Back to skill

Security audit

Trident Plugin

Security checks for vulnerabilities and agentic risk

Overview

This memory plugin is not clearly malicious, but it makes broad persistence and installation claims that do not match the shipped code and includes unsafe setup guidance.

Review carefully before installing. Treat it as a prototype or documentation-heavy package, not a verified memory system. Do not run the sudo curl pipeline or unsigned binary download commands without independent verification, and avoid enabling persistent capture, cloud embeddings, cron routing, or Git backup until you are comfortable with where conversation memory is stored and who can access it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
INSTALL.md:537
Finding

Remote NodeSource Script Is Executed with Root Privileges Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
INSTALL.md:279
Finding

Qdrant Executable Is Downloaded and Extracted Without Checksum or Signature Verification

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
index.ts:61
Finding

Memory Update Tool Reports an Append Operation Without Writing Any Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
INSTALL.md:481
Finding

Troubleshooting Guidance Makes Sensitive Agent Memory World-Readable

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (32)

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The command chains curl output directly into sudo -E bash, combining remote content retrieval, shell execution, and root privileges in one step. This sharply increases exploitation impact because any compromise or tampering of the fetched script results in immediate privileged code execution on the system.

Content

Scanner excerpt · INSTALL.md (reported line 537)May include surrounding context.

Install Node.js:

bash
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description overstates and partly differs from the code’s actual behavior. The code exposes memory-themed tool interfaces, but each tool merely returns a text response describing what would happen, without carrying out searches, persistence, expansion, recall, or recovery. Additionally, the high-level architecture conflicts with the description: the declared purpose says 'five tiers' and emphasizes disaster recovery, while the plugin describes itself as a 'three-tier' system and contains no recovery functionality. This is a material description-versus-behavior mismatch.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · plugin-manifest.json (reported line 263)May include surrounding context.

json
},
    "uninstall": {
      "type": "manual",
      "description": "Uninstall Trident. Memory is never automatically deleted. Use 'rm -r ~/.openclaw/workspace/memory' to remove memory files."
    }
  },
  "permissions": {

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · plugin-manifest.json (reported line 263)May include surrounding context.

json
},
    "uninstall": {
      "type": "manual",
      "description": "Uninstall Trident. Memory is never automatically deleted. Use 'rm -r ~/.openclaw/workspace/memory' to remove memory files."
    }
  },
  "permissions": {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cloud model configuration discusses providers and pricing but does not clearly disclose that workspace or memory contents may be transmitted to third-party model or embedding vendors. Because this plugin handles long-term memory and routing, users may unknowingly send sensitive historical data off-host to external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide states that Trident captures all conversation and performs recurring memory writes, but it does not prominently warn users about the privacy and retention implications of storing potentially sensitive prompts, outputs, credentials, or personal data. In a persistent-memory plugin, silent or underexplained capture materially increases the risk of unintended data collection and long-term exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · INSTALL.md (reported line 287)May include surrounding context.

md
**Option C: Qdrant Cloud (Managed)**

1. Create account at [qdrant.io](https://qdrant.io)
2. Create cluster
3. Copy API URL and key

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Git backup instructions encourage committing memory/ without warning that stored conversations and derived memories may be preserved indefinitely in Git history and potentially pushed to remotes. For a memory plugin, this can create durable leakage of sensitive data even after files are later deleted or edited.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
79% confidence
Finding

Piping a remote script directly into sudo bash executes network-fetched code as root without inspection, which is a well-known high-risk installation pattern. If the remote source, transport, or distribution endpoint is compromised, the host can be fully compromised immediately.

Content

Scanner excerpt · INSTALL.md (reported line 537)May include surrounding context.

Install Node.js:

bash
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Piping a remote script directly into sudo bash executes network-fetched code as root without inspection, which is a well-known high-risk installation pattern. If the remote source, transport, or distribution endpoint is compromised, the host can be fully compromised immediately.

Content

Scanner excerpt · INSTALL.md (reported line 537)May include surrounding context.

Install Node.js:

bash
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 538)May include surrounding context.

bash
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs

Docker Container

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The document describes an approval workflow where templates are auto-approved on activation, reducing meaningful human review of prompt-bearing content before scheduled execution. In this plugin context, the approved template influences autonomous Layer 0.5 routing behavior, so automatic approval weakens the protection the SHA256 check is supposed to provide and can allow unsafe or tampered prompt logic to become trusted by default.

Content

Scanner excerpt · MIGRATION.md (reported line 298)May include surrounding context.

md
- **SHA256 verification** — automatic before each Layer 0.5 run
- **Audit logging** — all routing decisions logged with timestamp, signal type, destination, and reasoning
- **Approval workflow** — template auto-approved on activation, re-approvable after edits
- **File scope** — Layer 0.5 cron sandboxed to `memory/` subdirectory only
- **Logs** — all security events to `memory/layer0/audit-log.md`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly states that binaries are downloaded and started automatically and that the plugin provides persistent memory capture, but it does not prominently warn users about the privacy, storage, background-process, and local-system implications. In an agent memory plugin, silent persistence and auto-start behavior can cause users to retain sensitive conversations or run additional services without informed consent, increasing exposure if the host is shared or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cloud setup instructions recommend hosted Qdrant and Redis/FalkorDB options without a clear warning that memory contents, embeddings, metadata, or related context may be transmitted to third-party infrastructure. For a plugin marketed as permanent agent memory, this omission is risky because users may unknowingly export sensitive long-term data outside their local environment and into external retention and access-control domains.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation states that missing Qdrant/FalkorDB binaries will be downloaded and started automatically, but it does not present a clear warning that the plugin may fetch and execute software on the user's machine. Automatic retrieval and execution of binaries materially increases supply-chain and remote-code-execution risk, especially in an agent plugin context where users may assume operations are limited to memory management.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill promotes persistent memory, embeddings, cloud deployment, and semantic recall, but does not clearly warn users that conversation memory and other sensitive content may be sent to third-party services for embedding, storage, or retrieval. In a memory plugin, this omission is more dangerous because the data likely includes long-lived personal, project, or credential-adjacent context, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill is explicitly designed for session persistence and long-term memory retention, which can store sensitive user data across sessions and reintroduce it later. In this context, persistence is security-relevant because it expands the blast radius of prompt-injected secrets, personal data, or confidential workspace content beyond a single conversation.

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

3. Initialize Memory Tiers

bash
# Create directory structure + config
openclaw trident init

# Runs Layer 0.5 signal router (one-time bootstrap)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The plugin advertises a 'five-tier, lossless permanent memory system' but implements only placeholder tools that return descriptive text. This creates a security-relevant integrity risk: agents or operators may rely on memory persistence, recall, or recovery that does not actually exist, leading to silent data loss, failed recovery, and incorrect autonomous decisions based on assumed state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Each tool description claims concrete memory operations such as search, expansion, update, and recall, but the handlers only echo user-controlled parameters and instructions. In an agent context, this is dangerous because downstream components may treat the tool as authoritative and proceed as if sensitive state was stored or retrieved, causing workflow corruption, missed auditing, and false assurance about persistence and recovery.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest clearly advertises persistent memory, daily logs, long-term memory, and continuity features, but it does not provide any explicit user-facing warning that conversations or agent-generated data may be stored on disk over time. In a memory plugin, this omission can lead users to unknowingly persist sensitive prompts, credentials, personal data, or proprietary workspace content, increasing privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The declared memory_update capability says it appends entries to a daily memory log, but the manifest does not disclose this write behavior in a prominent warning or consent-oriented description. Because this capability performs persistent on-disk writes, users and operators may underestimate the plugin's data collection and retention behavior, which is especially risky in an agent environment that may process secrets or sensitive operational context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation block uses type 'cron' with trigger 'environment', which is underspecified and could cause the plugin to start automatically in broader contexts than the user expects. Because this plugin performs persistent memory capture and routing, ambiguous activation increases the chance of unintended collection, processing, or background execution.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · plugin-manifest.json (reported line 263)May include surrounding context.

json
},
    "uninstall": {
      "type": "manual",
      "description": "Uninstall Trident. Memory is never automatically deleted. Use 'rm -r ~/.openclaw/workspace/memory' to remove memory files."
    }
  },
  "permissions": {

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The index advertises automatic audit logging to memory/layer0/audit-log.md but does not clearly warn that routine plugin operation persistently writes agent activity and routing decisions to disk. In a memory/persistence plugin, this can create unexpected retention of sensitive prompts, operational metadata, or user content, increasing privacy and data-handling risk if users enable the plugin without understanding the persistence behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.