Back to skill

Security audit

OpenClaw Dreaming Setup — Memory Consolidation Config

Security checks for vulnerabilities and agentic risk

Overview

This skill is a setup guide for OpenClaw Dreaming and clearly describes its opt-in persistent memory behavior, though users should treat automatic memory promotion carefully.

Install only if you want OpenClaw to maintain long-term memory automatically. Before enabling it, confirm which notes and transcripts can be used, preview promotions where possible, keep rollback/audit practices in place, and set the timezone to your own deployment preference.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:27
Finding

Automated Promotion of Untrusted Session Content into Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:27-32 and SKILL.md:40-57
Vulnerability Type: Agent memory poisoning through automatic memory consolidation
Risk Level: Medium

Relevant Snippets:

markdown
Dreaming automatically:
1. **Light phase** — stages recent daily notes and session transcripts
2. **REM phase** — extracts patterns and recurring themes
3. **Deep phase** — promotes strong signals into `MEMORY.md`

It runs as a background cron job tied to heartbeat.
json5
{
  plugins: {
    entries: {
      "memory-core": {
        config: {
          dreaming: {
            enabled: true,
            // Optional: custom schedule (default: 03:00 daily)
            frequency: "0 3 * * *",
            timezone: "Asia/Jerusalem",
          },
        },
      },
    },
  },
}

Technical Analysis

The documented configuration creates an automated path from recent notes and session transcripts into the persistent MEMORY.md file. Promotion is based on extracted patterns and recurring signals, but the Skill does not document any trust-boundary validation, provenance enforcement, prompt-injection filtering, content-type restrictions, or mandatory human approval before the Deep phase writes persistent memory.

An attacker who can influence session transcripts or daily notes could repeatedly introduce false facts, behavioral directives, or instruction-like content. Recurrence-based consolidation may then interpret that content as a strong signal and promote it into long-term memory. Once stored, the poisoned content can continue to affect later sessions that use MEMORY.md.

This issue does not grant operating-system privileges or independently provide arbitrary code execution. Its scope is the persistent memory and subsequent behavior of the affected OpenClaw agent.

Attack Path

  1. An administrator enables Dreaming using the documented configuration.

...[truncated 1150 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit human approval for every Deep-phase change to MEMORY.md, particularly when source material includes session transcripts.
  2. Present the exact proposed diff, source excerpts, source timestamps, and originating sessions before promotion.
  3. Treat transcripts and user-authored notes as untrusted input. Detect and reject instruction-like content, prompt-injection patterns, executable commands, and attempts to modify agent policy.
  4. Preserve provenance for every promoted item and distinguish verified user preferences from unverified conversational claims.
  5. Use an allowlist of data classes that may enter persistent memory, such as explicitly confirmed preferences or administrator-approved facts.
  6. Do not use repetition alone as evidence of trustworthiness. Apply source diversity, confidence, and explicit verification requirements.
  7. Default automatic promotion to preview-only mode and require a separate approval action before persistent writes.
  8. Maintain versioned backups and an auditable promotion log so poisoned entries can be identified and rolled back reliably.
  9. Add per-source exclusion controls so sensitive, external, anonymous, or otherwise untrusted conversations cannot participate in memory consolidation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents commands such as openclaw memory promote --apply and openclaw memory rem-backfill that can write to or alter persistent memory artifacts, including promotion into MEMORY.md. While the file explains what Dreaming does, it does not clearly warn users in the command sections that these operations change stored memory state and may affect future agent behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example configuration sets timezone: "Asia/Jerusalem", which imposes a specific locale-related setting in natural language documentation. The file does not present this as a user-selectable example or advise users to choose their own timezone, so it risks violating the policy against forcing a locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.