Compaction Survival System
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill instructs the agent to write user input and agent responses to local markdown files (`SESSION-STATE.md`, `memory/working-buffer.md`) for context persistence and recovery. While the stated purpose is benign, this creates a potential prompt injection vector. If a malicious user injects commands into their input, and the OpenClaw agent's underlying system later processes the content of these files in an insecure way (e.g., by executing or evaluating arbitrary content), it could lead to arbitrary code execution. This is a significant vulnerability risk, but the skill itself does not explicitly instruct malicious actions like data exfiltration or unauthorized access, classifying it as suspicious rather than malicious.
