Back to skill

Security audit

Hongnao Memory V1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is not clearly malicious, but it automatically stores conversations and inferred preferences in persistent plaintext files and can replay untrusted remembered text into later agent context.

Install only if you are comfortable with an OpenClaw memory component retaining conversation content, inferred preferences, and user profile details across sessions. Before production or shared-workspace use, disable automatic extraction/logging by default, require user review before storing memories, separate recalled memories from executable instructions, redact secrets, restrict file permissions, pin dependencies, and provide clear inspect/delete/export controls.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
openclaw_integration.py:70
Finding

Persistent Memory Poisoning Through Untrusted Session Content

Content
View full analysis
List[MemCell]: """从文本中抽取记忆 - 基于句子分析""" mem_cells = [] timestamp = datetime.now().isoformat() # 分句 sentences = self._split_sentences(text) for sentence in sentences: if not sentence.strip(): continue # 判断句子类型 memory_type = self._classify_sentence(sentence) if memory_type: cell_id = f"mem_{uuid.uuid4().hex[:12]}" mem_cell = MemCell( id=cell_id, content=sentence.strip(), memory_type=memory_type, source=source, created_at=timestamp, updated_at=timestamp, importance=self._calc_importance(sentence, memory_type), tags=[memory_type] ) mem_cells.append(mem_cell) return mem_cells ``` `memory_extraction_v3.py:101-110`: ```python # 偏好型:包含喜欢、偏好、讨厌等 if any(kw in sentence for kw in ['喜欢', '偏好', '讨厌', '习惯']): return MemoryType.PREFERENCE.value # 约束型:包含必须、不能、禁止等 if any(kw in sentence for kw in ['必须', '不能', '禁止', '不要', '务必']): return MemoryType.CONSTRAINT.value ``` `memory_retrieval.py:288-307`: ```python if not resu ...[truncated 2924 chars]
Remediation
View remediation
... ``` 7. Separate declarative user facts from imperative instructions. Stored memories should never be interpreted as system or developer instructions. 8. Add tenant and session isolation so one user's memories cannot affect another user's context. 9. Implement memory review, revocation, expiration, and audit-log controls. 10. Add adversarial tests covering quoted instructions, role spoofing, indirect prompt injection, and cross-session persistence. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
openclaw_integration.py:91
Finding

Plaintext Storage of Complete Session Transcripts and Inferred Preferences

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:5
Finding

Mutable and Unverified Third-Party Dependency Installation

Content
View full analysis
=0.4.0 # 数值计算 numpy>=1.20.0 # 嵌入模型 sentence-transformers>=2.2.0 ``` `install_hongnao.py:325-344`: ```python requirements = """# 弘脑记忆系统依赖 # HongNao Memory OS Requirements # 向量数据库 chromadb>=0.4.0 # 数值计算 numpy>=1.20.0 # 嵌入模型 sentence-transformers>=2.2.0 # 可选:更强大的嵌入模型 # FlagEmbedding>=1.2.0 # 可选:Redis 缓存 # redis>=4.5.0 """ ``` ### Technical Analysis The installation instructions direct users to install dependencies from open-ended version ranges. No lock file, exact version constraints, integrity hashes, trusted-index restriction, or reviewed transitive dependency set is supplied. The effective package set can therefore change after the Skill has been audited. A future release satisfying one of the minimum-version constraints can be selected automatically. Package installation may execute build backends, setup hooks, native extensions, and imported package initialization code. This is a supply-chain weakness rather than evidence that the currently named packages are malicious. Exploitation requires a compromised package release, compromised package index, dependency takeover, or malicious package substitution in the user's configured index. ### Attack Path 1. A user follows the documented `pip3 install -r requirements.txt` instruction. 2. Pip queries the configured package index and resolves versions newer than the stated minimums. 3. A compromised or malicious release satisfying the open-ended constraint is selected, either directly or as a transitive dependency. 4. Pip downloads and installs the package without checking project-provided hashes. 5. Build or install ...[truncated 950 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (60)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly promotes extracting, storing, retrieving, and exporting user memories such as identity, preferences, emotions, and constraints, but does not warn about consent, retention limits, or privacy implications. In a long-term memory skill for an agent platform, this can normalize persistent collection of sensitive personal data and lead to over-retention or inappropriate downstream sharing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The design describes broad persistent collection of user information, preferences, skills, emotions, and constraints across conversations without stating minimization boundaries or consent requirements. Because the skill is specifically intended to create long-term memory for an agent platform, the context makes over-collection more dangerous: it is likely to capture sensitive behavioral and personal data at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README documents automatic forgetting, archiving, and deletion of memories without warning about irreversible data loss, retention thresholds, or recovery options. In a memory system integrated into agent workflows, this can cause silent loss of important user, project, or compliance-related context and make operators unaware of destructive lifecycle behavior.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The integration section encourages cross-session persistence of session memory, user preferences, project context, tool usage habits, and interaction history, but does not mention consent, isolation boundaries, or least-retention practices. In an OpenClaw-integrated multi-channel environment, such retention increases the risk of privacy leakage, unintended profiling, and data propagation across tools or contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The release notes advertise automatic preference learning as a core feature but provide no notice about what user data may be collected, inferred, stored, or reused. In a memory system for an AI assistant, silent behavioral profiling can expose sensitive personal patterns and create privacy and consent risks, especially if users enable or deploy it based only on these notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The sample configuration enables preference learning by default without warning users that their interactions may be profiled and persisted. Default-on behavioral learning in an AI memory component increases the likelihood of collecting sensitive user data without informed consent, which is particularly risky given the product’s long-term memory and integration context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly promotes long-term memory persistence, session synchronization, and automatic user preference learning, but the description does not warn users that their conversations and inferred preferences may be stored across sessions. This creates a real privacy and consent risk because users may disclose sensitive personal data without understanding that it will be retained and profiled persistently.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · install_hongnao.py (reported line 29)May include surrounding context.

python
required_packages = ['chromadb', 'sqlite3', 'numpy']
    for pkg in required_packages:
        try:
            __import__(pkg.replace('-', '_'))
        except ImportError:
            print(f"⚠️  缺少依赖:{pkg}")
            print(f"   运行:pip3 install {pkg}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script creates the destination directory and then copies plugin files into it, which modifies the user's filesystem. Although it prints progress messages, there is no confirmation prompt or explicit warning that installation will create or overwrite files in the target workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script writes a configuration file directly to the workspace and later writes an INSTALL.md file, which are user-visible filesystem changes. While success messages are printed after writing, the code does not provide advance disclosure or confirmation before these write operations occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The forgetting flow removes memories via apply_forgetting and cleanup_old_memories, including reporting deleted and cleaned counts, but there is no confirmation prompt or explicit user-facing disclosure that stored memories may be deleted. Because this is a safety-relevant destructive operation on user data, the code should visibly warn before or during execution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The class first defines create_scene as creating a memory scene with optional query-based filtering of relevant memories (L251-L297). Later, a second create_scene method with the same name replaces it entirely, but only creates an empty scene from title and type, so the earlier documented behavior is no longer what the code actually exposes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The test section demonstrates system.create_scene("燧弘华创项目", "project", query="燧弘华创"), implying the API supports query-based scene creation. However, the effective create_scene method exposed by the class is the later redefinition at L377-L401, which accepts only title and scene_type, directly contradicting the documented/tested intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The extractor turns free-form conversation into persistent memory objects containing personal data such as names, employer, role, preferences, and constraints, but the code shows no consent gate, notice, minimization, or policy checks before storing it. In an agent memory context, this can silently accumulate identifiable and behavioral data, creating privacy, compliance, and misuse risk if later queried, shared, or retained indefinitely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The extraction logic broadly stores user facts and preferences from natural-language input without screening for sensitive categories such as financial, employment, health, identity, or other confidential information. Because the resulting MemCell content preserves original sentences, sensitive details can be retained verbatim and later surfaced to downstream components or logs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The fallback rule marks nearly any sentence containing '用户' and having length greater than five as a fact, which substantially increases over-collection and false capture of conversational content. In a memory system, that means incidental, speculative, or sensitive statements about the user may be stored without sufficient relevance checks, amplifying privacy and downstream misuse risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The test routine prints retrieved memory contents directly, including profile and potentially sensitive business or personal data embedded in memory cells. In environments where tests run in shared consoles, CI logs, or developer machines, this can expose sensitive memory contents to unauthorized viewers and create persistent log leakage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level natural-language documentation is presented only in Chinese for the functional description, which imposes a specific language context without any opt-in or alternative. Under the policy, language constraints should either be user-selectable or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The forgetting logic can automatically archive, soft-delete, or delete memories based solely on computed thresholds, with no explicit confirmation, policy guardrail, or recoverability guarantee for direct deletions. In a memory system, this creates an integrity and availability risk because valuable or sensitive records may be silently removed due to heuristic error or manipulated metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The cleanup routine drops old, low-access memories from the returned result set without explicit warning or confirmation, effectively deleting data by omission. In this skill's context—a persistent memory module—silent removal is more dangerous because downstream components may treat the filtered list as authoritative and permanently persist the loss.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This synchronization flow both auto-extracts memory from entire conversations and persists session data, creating broad natural-language retention of potentially sensitive user content. In an assistant memory system, that context makes the issue more dangerous because the feature is specifically designed to accumulate personal data across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Automatic memory extraction processes conversation text and persists derived memories without an explicit user warning or consent control. Because extracted memories may include sensitive preferences, facts, and constraints across sessions, this creates a persistent privacy risk beyond the original conversation scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code writes full session conversations to disk automatically in the workspace memory directory without any consent, notice, minimization, or access-control step visible here. In a memory/assistant integration context, conversations can contain credentials, personal data, or proprietary content, so persistent plaintext logging materially increases privacy and disclosure risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The session log stores the complete message history to disk in JSON, which can expose secrets and sensitive user text if the workspace is accessed by other local users, backups, plugins, or later exports. Plain-language full-history logging is especially risky in chat systems because users routinely paste tokens, internal documents, and personal details.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The daily export writes stored memory contents, including facts and preferences, into a Markdown file, increasing the number of persistent copies of sensitive data and making disclosure easier through file sharing, indexing, or accidental publication. In a memory profile context, exported summaries can be more sensitive than raw logs because they consolidate personal information into a concise report.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.