Back to skill

Security audit

Context Clear

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is purpose-aligned, but it should be reviewed because it automatically persists and injects conversation memory with limited user control or safeguards.

Install only if you want OpenClaw to keep local cross-session memory and inject recent memory into prompts automatically. Treat stored memory as sensitive, avoid saving secrets or credentials there, review ~/.openclaw/memory_fs regularly, and be aware that /refresh can reorganize, mark, reset, and eventually delete memory files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
plugin/index.js:45
Finding

Untrusted Hot-Memory Content Is Automatically Injected into Agent Prompts

Content
View full analysis
{ if (!existsSync(HOT_DIR)) return; const now = Date.now(); try { const hotContent = readdirSync(HOT_DIR) .filter((f) => f.endsWith(".md")) .map((name) => ({ name, path: join(HOT_DIR, name), mtime: statSync(join(HOT_DIR, name)).mtimeMs, })) .filter((f) => now - f.mtime < HOT_AGE_MS) .sort((a, b) => b.mtime - a.mtime) .map((f) => { const c = readFileSync(f.path, "utf-8").trim(); if (!c) return null; return `## 热记忆: ${f.name.replace(/\.md$/, "")}\n${c}`; }) .filter(Boolean); if (hotContent.length > 0) { return { prependContext: hotContent }; } } catch { // 静默失败 } }); ``` ### Technical Analysis The `before_prompt_build` hook reads every recent Markdown file from `~/.openclaw/memory_fs/hot` and inserts its contents directly into the agent context through `prependContext`. The implementation does not: - Mark the imported content as untrusted reference data. - Instruct the model not to execute instructions found in memory. - Sanitize or classify stored instructions. - Restrict injection to trusted memory producers. - Enforce a file-size, aggregate-size, or token limit. Consequently, prompt instructions contained in a checkpoint, conversation record, or tool output can be interpreted as authoritative instructions in subsequent prompts. Because this hook runs before prompt construction, the malicious content can continue influencing future interactions while the file remains in the hot tier. The `tokenBudget` and `safetyBuffer` settings declared i ...[truncated 1904 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
plugin/scripts/organize.py:128
Finding

Memory Files Can Be Overwritten Through Cross-Layer Filename Collisions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding

A second description-behavior mismatch indicates the skill overstates automated memory lifecycle, retrieval, and checkpoint-management functions relative to what is actually present. Overclaiming capability in a persistence-oriented skill can cause unsafe reliance, accidental data handling beyond user expectations, and improper integration into workflows that assume stronger controls than exist.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

A second description-behavior mismatch indicates the skill overstates automated memory lifecycle, retrieval, and checkpoint-management functions relative to what is actually present. Overclaiming capability in a persistence-oriented skill can cause unsafe reliance, accidental data handling beyond user expectations, and improper integration into workflows that assume stronger controls than exist.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes operations that read, write, move, summarize, and delete files under a persistent memory directory, but it declares no explicit tool scope or permissions boundary. In an agent setting, missing scope makes those filesystem capabilities implicit and easier to invoke without clear user consent or runtime restriction, increasing the chance of unintended persistence or deletion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation scope is broad enough that the skill may run in many normal conversation-management situations without a precise trigger boundary. For a skill that persists, retrieves, and deletes historical content, ambiguous invocation increases the chance of unnecessary memory access, unintended retention, or cleanup being performed when the user did not specifically request it.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs persistence of full dialogue, tool output, and checkpoints into long-term filesystem storage for later retrieval. This is dangerous because it can retain secrets, personal data, credentials, or sensitive tool results far beyond the active session, creating a durable data-exposure surface if the files are later searched, promoted, or accessed by other processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents automatic physical deletion of stored memory after a retention period without a strong warning, confirmation mechanism, or recovery process. Because the stored material includes prior dialogue and tool outputs, silent deletion can cause irreversible loss of user data and audit history.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The promotion logic moves frequently accessed content into durable files such as MEMORY.md based on access frequency rather than sensitivity or necessity. That creates a feedback loop where repeatedly referenced sensitive material becomes more permanently retained, expanding exposure and making deletion or privacy compliance harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The retrieval trigger section includes vague signals like the model noticing context is missing or the user referencing prior discussion, which can cause automatic searches of stored memory. In a long-term memory system, that behavior is risky because it can surface old sensitive content or perform file operations without an explicit retrieval request.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The retrieval protocol tells the agent to search disk and read prior recorded content whenever current context lacks an answer, effectively encouraging automatic fallback to persistent memory. In context, this is more dangerous because the store contains full historical conversations and tool outputs, so automatic retrieval can reintroduce stale, private, or previously forgotten sensitive information into the active session.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This skill is described as a memory management and session-injection system, but the implementation invokes shell commands to discover global npm paths and later runs external Python programs. Spawning subprocesses is a broader capability than the manifested purpose itself and is not explicitly justified in the description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The plugin automatically reads markdown files from the user's hot-memory directory and prepends their contents to every prompt. That behavior can silently expose sensitive local data to the model and any downstream provider/tooling path on each turn, and memory files can also act as prompt-injection content that influences future model behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The /refresh command performs state-changing actions—running local scripts and resetting the active session—without an explicit confirmation step. A user can trigger destructive or privacy-impacting behavior unexpectedly, and if command invocation can be socially engineered through chat instructions, the lack of friction increases the chance of accidental execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The /refresh command executes local Python scripts with the plugin's privileges and one of them explicitly applies changes. Even though the paths are not user-supplied, this creates a code-execution and file-modification boundary crossing that is not constrained or validated here, so a compromised plugin install or modified script can perform arbitrary actions under the user's account.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The plugin is configured to auto-run on every startup via onStartup: true, but the manifest provides no gating conditions, user consent requirement, or scope limitations. In a memory-management skill that injects hot memory at startup, this broad trigger can cause unsolicited context injection or retrieval in every session, increasing the chance of privacy leakage, prompt-context contamination, or unintended behavior before the user explicitly invokes the skill.

Content

No source excerpt is available for this finding.

Tainted flow: 'dest' from os.environ.get (line 123, credential/environment) → shutil.copy2 (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · plugin/scripts/organize.py (reported line 124)May include surrounding context.

python
# warm → gist: copy 到 gist,warm 保留原文
            src = f
            dest = FS_BASE / "gist" / f.name
            shutil.copy2(str(src), str(dest))

            # gist 副本做摘要化
            summary = extract_summary(src.read_text(encoding="utf-8"))

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script permanently deletes files from forgotten/ after 30 days with no confirmation, dry-run mode, trash/quarantine step, or explicit external warning. In a memory-management skill, this is more dangerous because users may not realize that automated cleanup crosses from archival organization into irreversible data destruction, creating risk of unintended loss of conversation history or stored notes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file header says any one listed condition qualifies an item as a promotion candidate, including user_marked = true. However, the actual condition at L062 only promotes user-marked entries when they also have at least one reference in the last 7 days. This is an active contradiction between documented intent and implemented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The title and body switch into Chinese and present the operating instructions in that language, but there is no indication that the user may choose another language. This can violate a language/locale policy when a specific language is imposed without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest description is written only in Chinese, with no indication that users can select another language or that the plugin is intentionally limited to a Chinese-speaking audience. This can conflict with language/locale policy expectations when a skill is otherwise presented as generally applicable.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The top-level documentation describes the output as a report for manual classification and handling by a sub-session reader, implying a reporting-only role. Later embedded instructions explicitly direct spawning child sessions to read original content and move or extract data into long-term storage files. This creates a documentation-level inconsistency about whether the script is purely reporting/manual or part of an automated session-driven processing workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.