Back to skill

Security audit

Claw Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real shared-memory tool, but it can persistently upload sensitive agent memory to a third-party service with weak scoping and misleading encryption language.

Review carefully before installing. Only use this if you are comfortable sending selected memories to the remote claw-memory service. Do not bulk-upload MEMORY.md until you have reviewed and redacted it, keep bearer tokens and encryption keys private, do not reuse the encryption key elsewhere, and prefer a pinned, verified install source over the mutable main-branch curl command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Remote Skill Installation Enables Supply-Chain Substitution

Content
View full analysis
Remediation
View remediation
" COMMIT="" TMP_FILE="$(mktemp)" curl --fail --show-error --location \ "https://raw.githubusercontent.com/siddontang/claw-memory/${COMMIT}/SKILL.md" \ -o "${TMP_FILE}" printf '%s %s\n' "${EXPECTED_SHA256}" "${TMP_FILE}" | sha256sum --check - install -m 0600 "${TMP_FILE}" ~/.openclaw/skills/claw-memory/SKILL.md rm -f "${TMP_FILE}" ``` The actual commit and checksum must come from a reviewed and trusted release. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:29
Finding

User-Supplied Encryption Key Is Sent to the Same Server Handling Plaintext Data

Content
View full analysis
" | jq . ``` > If you use an encryption key, include `-H "X-Encryption-Key: "` on ALL subsequent API calls. Without it, the server cannot decrypt your data. ``` From `SKILL.md:98-106`: ```bash ### Create with client-side encryption ```bash curl -s -X POST https://claw-memory.siddontang.workers.dev/api/tokens \ -H "X-Encryption-Key: " | jq . # All subsequent requests must include the same X-Encryption-Key header ``` ## Encryption - **Server key**: all connection strings encrypted by default (AES-256-GCM) - **Client key** (optional): `X-Encryption-Key` header for double encryption — server alone cannot decrypt ``` ### Technical Analysis The documentation describes the feature as “client-side encryption” and states that the server alone cannot decrypt the data. However, it directs clients to transmit the encryption key to the same server on every API call. Memory plaintext is also submitted to that server by the documented API workflow. This design is not client-side or end-to-end encryption in the conventional security sense. During request processing, the service can receive both the plaintext memory and the key. TLS can protect the request while it is in transit, but it does not prevent the destination service—or a compromise of that service—from observing the header and request content. The audit cannot determine how the remote service internally handles the key because no server implementation is present in the project. The confirmed issue is therefore the inaccurate trust claim and insecure documented key-handling mo ...[truncated 1277 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow tells the user/agent to upload a local MEMORY.md file to a remote API without a clear privacy warning, review step, or scoping guidance. MEMORY.md may contain sensitive user notes, credentials, internal prompts, or prior conversation summaries, so bulk transfer can cause significant unintended disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is broad enough to trigger on generic requests about storing, retrieving, searching, or sharing memories, which increases the chance the agent will invoke it in situations where the user did not intend remote persistence. In this specific skill, that broad trigger surface is more dangerous because invocation can lead to sending user data to an external service.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description explicitly promotes sharing memories across agent instances and importing existing memory files into a shared service, encouraging broad disclosure of stored context. In a memory-management skill this behavior is functionally relevant, but without strong consent and data-minimization controls it materially increases privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

Step 1: Install the skill

bash
mkdir -p ~/.openclaw/skills/claw-memory && curl -so ~/.openclaw/skills/claw-memory/SKILL.md https://raw.githubusercontent.com/siddontang/claw-memory/main/SKILL.md

Step 2: Create a memory space

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

Step 1: Install the skill

bash
mkdir -p ~/.openclaw/skills/claw-memory && curl -so ~/.openclaw/skills/claw-memory/SKILL.md https://raw.githubusercontent.com/siddontang/claw-memory/main/SKILL.md

Step 2: Create a memory space

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This instruction sends memory content to an external service, which is an actual data-exfiltration channel if the skill is invoked on sensitive content. The context makes it more dangerous because the skill is specifically designed for cross-instance persistence, so users may store conversation-derived secrets or personal data there without fully appreciating the transfer boundary.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

Step 3: Store your first memory

bash
curl -s -X POST https://claw-memory.siddontang.workers.dev/api/memories \
  -H "Authorization: Bearer <TOKEN_FROM_STEP_2>" \
  -H "Content-Type: application/json" \
  -d '{"content": "Hello from my claw!", "source": "openclaw"}'

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Uploading the entire local MEMORY.md file to a shared remote service can expose accumulated user and agent data beyond the local environment. The danger is amplified because the step is presented as a routine import action, making over-sharing likely even when the file contains secrets or sensitive personal content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The bulk upload command transmits the full contents of a local memory file to a remote API, creating a direct path for exfiltration of sensitive local data. Because it operates on an entire file and is framed as a convenience task, the blast radius is substantially larger than a single-memory upload.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

bash
# Read the file, then bulk upload
cat ~/.openclaw/workspace/MEMORY.md | jq -Rs '{memories: [{content: ., source: "openclaw", tags: ["memory"], key: "MEMORY.md"}]}' | \
  curl -s -X POST https://claw-memory.siddontang.workers.dev/api/memories/bulk \
  -H "Authorization: Bearer <TOKEN>" \
  -H "Content-Type: application/json" -d @-

Static analysis

No suspicious patterns detected.