Back to skill

Security audit

hierarchical-agent-memory

Security checks for vulnerabilities and agentic risk

Overview

This skill persistently organizes OpenClaw memory files, but the behavior is clearly disclosed, purpose-aligned, and gated by user setup choices.

Install only if you want OpenClaw to maintain persistent project, contact, and daily memory files. Keep secrets, API keys, passwords, and sensitive personal data out of these memory files, and review any migration plan before allowing existing MEMORY.md content to be reorganized.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/migration-v2-to-v3.md (reported line 45)May include surrounding context.

md
1. Create `memory/topics/` directory
2. For each active project, create `memory/topics/<project-name>.md`
3. Move project-specific content from MEMORY.md to the topic file
4. Replace MEMORY.md content with one-line pointers to topic files
5. Repeat for contacts if desired

## Rollback

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The detection rule says onboarding should start if the user says "set up memory", "configure memory skill", "or similar." That catch-all phrase makes the trigger boundary unclear and could match ordinary conversation about memory setup without a clear intent to invoke onboarding.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script instructs the agent to "Create directory structure" when the user says "just use defaults." While this is not hidden, the specific step that filesystem changes will occur is not disclosed to the user in that default path before the action happens.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.