not be retained or exposed through normal data-access paths.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly states that it stores agent reasoning logs / chain-of-thought alongside highly sensitive user profile data. Persisting internal reasoning materially increases privacy and security risk because it can capture secrets, sensitive intermediate inferences, policy artifacts, or other data never intended for storage, and these records become available to anyone who gains database access.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The auto-extraction pipeline is explicitly intended to harvest conversation content into persistent memory stores, including inferred facts and graph-linked relations. In this context, the danger is not classic code execution but mass privacy intrusion and durable storage of sensitive conversational data at scale, which amplifies harm if the system is misconfigured, overbroad, or later compromised.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · changelog.md (reported line 14)May include surrounding context.

md
d respects [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [5.0.0] – 2026-05-27

### Added — MyVector Self-Sufficiency: Auto-Extraction + Knowledge Graph

This release makes MyVector self-sufficient by absorbing Mem0's auto-extraction and Hancho's knowledge graph reasoning into native MySQL systems.

**Auto-Extraction Hook (`scripts/auto-extract.py`):**
- Uses local qwen3.5:4b model with structured JSON prompt to extract atomic facts from conversation text
- Extracts: core_fact, confidence (0-1), entities[], linked_to[], tags[], memory_type, importance
- Key mapping normalizes LLM output (handles "fact" → "core_fact", invalid memory_types → "semantic")
- Auto-dedup on insert: Jaccard similarity check against existing memories, merges if >50% overlap
- Auto-discovers relations: finds existing memories sharing entities, creates edges in `memory_relations` table
- Source tracking: marks auto-extracted memories with `source='auto'` for quality monitoring
- Fallback

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · changelog.md (reported line 355)May include surrounding context.

md
### Added — New Security Controls

- **Comment injection blocking.** `sql_safe_exec.sh` now rejects SQL containing `/*`, `*/`, `--` followed by whitespace, or `#` followed by whitespace. This prevents attackers from using comments to truncate SQL and bypass security checks.

- **Hex-encoded string detection.** `sql_safe_exec.sh` now rejects SQL containing `0x` followed by hex digits, `UNHEX(`, or `HEX(`. This prevents encoding-based bypasses of the escaping system.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · changelog.md (reported line 355)May include surrounding context.

md
### Added — New Security Controls

- **Comment injection blocking.** `sql_safe_exec.sh` now rejects SQL containing `/*`, `*/`, `--` followed by whitespace, or `#` followed by whitespace. This prevents attackers from using comments to truncate SQL and bypass security checks.

- **Hex-encoded string detection.** `sql_safe_exec.sh` now rejects SQL containing `0x` followed by hex digits, `UNHEX(`, or `HEX(`. This prevents encoding-based bypasses of the escaping system.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema enables extensive profiling of users through mood, engagement patterns, activity heatmaps, relationships, reminders, topic indexing, and inferred preferences without any indication of consent, minimization, or disclosure. In the context of an agent skill, this is more dangerous because these tables support persistent cross-session surveillance and inference about sensitive personal and behavioral traits.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

A thought-stream reasoning log tied to user_id, channel_id, and related interactions risks storing internal deliberations, inferred sensitive attributes, and raw user-linked mental models that should not be retained. This is especially dangerous in an agent skill because such logs can expose hidden prompts, sensitive user data, and speculative or unsafe inferences if accessed, leaked, or repurposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script performs irreversible bulk deletion across many user-scoped tables and relies on manual placeholder replacement and external execution without any built-in confirmation, guardrails, or transaction safety visible in the file. In an agent or operational workflow, that makes accidental execution, wrong-user targeting, or misuse much more likely, leading to large-scale loss of user data.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CAPABILITIES.md (reported line 33)May include surrounding context.

md
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

md
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

md
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · changelog.md (reported line 515)May include surrounding context.

md
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sql_safe_exec.sh (reported line 17)May include surrounding context.

sh
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · sql_safe_exec.sh (reported line 27)May include surrounding context.

sh
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · updated_SKILL.md (reported line 20)May include surrounding context.

md
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · vector_claw.sh (reported line 32)May include surrounding context.

sh
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · vector_claw.sh (reported line 38)May include surrounding context.

sh
#   - Table allowlist enforced for all write operations (26 approved tables)
#   - Path traversal / sensitive file patterns blocked
#   - Credentials via temporary --defaults-extra-file (password never on command line)
#   - .env file parsed as KEY=VALUE (never shell-sourced)
#   - Comment injection blocked (/* */ and -- style)
#   - Hex-encoded string detection blocked
#   - Temp credentials file cleaned up on ANY exit

Static analysis

No suspicious patterns detected.