T02 · Agent Memory Poisoning
- Location
hooks/openclaw/handler.js:11- Finding
Untrusted Corrections Can Be Promoted into Persistent Agent Control Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent learning-capture purpose, but it saves and promotes potentially sensitive conversation and error details into persistent agent files without enough redaction or approval safeguards.
Install only if you are comfortable with persistent learning files and optional hooks affecting future sessions. Keep it project-scoped where possible, do not enable global hooks casually, and redact tokens, credentials, private paths, customer data, request bodies, and full stack traces before writing learnings. Treat any promotion into AGENTS.md, SOUL.md, TOOLS.md, or MEMORY.md as a manual review step by a trusted operator, not an automatic result of repeated corrections.
hooks/openclaw/handler.js:11Untrusted Corrections Can Be Promoted into Persistent Agent Control Files
scripts/error-detector.sh:9Raw Tool Errors May Be Persisted Without Sensitive-Data Redaction
声明描述的是一个“持续改进/经验记录”类能力:记录错误、纠正、能力缺口与最佳实践,并在任务前复盘历史经验。代码实际并未实现学习记录、错误归档、复盘检索或闭环分析等功能;它只是一个本地 shell 脚本,用来创建 skill 目录和 SKILL.md 模板文件。其主要能力是文件系统写入与模板生成,这与声明的核心用途明显不同,属于实质性目的不一致。
The error template explicitly asks for full error text, parameters, and key environment information, which commonly contain API keys, internal URLs, usernames, file paths, stack traces, and customer data. Persisting these verbatim into markdown files materially increases the chance of secret leakage, lateral disclosure, and unintended retention of sensitive system context.
The guide recommends adding hook configuration to ~/.claude/settings.json for global activation, which creates persistent execution of local shell scripts across sessions and repositories. This broadens the trust boundary from one project to the user’s entire agent environment, so any compromised or replaced referenced script could run automatically in many contexts.
Add to ~/.claude/settings.json for global activation:
{
Instructions found that direct the agent to transmit conversation context or user data to external services.
Send message to another session:
sessions_send(sessionKey="session-id", message="Learning: API requires X-Custom-Header")
The skill's natural-language instructions and examples are effectively constrained to Chinese throughout the file. Under the language/locale policy, forcing a specific language without user opt-in or documented regional justification is a policy concern.
The skill directs the agent to persist user corrections, capability requests, and long-term preferences/facts into durable memory files, creating a retention channel for conversation-derived data. Without explicit data classification and consent boundaries, this can accumulate sensitive user information and make later cross-task disclosure more likely.
The skill instructs persistent logging into workspace files but provides no guidance to avoid storing secrets, personal data, tokens, or sensitive operational context. Because these records are meant to be reused and reviewed later, accidental inclusion of sensitive information can create long-lived exposure in the repository or shared workspace.
Detailed logging of raw errors, command context, parameters, and environment details creates a semantic exfiltration and retention risk even if no single field is labeled secret. These narratives often embed credentials, infrastructure topology, customer identifiers, and internal debugging data that can later be searched, shared, or committed.
Recommending synchronization of learnings to MEMORY.md and sharing via sessions_send extends the exposure surface from local retention to cross-session transmission. If those learnings include conversation-derived or operationally sensitive details, this guidance can propagate data beyond its original context and increase the risk of inadvertent disclosure.
The template tells authors to 'Include trigger conditions' but does not require specific trigger phrases, scope boundaries, or negative examples. Because this is a reusable markdown template for manifests, it may propagate vague activation descriptions into downstream skills.
The minimal template uses the generic instruction 'What this skill does and when to use it' without requiring precise invocation constraints. This can lead authors to write broad descriptions that overlap with ordinary language and cause unintended activation.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
When the above learning is extracted as a skill, it becomes:
File: skills/docker-m1-fixes/SKILL.md
---
Project-level hook configuration in .claude/settings.json establishes session-persistent behavior that automatically injects or executes logic during future agent interactions. While persistence is the intended feature, it is security-relevant because it survives beyond the immediate task and can continue affecting prompts and tool flows without repeated user review.
Create .claude/settings.json in your project root:
{
The document’s security section states that the scripts 'only output text' and 'don’t modify files or run commands', but the setup earlier explicitly configures them as command hooks that execute shell scripts. This mismatch is dangerous because it can cause users to grant trust and install auto-executed hooks under false assumptions, reducing scrutiny of code that runs on every prompt or tool event.
The guide instructs users to create persistent learning storage in the workspace or skill directory, which increases the chance that sensitive operational details, user data, or credentials may be retained and later re-injected into future sessions. In this skill's context, persistent memory is a core mechanism, so omissions around data classification, retention, and cleanup make the risk more concrete.
openclaw hooks enable self-improvement
### 3. Create Learning Files
Create the `.learnings/` directory in your workspace:
The document encourages storing learnings in shared workspace files and using cross-session communication, but it does not warn against placing secrets, credentials, personal data, or sensitive internal details into those locations. In a system built around prompt injection from workspace files and transcript visibility across sessions, this can cause unintended propagation and retention of sensitive data beyond the original task context.
No suspicious patterns detected.