Back to skill

Security audit

PAFH-Memory

Security checks for vulnerabilities and agentic risk

Overview

This personalization skill is mostly transparent about local memory use, but it gives broad access to profile files and permits persistent logging of inferred user habits without clear per-update consent.

Install only if you are comfortable with a skill that reads local memory/profile files and writes persistent preference records. Before use, narrow its activation, remove or require confirmation for automatic daily observations, avoid storing contacts/locations/schedules unless explicitly needed, and review the memory files regularly.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:147
Finding

Persistent Storage of Inferred Personal Observations Without Per-Update Consent

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:22
Finding

Overbroad Access to Identity and Personal Profile Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description mixes 'triggered when applying the PAHF loop' with general behavioral guidance, making it unclear whether the skill should activate as an explicit tool or just serve as internal methodology. This ambiguity can lead to inconsistent invocation and accidental use of memory features when the agent should simply answer normally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger conditions are broad enough to match many ordinary conversations, such as any expression of habits, corrections, or decisions with multiple valid options. That increases the chance of unintended invocation, causing unnecessary memory access, preference inference, and persistent storage in contexts where the user did not expect personalization logic to activate.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill explicitly supports cross-session storage and tracking of preferences over time in local files, including data from USER.md and IDENTITY.md. Session persistence is the skill's purpose, but it still creates real privacy and profiling risk if retention scope, user approval, and deletion/review controls are not rigorously enforced.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
scope: |
    This skill will:
    - Read your preference memory files (MEMORY.md, USER.md, etc.)
    - Write preference updates to these files
    - Track preference changes over time
    
    Your preferences will be stored locally in ~/.openclaw/workspace/memory/

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that user consent is required for persistent preference storage, but the feedback-integration logic then allows some preference writes to occur automatically in daily logs without explicit confirmation. This contradiction can cause personal data to be stored persistently even when the user has not clearly agreed to that specific retention behavior, undermining privacy expectations and informed consent.

Content

No source excerpt is available for this finding.

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Encouraging the agent to 'remember this for future interactions' is a persistence mechanism that can inject user-provided instructions or preferences into future sessions. In a personalization skill this is expected behavior, but it becomes dangerous when combined with broad triggers and inconsistent consent because it can carry forward manipulated, outdated, or unauthorized context.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
# Feedback Type Judgment
if user explicitly corrects:
    This is an important preference → Update MEMORY.md
    Ask: "Should I remember this for future interactions?"
    
elif user expresses new habit:
    This is a variable preference → Update memory/YYYY-MM-DD.md

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

The instruction to 'Record without asking' authorizes autonomous persistence of inferred user habits into a dated memory log. Because the skill reads and writes personal and identity-related files, this creates a real risk of silently storing behavioral data without meaningful consent or verification.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
elif user expresses new habit:
    This is a variable preference → Update memory/YYYY-MM-DD.md
    Record without asking (daily log)
    
elif user simply confirms:
    Validated preference → Optionally record

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The write-confirmation table says some preference updates and observations do not require confirmation, which directly conflicts with the earlier statement that user consent is required for persistent preference storage. In practice, this can normalize silent retention of user behavior and create unauthorized profile building across sessions.

Content

No source excerpt is available for this finding.

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill injects content designed to persist in agent memory or context across interactions. Persistent injection can alter agent behavior long after the initial interaction.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

Example 1: Learning New Preference

text
User: "From now on, always send reports in PDF format"

PAHF Response:
1. Pre-action: ✓ Clear instruction, no clarification needed

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The example operationalizes the same unsafe pattern by instructing the agent to record a preference with 'No confirmation needed.' Examples are often followed as normative guidance, so this increases the likelihood that agents will persist user preferences automatically in routine tasks.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

  1. Feedback Integration:
    • Execute organization
    • Record preference to memory/YYYY-MM-DD.md
    • No confirmation needed (daily observation)
text

### Example 3: Preference Drift Detection

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 325)May include surrounding context.

md
1. **Don't Implicitly Assume**: Ask if uncertain
2. **Don't Over-record**: Recording every detail creates noise
3. **Don't Ignore Changes**: "This time is different" is an important signal
4. **Don't Store Without Consent**: Ask for significant new preferences

---

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document says sensitive data must never be stored, but later defines free-form personal fields such as home, work, frequent places, contacts, and routines that can easily capture health, financial, credential-adjacent, or other sensitive details in practice. This mismatch creates a policy gap where the implementation schema invites exactly the kind of data the privacy guidance claims to forbid.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Restricting language preference to zh or en hard-codes an unjustified limitation that can misrepresent users and force inaccurate storage of identity or communication preferences. While not a classic security exploit, it is a data-handling flaw that can lead to exclusion, incorrect personalization, and unsafe assumptions in multilingual contexts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema explicitly permits storing personal contacts, locations, and schedules, which goes beyond narrow preference personalization and creates a repository of sensitive personal profile data. Even if intended for convenience, these fields increase privacy risk, enable over-collection, and could expose users to tracking or social engineering if memory is misused or leaked.

Content

No source excerpt is available for this finding.

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
86% confidence
Finding

The design encourages persisting behavior-guiding context across future interactions, which can become a durable prompt/context injection channel if incorrect, manipulated, or adversarially induced preferences are stored. In a personalization framework, this is particularly risky because future agent actions may be silently steered by stale or maliciously planted memory.

Content

Scanner excerpt · references/preference-schema.md (reported line 209)May include surrounding context.

md
- Same feedback appears 3+ times
- Preference persists over 2 weeks

**With confirmation**: Ask "Should I remember this for future interactions?"

### When to Only Update Short-term Memory (memory/YYYY-MM-DD.md)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The schema authorizes automatic logging of daily observations without confirmation, which allows the agent to infer and persist user traits without explicit consent. In the context of a memory system, this increases the risk of covert profiling, inaccurate inferences, and unauthorized accumulation of behavioral data over time.

Content

Scanner excerpt · references/preference-schema.md (reported line 217)May include surrounding context.

md
- Temporary needs
- Patterns under observation

**No confirmation needed**: Daily observations are logged automatically.

### Preference Expiration Handling

Static analysis

No suspicious patterns detected.