Back to skill

Security audit

memclaw

Security checks for vulnerabilities and agentic risk

Overview

MemClaw is a coherent memory-management skill, but it asks to broadly replace built-in memory and persist or migrate conversation data without enough explicit user-control safeguards.

Install only if you are comfortable making MemClaw the main memory layer for OpenClaw. Review what it may store before use, avoid saving secrets or regulated personal data, set narrow session IDs, and require explicit confirmation before migration, maintenance, pruning, reindexing, or committing sensitive sessions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/security.md (reported line 13)May include surrounding context.

md
## What the Plugin Does NOT Do

- **No External Data Transmission**: Does NOT send data to external servers (all processing is local)
- **No API Key Leakage**: Does NOT transmit API keys to anywhere other than your configured LLM/embedding provider

## Data Storage Location

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill metadata and opening guidance strongly position MemClaw as the preferred or replacement memory system for all memory operations, which can cause an agent to invoke it very broadly without verifying user intent, plugin availability, or data-scope appropriateness. In a memory plugin, over-broad invocation increases the chance of unnecessary storage, retrieval across unintended contexts, and accidental exposure or persistence of sensitive conversation data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented cortex_migrate operation describes migrating native memory to MemClaw without an explicit warning that it is a data-impacting action that may copy, transform, or reorganize persisted user data. Without a confirmation requirement and explanation of consequences, an agent could invoke migration automatically, leading to unintended duplication, privacy issues, or irreversible changes in how memory is managed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/security.md (reported line 13)May include surrounding context.

md
## What the Plugin Does NOT Do

- **No External Data Transmission**: Does NOT send data to external servers (all processing is local)
- **No API Key Leakage**: Does NOT transmit API keys to anywhere other than your configured LLM/embedding provider

## Data Storage Location

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation for cortex_add_memory encourages storing arbitrary message content and metadata but does not warn users that data may persist beyond the current interaction and may include sensitive or regulated information. In a memory-management plugin explicitly intended to replace built-in memory, this omission increases the likelihood of accidental retention of secrets, personal data, or other confidential content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cortex_commit_session documentation notes that it closes the session and triggers memory extraction, but it does not clearly warn that invoking the tool may finalize conversation state and persist additional derived memory. Users or agents may call it routinely without understanding that it changes system state and expands what is stored or indexed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The maintenance and migration tools are system-altering operations that can reindex, prune, ensure data consistency, or import existing memory, yet the documentation omits safety warnings about side effects, scope, and data integrity implications. In a memory plugin with broad access to stored conversation history, unclear guidance can lead to unintended data modification, retention expansion, or migration of sensitive legacy data without review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.