Security audit
qui-context-manager
Security checks for vulnerabilities and agentic risk
Overview
The skill is a clearly disclosed context-compression helper, but users should understand it can read, summarize, back up, and reset OpenClaw session history when explicitly invoked.
Install only if you are comfortable letting this workflow access OpenClaw session history and use AI summarization. Run the non-destructive summarize command first, verify the generated summary, and use --replace only for sessions you are willing to reset from the saved backup.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
