Back to skill

Security audit

Mem9

Security checks for vulnerabilities and agentic risk

Overview

This deprecated skill only redirects users to install a mutable remote replacement, so the local file is not malicious but the effective installed skill is outside the reviewed artifact.

Treat this local package as a redirect, not as the actual mem9 implementation. Before installing the remote replacement, review the current c4pt0r/mem9-ai package contents, publisher identity, requested tools, storage behavior, and any executable files, and prefer a pinned or reviewed version when available.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:26
Finding

Unpinned Remote Skill Retrieval and Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 26–32
Vulnerability Type: Unpinned retrieval and installation of mutable remote skill content
Risk Level: Medium

markdown
The canonical, up-to-date version lives at:

👉 **https://clawhub.ai/c4pt0r/mem9-ai**

## How to update

Replace this file with the latest version:

```bash
# Install from ClawHub directly:
openclaw skills install c4pt0r/mem9-ai

Technical Analysis

The deprecated local skill instructs users to install the latest version of an externally maintained skill. The command does not specify an immutable version, cryptographic digest, or signature requirement, and it provides no review or verification step before installation.

Consequently, the effective skill installed by this instruction can change after the audited local file has been reviewed. Although the current repository contains no embedded malicious scripts, credential access, persistence, or exfiltration logic, its update process transfers trust to mutable remote content outside the audit boundary.

This is best classified as remote payload retrieval because the instruction causes externally controlled skill content to be fetched and installed. Exploitation would require the remote package, publisher account, distribution service, or delivery path to become malicious or compromised.

Attack Path

  1. A user or agent loads the deprecated local skill and follows its update instructions.
  2. The user runs openclaw skills install c4pt0r/mem9-ai.
  3. OpenClaw retrieves the package version currently published under that remote identifier.
  4. Because no version or digest is pinned, the retrieved content may differ from content previously reviewed.
  5. If the publisher account or supply chain is compromised, attacker-controlled instructions or executable components can be installed.
  6. When the installed skill is subsequently loaded or invoked, that content can operate ...[truncated 707 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the mutable package reference with a pinned, audited version or immutable content digest.
  • Require cryptographic signature verification and validate the expected publisher identity before installation.
  • Download the package into a staging area and present its files, scripts, permissions, and external dependencies for review before activation.
  • Prevent automatic execution of post-install scripts unless they have been explicitly reviewed and approved.
  • Document the exact tools, filesystem paths, network destinations, and credentials required by the replacement skill.
  • Run the installed skill with least privilege, restricting filesystem, network, command-execution, and secret access to what is strictly necessary.
  • Retain a known-good package or lockfile so installations can be reproduced and rolled back safely.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.