T03 · Remote Payload Retrieval and Execution
- Location
INSTALL.md:537- Finding
Remote NodeSource Script Is Executed with Root Privileges Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory plugin is not clearly malicious, but it makes broad persistence and installation claims that do not match the shipped code and includes unsafe setup guidance.
Review carefully before installing. Treat it as a prototype or documentation-heavy package, not a verified memory system. Do not run the sudo curl pipeline or unsigned binary download commands without independent verification, and avoid enabling persistent capture, cloud embeddings, cron routing, or Git backup until you are comfortable with where conversation memory is stored and who can access it.
INSTALL.md:537Remote NodeSource Script Is Executed with Root Privileges Without Integrity Verification
INSTALL.md:279Qdrant Executable Is Downloaded and Extracted Without Checksum or Signature Verification
index.ts:61Memory Update Tool Reports an Append Operation Without Writing Any Data
INSTALL.md:481Troubleshooting Guidance Makes Sensitive Agent Memory World-Readable
The command chains curl output directly into sudo -E bash, combining remote content retrieval, shell execution, and root privileges in one step. This sharply increases exploitation impact because any compromise or tampering of the fetched script results in immediate privileged code execution on the system.
Install Node.js:
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs
The description overstates and partly differs from the code’s actual behavior. The code exposes memory-themed tool interfaces, but each tool merely returns a text response describing what would happen, without carrying out searches, persistence, expansion, recall, or recovery. Additionally, the high-level architecture conflicts with the description: the declared purpose says 'five tiers' and emphasizes disaster recovery, while the plugin describes itself as a 'three-tier' system and contains no recovery functionality. This is a material description-versus-behavior mismatch.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
},
"uninstall": {
"type": "manual",
"description": "Uninstall Trident. Memory is never automatically deleted. Use 'rm -r ~/.openclaw/workspace/memory' to remove memory files."
}
},
"permissions": {
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
},
"uninstall": {
"type": "manual",
"description": "Uninstall Trident. Memory is never automatically deleted. Use 'rm -r ~/.openclaw/workspace/memory' to remove memory files."
}
},
"permissions": {
The cloud model configuration discusses providers and pricing but does not clearly disclose that workspace or memory contents may be transmitted to third-party model or embedding vendors. Because this plugin handles long-term memory and routing, users may unknowingly send sensitive historical data off-host to external services.
The guide states that Trident captures all conversation and performs recurring memory writes, but it does not prominently warn users about the privacy and retention implications of storing potentially sensitive prompts, outputs, credentials, or personal data. In a persistent-memory plugin, silent or underexplained capture materially increases the risk of unintended data collection and long-term exposure.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
**Option C: Qdrant Cloud (Managed)**
1. Create account at [qdrant.io](https://qdrant.io)
2. Create cluster
3. Copy API URL and key
The Git backup instructions encourage committing memory/ without warning that stored conversations and derived memories may be preserved indefinitely in Git history and potentially pushed to remotes. For a memory plugin, this can create durable leakage of sensitive data even after files are later deleted or edited.
Piping a remote script directly into sudo bash executes network-fetched code as root without inspection, which is a well-known high-risk installation pattern. If the remote source, transport, or distribution endpoint is compromised, the host can be fully compromised immediately.
Install Node.js:
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs
Piping a remote script directly into sudo bash executes network-fetched code as root without inspection, which is a well-known high-risk installation pattern. If the remote source, transport, or distribution endpoint is compromised, the host can be fully compromised immediately.
Install Node.js:
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs
The document describes an approval workflow where templates are auto-approved on activation, reducing meaningful human review of prompt-bearing content before scheduled execution. In this plugin context, the approved template influences autonomous Layer 0.5 routing behavior, so automatic approval weakens the protection the SHA256 check is supposed to provide and can allow unsafe or tampered prompt logic to become trusted by default.
- **SHA256 verification** — automatic before each Layer 0.5 run
- **Audit logging** — all routing decisions logged with timestamp, signal type, destination, and reasoning
- **Approval workflow** — template auto-approved on activation, re-approvable after edits
- **File scope** — Layer 0.5 cron sandboxed to `memory/` subdirectory only
- **Logs** — all security events to `memory/layer0/audit-log.md`
The README explicitly states that binaries are downloaded and started automatically and that the plugin provides persistent memory capture, but it does not prominently warn users about the privacy, storage, background-process, and local-system implications. In an agent memory plugin, silent persistence and auto-start behavior can cause users to retain sensitive conversations or run additional services without informed consent, increasing exposure if the host is shared or compromised.
The cloud setup instructions recommend hosted Qdrant and Redis/FalkorDB options without a clear warning that memory contents, embeddings, metadata, or related context may be transmitted to third-party infrastructure. For a plugin marketed as permanent agent memory, this omission is risky because users may unknowingly export sensitive long-term data outside their local environment and into external retention and access-control domains.
The documentation states that missing Qdrant/FalkorDB binaries will be downloaded and started automatically, but it does not present a clear warning that the plugin may fetch and execute software on the user's machine. Automatic retrieval and execution of binaries materially increases supply-chain and remote-code-execution risk, especially in an agent plugin context where users may assume operations are limited to memory management.
The skill promotes persistent memory, embeddings, cloud deployment, and semantic recall, but does not clearly warn users that conversation memory and other sensitive content may be sent to third-party services for embedding, storage, or retrieval. In a memory plugin, this omission is more dangerous because the data likely includes long-lived personal, project, or credential-adjacent context, increasing privacy and compliance risk.
The skill is explicitly designed for session persistence and long-term memory retention, which can store sensitive user data across sessions and reintroduce it later. In this context, persistence is security-relevant because it expands the blast radius of prompt-injected secrets, personal data, or confidential workspace content beyond a single conversation.
# Create directory structure + config
openclaw trident init
# Runs Layer 0.5 signal router (one-time bootstrap)
The plugin advertises a 'five-tier, lossless permanent memory system' but implements only placeholder tools that return descriptive text. This creates a security-relevant integrity risk: agents or operators may rely on memory persistence, recall, or recovery that does not actually exist, leading to silent data loss, failed recovery, and incorrect autonomous decisions based on assumed state.
Each tool description claims concrete memory operations such as search, expansion, update, and recall, but the handlers only echo user-controlled parameters and instructions. In an agent context, this is dangerous because downstream components may treat the tool as authoritative and proceed as if sensitive state was stored or retrieved, causing workflow corruption, missed auditing, and false assurance about persistence and recovery.
The manifest clearly advertises persistent memory, daily logs, long-term memory, and continuity features, but it does not provide any explicit user-facing warning that conversations or agent-generated data may be stored on disk over time. In a memory plugin, this omission can lead users to unknowingly persist sensitive prompts, credentials, personal data, or proprietary workspace content, increasing privacy and data-retention risk.
The declared memory_update capability says it appends entries to a daily memory log, but the manifest does not disclose this write behavior in a prominent warning or consent-oriented description. Because this capability performs persistent on-disk writes, users and operators may underestimate the plugin's data collection and retention behavior, which is especially risky in an agent environment that may process secrets or sensitive operational context.
The activation block uses type 'cron' with trigger 'environment', which is underspecified and could cause the plugin to start automatically in broader contexts than the user expects. Because this plugin performs persistent memory capture and routing, ambiguous activation increases the chance of unintended collection, processing, or background execution.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
},
"uninstall": {
"type": "manual",
"description": "Uninstall Trident. Memory is never automatically deleted. Use 'rm -r ~/.openclaw/workspace/memory' to remove memory files."
}
},
"permissions": {
The index advertises automatic audit logging to memory/layer0/audit-log.md but does not clearly warn that routine plugin operation persistently writes agent activity and routing decisions to disk. In a memory/persistence plugin, this can create unexpected retention of sensitive prompts, operational metadata, or user content, increasing privacy and data-handling risk if users enable the plugin without understanding the persistence behavior.
No suspicious patterns detected.