Back to skill

Security audit

Memos

Security checks for vulnerabilities and agentic risk

Overview

This Memos skill is coherent, but it asks users to run an unpinned npm MCP server that receives a Memos access token and can read, update, and delete memos.

Install only if you trust the `openclaw-memos-mcp` npm package and its publisher. Prefer pinning an exact reviewed package version, using a least-privilege Memos token, storing the token through your MCP client's secret mechanism if available, and confirming destructive memo operations manually.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:32
Finding

Unpinned npm Package Execution with Access to Memos Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 32–39
Vulnerability Type: Unpinned third-party dependency executed through npx
Risk Level: Medium

Vulnerable Code:

json
{
  "mcpServers": {
    "memos": {
      "command": "npx",
      "args": ["openclaw-memos-mcp"],
      "env": {
        "MEMOS_API_URL": "http://localhost:5230",
        "MEMOS_TOKEN": "<your-access-token>"
      }
    }
  }
}

Technical Analysis

The documented configuration directs npx to execute openclaw-memos-mcp without specifying an exact version. As a result, the package version resolved by npm may change between installations or executions. The project provides no lockfile, integrity hash, reviewed source revision, or registry restriction to ensure that the executed package is the version that was originally audited.

The package process is also given MEMOS_TOKEN through its environment. Therefore, a compromised, malicious, or unexpectedly modified package release would receive the user's Memos credential while executing with the operating-system permissions of the MCP client.

The package implementation is not included in the audited project, so its internal behavior cannot be verified from the available artifact. This finding concerns the unsafe dependency resolution and execution pattern documented by the skill; it does not establish that the named package is currently malicious.

Attack Path

  1. An attacker compromises the package publisher account, npm package, release process, or another relevant supply-chain component.
  2. The attacker publishes a malicious version under the same package name.
  3. A user follows the documented configuration and starts or restarts the MCP client.
  4. npx resolves and executes the unpinned package version.
  5. The malicious package inherits MEMOS_API_URL and MEMOS_TOKEN from the configured environment.
  6. It uses the token to access or ...[truncated 803 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin openclaw-memos-mcp to an exact, reviewed version rather than allowing npx to resolve an unspecified release.
  • Install dependencies through a committed lockfile and use deterministic installation, such as npm ci, where applicable.
  • Verify package integrity and provenance, including the official publisher, repository, release signatures or attestations, and registry source.
  • Configure npm to use an explicitly trusted registry and prevent unintended dependency substitution.
  • Review new package versions before upgrading instead of automatically consuming the latest release.
  • Run the MCP server in a restricted container, sandbox, or dedicated low-privilege OS account with minimal filesystem and network access.
  • Issue a least-privilege Memos token limited to only the operations needed by the skill.
  • Store the token through the MCP client's supported secret-management facility rather than in a broadly accessible configuration file.
  • Rotate the token after suspected dependency compromise and monitor the Memos instance for unauthorized CRUD operations.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
Tell the user to:
1. Replace `MEMOS_API_URL` with their Memos instance URL
2. Get an access token from Memos: **Settings > Access Tokens > Create**
3. Replace `<your-access-token>` with the token
4. Restart their MCP client after saving the configuration

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
Tell the user to:
1. Replace `MEMOS_API_URL` with their Memos instance URL
2. Get an access token from Memos: **Settings > Access Tokens > Create**
3. Replace `<your-access-token>` with the token
4. Restart their MCP client after saving the configuration

Static analysis

No suspicious patterns detected.