Back to skill

Security audit

memory-tencentdb

Security checks for vulnerabilities and agentic risk

Overview

This memory plugin has useful disclosed memory features, but it also performs high-impact host patching and optional remote offload/tracing behavior that is broader and less clearly disclosed than the core purpose.

Install only if you are comfortable with this package modifying OpenClaw behavior and capturing long-term conversation memory. Review or disable the postinstall patch path, avoid backend/offload unless you trust the endpoint, do not use insecure HTTPS settings for sensitive data, set an explicit userId instead of IP fallback, and keep Opik/full-content tracing off unless you intentionally want conversations and tool payloads sent to that service.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (107)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

The supervisor launches a subprocess from a command string that can come from an explicit parameter or the MEMORY_TENCENTDB_GATEWAY_CMD environment variable. Although shell=True is not used, this still allows execution of an attacker-controlled binary or argument set if configuration or environment input is influenced, which is a meaningful command-execution risk in plugin/agent deployments.

Content

Scanner excerpt · hermes-plugin/memory/memory_tencentdb/supervisor.py (reported line 176)May include surrounding context.

python
stdout_target = subprocess.DEVNULL
                stderr_target = subprocess.DEVNULL

            self._process = subprocess.Popen(
                shlex.split(self._gateway_cmd),
                env=env,
                stdout=stdout_target,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code derives a persistent user identifier from the host's non-loopback IPv4 address when no explicit user ID is configured. That creates device-level tracking without clear user consent and sends infrastructure-identifying information to backend services, which is unnecessary for a memory plugin's core function.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The comment explicitly states the environment access layer exists to avoid static security scanner detection of credential harvesting patterns. Even if the functional use is mixed, deliberate concealment of env access in network-capable code is a strong red flag because it frustrates auditing and can hide secret exfiltration paths.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The tracing code serializes full message contents, prompts, tool inputs/results, and model responses and sends them to an external Opik backend. This can leak sensitive conversation data, files, credentials, or proprietary code to a third party far beyond the plugin's stated memory-storage purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The backend HTTP client sets rejectUnauthorized: false for HTTPS requests, which disables TLS certificate validation. That allows man-in-the-middle interception and modification of requests carrying conversation data, API keys, and backend control payloads.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
88% confidence
Finding

The plugin can generate and write new skill files to disk from conversation-derived data via backend-driven L4 generation. This creates a code/content supply-chain risk because untrusted model output can persist as executable or trusted plugin artifacts on the host.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module documentation claims zero external API dependencies while the code clearly performs multiple outbound API calls and telemetry transmissions. Misleading security-relevant documentation increases deployment risk because operators may enable the plugin under false assumptions about data locality.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module header claims all processing is local with zero external API dependencies, but the implementation conditionally enables a remote offload path and references a backend URL. This is dangerous because operators and users may rely on the documentation when deciding whether sensitive conversation data ever leaves the host, leading to uninformed deployment of a feature that can transmit stored memory data externally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest markets the package primarily as a local memory plugin, but it also exposes commands for exporting data to Tencent vector DB and migrating local SQLite memory into TencentDB. That discrepancy can mislead operators about where conversational memory may flow, increasing the risk of unintended data exfiltration or privacy-impacting deployment decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The package description does not disclose that installation triggers a postinstall shell script that patches host behavior. Undisclosed install-time modification is dangerous because it executes automatically in the consumer environment and can alter trusted tooling or runtime behavior before the user has reviewed the package contents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

A bash postinstall script executes automatically during package installation, which is a high-risk behavior for a memory plugin because it grants code execution on the host without an explicit runtime action by the user. Even if intended for benign patching, this expands the attack surface substantially and can be abused to modify local tools, persist changes, or tamper with security boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documented workflow includes pkill -f hermes-agent, which can terminate host agent processes based on a broad pattern match. Pattern-based killing is dangerous because it may stop unintended processes, cause denial of service, and disrupt the host environment outside the plugin's narrowly needed scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script can modify Hermes-wide state outside the plugin’s own directory, including ~/.hermes/config.yaml and ~/.hermes/env.d, which expands its authority beyond a narrow memory backend. Even though this is gated behind --hermes, it still lets the plugin alter global agent behavior and credential-loading paths, increasing blast radius if the script is invoked unexpectedly or by automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

source_user_envs() sources arbitrary shell fragments from /etc/profile.d, /etc/profile.d/hermes-env.sh, and every readable *.sh under ~/.hermes/env.d. Because sourcing executes shell code in-process, any malicious or compromised file in those locations gains code execution with the privileges of whoever runs this control script.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

resolve_gateway_cmd() accepts MEMORY_TENCENTDB_GATEWAY_CMD from the environment, and cmd_start() executes it via eval. This permits shell metacharacter injection and arbitrary command execution, so any attacker who can influence that environment variable can run unrelated commands under the operator’s account.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code intentionally renders absolute filesystem paths into a navigation section so the agent can call read_file directly. Exposing internal absolute paths leaks host filesystem structure and expands the agent's effective file-access knowledge beyond what a memory indexing feature needs, which can aid unintended file reads or prompt-driven data exfiltration if the agent is induced to follow those paths.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The comments and generated content present this as a summary/navigation feature, but the implementation embeds absolute paths specifically to enable direct file reads by the agent. That design increases the agent's operational access surface in a way that is not necessary for summarization, making prompt abuse or accidental overreach more likely in a memory plugin context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script modifies the host OpenClaw configuration, assigns plugin slots, and invokes an external patch script against OpenClaw behavior. Even if intended to enable offload support, this exceeds a narrow 'memory plugin' role and creates persistent system-wide changes that can affect unrelated agent behavior and trust boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Patching external OpenClaw hook behavior to inject after_tool_call messages expands the plugin's visibility into session/tool data and alters core runtime behavior. In a memory/offload context, this is especially sensitive because it can capture and forward additional conversational or tool-derived content to the offload backend, increasing data exposure and attack surface.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Changing the global agent compaction mode to 'safeguard' affects behavior outside this plugin and may alter retention, summarization, or memory handling for all agents. While not directly a code execution issue, it is an unauthorized global side effect inconsistent with least surprise and least privilege.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This runner exposes model-invocable local file read, write, and edit capabilities, allowing untrusted prompt content or model behavior to directly manipulate files in the configured workspace. In a memory-database plugin, such broad filesystem tooling is not clearly necessary, so prompt injection or model misuse could lead to unauthorized reading of sensitive local data or corruption of application state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

When enableTools is false, the code still supplies a read_file tool to the model, so the runner is not actually tool-free. This means prompts intended to be text-only can still trigger local file reads, creating an unexpected data exposure path via prompt injection or model-initiated file access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The client sets rejectUnauthorized: false for all HTTPS requests, which disables TLS certificate validation entirely. This allows man-in-the-middle attackers to impersonate the backend and read or modify highly sensitive offload traffic, including conversation content, tool results, generated memory, and propagated identity headers such as X-User-Id and X-Task-Id.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module implements an undeclared L4 feature that can generate and write new skill files based on conversation memory when a user issues /create-skill. This expands the plugin from memory/offload into code/content generation and persistence, creating an unexpected capability boundary that could be abused to plant new executable agent behavior or sensitive-derived artifacts on disk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The presence of /create-skill command parsing in an offload/memory module shows hidden skill-scaffolding functionality unrelated to the stated purpose. Hidden multi-purpose behavior is dangerous because users and operators may grant this plugin broad access for memory features without realizing it can also create persistent new agent assets.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/openclaw-after-tool-call-messages.patch.sh:58

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/index.mjs:12967

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/migrate-sqlite-to-tcvdb/dist/scripts/migrate-sqlite-to-tcvdb/sqlite-to-tcvdb.js:199

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/adapters/standalone/llm-runner.ts:196

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/core/store/factory.ts:98

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/gateway/server.ts:388

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
dist/index.mjs:3484

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/offload/backend-client.ts:312