Back to skill

Security audit

Memory Keep-Alive for Obsidian

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it installs always-enabled background jobs and automatically persists task details to an Obsidian vault, with an installer bug that can mishandle crafted vault paths.

Review this before installing if your tasks may contain secrets, client data, private file paths, or sensitive decisions. Prefer a dedicated Obsidian vault, inspect the five cron jobs after install, avoid untrusted vault-path commands, and remove or disable the jobs when you no longer want background automation.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
install.sh:97
Finding

Installation of Persistent Autonomous Scheduled Jobs

Content
View full analysis
/dev/null; then echo "Using OpenClaw CLI to add cron jobs..." add_job_if_missing() { local name="$1" cron="$2" prompt="$3" # Check if job already exists if openclaw cron list 2>/dev/null | grep -q "$name"; then echo " Skipped (already exists): $name" else openclaw cron add \ --name "$name" \ --cron "$cron" \ --session isolated \ --message "$prompt" \ --announce 2>/dev/null && echo " Added job: $name" || echo " Warning: failed to add $name via CLI" fi } add_job_if_missing "keep-alive-watchdog" "*/15 * * * *" "$WATCHDOG_PROMPT" add_job_if_missing "keep-alive-replayer" "*/30 * * * *" "$REPLAYER_PROMPT" add_job_if_missing "keep-alive-escalator" "0 * * * *" "$ESCALATOR_PROMPT" add_job_if_missing "memory-validator" "5 * * * *" "$VALIDATOR_PROMPT" add_job_if_missing "memory-smoke-test" "0 */6 * * *" "$SMOKETEST_PROMPT" else echo "OpenClaw CLI not found. Merging jobs directly into jobs.json..." JOBS_FILE="$OPENCLAW_DIR/cron/jobs.json" mkdir -p "$OPENCLAW_DIR/cron" ``` The fallback creates each job as enabled and scheduled: ```python job = { "id": secrets.token_hex(6), "name": name, "prompt": info["prompt"], "skills": [SKILL_NAME], "skill": SKILL_NAME, "model": None, "provider": None, "base_url": None, "schedule": { "kind": "cron", "expression": info["cron"], "display": info["cron"] }, "schedule_display": info["cron"], "repeat": {"times": None, "completed": 0}, "enabled": True, "state": "scheduled", "paused_at": None, "paused_reason": None, "created_at": now, "next_run_at": now, ...[truncated 2030 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
install.sh:22
Finding

Command Injection Through Unescaped Vault Path in sed Program

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:9
Finding

Execution of an Unpinned Mutable npm Package Release

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (21)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 108)May include surrounding context.

Uninstall

bash
rm -rf ~/.openclaw/skills/memory-keep-alive-for-obsidian
# Then remove the 5 jobs (keep-alive-* and memory-*) using:
openclaw cron remove --name "keep-alive-watchdog"
openclaw cron remove --name "keep-alive-replayer"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · INSTALL.md (reported line 108)May include surrounding context.

Uninstall

bash
rm -rf ~/.openclaw/skills/memory-keep-alive-for-obsidian
# Then remove the 5 jobs (keep-alive-* and memory-*) using:
openclaw cron remove --name "keep-alive-watchdog"
openclaw cron remove --name "keep-alive-replayer"

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The stated description emphasizes task memory and keep-alive behavior, but the skill behavior includes persistent vault modification, scheduled background jobs, and possible direct editing of job configuration. This mismatch weakens informed consent and can conceal operationally significant behavior such as recurring automation and configuration changes that users would reasonably expect to be disclosed up front.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill is explicitly designed to create persistent task memory and scheduled keep-alive behavior, which introduces intentional session persistence. In this context, persistence is the core feature, but it still expands the attack surface by retaining task artifacts and enabling recurring automated actions after the initial session ends.

Content

Scanner excerpt · INSTALL.md (reported line 6)May include surrounding context.

md
## Prerequisites

- OpenClaw installed and running
- An Obsidian vault (or willingness to create one)
- Python 3 (for the install script's job setup, if OpenClaw CLI is unavailable)

## Option 1: ClawHub

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The install command uses npx clawhub@latest, which fetches and executes the latest package version without pinning. This creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious release is published, users may execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installation flow states that the script 'does everything,' including creating files in the user's Obsidian vault and adding 5 recurring cron jobs, but it does not present this behavior as a prominent warning requiring explicit informed consent. Persistent scheduled jobs and automatic writes materially change the user's environment and can create unexpected privacy, resource-consumption, and persistence risks.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALL.md (reported line 63)May include surrounding context.

md
| What | Where |
|------|-------|
| Skill | `~/.openclaw/skills/memory-keep-alive-for-obsidian/SKILL.md` |
| Template | `<vault>/Tasks/Session-Resume-Workflow/TEMPLATE.md` |
| Workflow index | `<vault>/Tasks/Session-Resume-Workflow/WORKFLOW-INDEX.md` |
| Loop state | `<vault>/Tasks/Session-Resume-Workflow/LOOP-STATE.md` |

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The manual install instructions direct users to place templates and prompts into an Obsidian-backed workflow directory and create recurring cron jobs. This establishes durable state outside a single session and can cause ongoing automated behavior, making mistakes or misuse persist over time.

Content

Scanner excerpt · INSTALL.md (reported line 79)May include surrounding context.

md
## Option 3: Manual install

1. Copy the `SKILL.md` file and `templates/`, `prompts/`, `examples/` directories into `~/.openclaw/skills/memory-keep-alive-for-obsidian/`.
2. Create `Tasks/Session-Resume-Workflow/` in your Obsidian vault.
3. Copy `templates/TEMPLATE.md`, `templates/LOOP-STATE.md`, and `examples/WORKFLOW-INDEX.md` into that folder.
4. Replace `VAULT_PATH` in each file under `prompts/` with your actual vault path.
5. Create the 5 cron jobs manually using `openclaw cron add` (see table above).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises automatic persistent task memory in an Obsidian vault but does not prominently warn that agent task contents, status, and notes will be written automatically to local persistent storage. This can lead users to unintentionally persist sensitive prompts, secrets, or client data, especially because the feature is described as always-on and resilient across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README instructs users to set up cron-based watchdog, replay, validation, and escalation jobs without clearly emphasizing that these jobs will continue running in the background and may automatically modify notes or advance task state. In this skill's context, that matters because autonomous background actions on user task data can cause unexpected persistence, unintended edits, and ongoing token or system resource consumption if not fully understood.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx clawhub@latest install ..., which pulls and executes the latest published package version at install time rather than a reviewed, pinned release. That creates a supply-chain execution risk: if the package or publisher account is compromised, or a breaking/malicious update is published, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes automatic filesystem writes to the Obsidian vault but declares no explicit tool scope or permission boundary. That makes the write capability implicit and harder for users or hosting frameworks to review, increasing the risk of unanticipated file modification or broader abuse if the skill is installed in a permissive environment.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Mandating persistent note-taking for every task creates a systematic retention channel for user-provided content, including potentially sensitive requests, internal file paths, and workflow context. Because it applies by default to all tasks, it increases the likelihood that confidential or unnecessary data will be stored long-term without minimization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs automatic creation of task folders and notes in a persistent vault without warning the user that their prompts, task state, file paths, and related context will be written to disk. This creates a privacy and integrity risk because users may provide sensitive material assuming it remains ephemeral within the session.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The required note contents explicitly encourage storing restart context, key file paths, decisions, gotchas, and next-session notes, all of which can contain sensitive operational details. Persisting this level of context in natural-language documents raises the risk of information disclosure to other tools, users, or future sessions with access to the vault.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The update rules require immediate and continuous persistence of discoveries, milestones, and heartbeats, which encourages writing transient session context to long-lived storage as soon as it appears. This increases leakage risk because sensitive data may be recorded before the user can review or redact it, and repeated updates broaden the retained audit trail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The keep-alive loop describes recurring monitoring jobs that continue to inspect task state and modify vault files in the background, but does not clearly warn users about ongoing automated changes. Background persistence and repeated writes increase the chance of silent data retention, confusing edits, and unintended actions after the user believes the session is complete.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The installer silently provisions five autonomous scheduled jobs that will run indefinitely, which materially expands behavior beyond a user-triggered arm/disarm keep-alive loop. Even though the jobs are not obviously destructive, persistent background automation can consume tokens, access task data repeatedly, and create ongoing agent activity the user may not have clearly consented to.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The prompt explicitly instructs the agent to create missing task files and remove WATCHDOG.md as part of its replay workflow, but it provides no user-facing notice, confirmation, or audit guard before modifying persistent notes. Because this skill is designed to run automatically on stalled tasks, silent file creation/deletion can alter task state, obscure history, or cause unintended workflow changes without the user's awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prompt directs the agent to create and update files under the Obsidian vault automatically, but it does not require any explicit user notice or confirmation before making those modifications. Even though the writes are scoped to VAULT_PATH/Tasks/, this still enables silent persistence and alteration of user data, which is risky for an agent skill that may run unattended or on a schedule.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The user-facing install output states that the agent will now automatically create task notes for every task. In this file, the implemented behavior is limited to copying vault files and registering scheduled prompts; there is no direct code here that hooks task creation or guarantees note creation for every task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.