Back to skill

Security audit

Memory Layer

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only memory skill is purpose-aligned, but it needs review because it documents persistent conversation logging, scheduled memory mutation, and an unsafe rollback deletion command.

Install only if you want an agent to help design and operate a persistent local memory system. Keep autoDream disabled or in dry-run until you have backups and understand which files it will modify. Do not run the rollback rm -rf command as written; verify backups and move directories aside instead. Avoid storing secrets, health records, financial identifiers, or other private material in plaintext transcripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/architecture.md:57
Finding

Plaintext Retention of Complete Conversation Logs Creates Sensitive Data Exposure

Content
View full analysis

Vulnerability Details

File Location: references/architecture.md, lines 57-80
Vulnerability Type: Plaintext sensitive-data retention
Risk Level: Medium

Evidence

The following is an English translation of the relevant source excerpt:

text
Third layer: Transcript

Location: memory/transcripts/YYYY-MM/*.log

Responsibilities:
- Raw conversation logs
- Temporary, context-specific information
- Source data for the Topic layer

Constraints:
- Limit: 500 KB per file, split daily
- Retention: keep complete records for 90 days, then compress and archive

Data flow:
User request / Cron trigger
         ↓
Write to Transcript (complete log)
         ↓
Extract key facts and update Topic

Related retention behavior is specified in references/transcript-spec.md, lines 89-103:

text
Transcripts older than 90 days:

1. Compress into .gz format
2. Move into memory/transcripts/archive/
3. Retain an index record

Technical Analysis

The architecture directs implementations to write complete conversation logs to plaintext .log files. Although references/transcript-spec.md lines 11-23 prohibit deliberately storing credentials, financial identifiers, and health records, the design does not define a redaction or classification step before the complete log is written.

Conversations can incidentally contain API keys, authentication links, personal data, confidential source code, financial details, or health information. A policy statement alone cannot reliably prevent such content from entering an automatically captured complete transcript.

Archiving old logs with gzip does not provide confidentiality. Gzip is compression rather than encryption, and the design retains archived records indefinitely without specifying deletion, restrictive file permissions, access controls, or encryption at rest. Topic files can also retain extracted personal information, while `references/top ...[truncated 1375 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace “complete log” collection with an explicit data-minimization rule that stores only structured operational events and user-approved summaries.
  2. Add mandatory redaction before disk writes for passwords, API keys, bearer tokens, cookies, private keys, identity numbers, payment data, authentication URLs, and other configured patterns.
  3. Require explicit user consent before transcript capture and provide a per-session option to disable recording.
  4. Default transcript collection to disabled, independently of autoDream and notification settings.
  5. Create transcript files with restrictive permissions, such as owner-only access, and reject unsafe directories or symbolic links.
  6. Encrypt retained transcripts and archives using keys managed separately from the workspace. Do not describe gzip as a security control.
  7. Define a deletion deadline rather than indefinite compressed archival, including deletion from derived indexes and backup systems where feasible.
  8. Prevent sensitive Topic categories, including health, social, and asset records, from being created without explicit consent and protected storage.
  9. Add tests using representative secret formats to confirm that sensitive values never reach transcript, Topic, Index, notification, or report files.

T09 · Insecure Skill Coding Practices

Warning
Location
guides/MIGRATION.md:75
Finding

Rollback Procedure Can Irreversibly Delete Pre-existing Memory Data

Content
View full analysis

Vulnerability Details

File Location: guides/MIGRATION.md, lines 75-81
Vulnerability Type: Unsafe destructive rollback command
Risk Level: Medium

Evidence

bash
rm -rf memory/topics memory/transcripts

cp -r memory.backup.20260403/* memory/
cp MEMORY.md.backup.20260403 MEMORY.md

Technical Analysis

The documented rollback unconditionally and recursively deletes both memory/topics and memory/transcripts. These directories may contain data that existed before migration or new records created after the backup. The procedure does not validate the working directory, verify the backup, ask for confirmation, or distinguish migrated files from unrelated existing content.

Restoration is also incomplete and brittle:

  • The backup name is hardcoded to 20260403, while the backup command uses the current date.
  • The * wildcard does not restore hidden files under the backup directory.
  • No integrity or completeness check occurs before deletion.
  • If either copy command fails after deletion, the workspace remains partially or completely unrecovered.
  • Concurrent transcript writes or scheduled processing can create additional inconsistencies.

The initial backup reduces risk only when it exists, is complete, matches the hardcoded date, and remains readable. The rollback procedure verifies none of those conditions.

Attack Path

  1. A user already has valuable files in memory/topics or memory/transcripts, or new records are written after migration.
  2. The user follows the documented rollback procedure from the workspace root.
  3. rm -rf removes both directory trees without confirmation.
  4. The dated backup is absent, incomplete, stale, or has a different date from the hardcoded restoration path.
  5. Restoration fails or restores only part of the previous state.
  6. Pre-existing files, post-backup transcripts, hidden files, and recent Topic updates are permanently lost unless another ...[truncated 938 chars]
Remediation
View remediation

Remediation Suggestions

  1. Never delete the original directories before verifying that a complete, readable backup exists.
  2. Generate and retain the exact backup path in a variable or manifest rather than using a hardcoded date.
  3. Validate that execution occurs from the intended workspace root and that target paths resolve beneath that root.
  4. Reject symbolic links for rollback targets and backup sources.
  5. Use a reversible rename, such as moving the new directories to a quarantine path, instead of immediately invoking rm -rf.
  6. Restore into a temporary directory first, verify file counts and checksums, and atomically swap directories only after validation.
  7. Use a restoration method that includes hidden files and preserves metadata, such as a reviewed archive or an appropriately configured synchronization tool.
  8. Stop scheduled writers before rollback and restart them only after integrity checks succeed.
  9. Require explicit confirmation that identifies the exact target paths and warns that post-backup changes will otherwise be lost.
  10. Document recovery steps for partial restore failures and retain the quarantined copy until the user confirms successful restoration.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The documented rm -rf memory/topics memory/transcripts command is a high-risk destructive operation that can be abused or mis-executed to delete important data. Because this skill is specifically about restructuring persistent memory storage, the affected directories are likely to contain valuable state, making accidental or unsafe invocation especially dangerous in context.

Content

Scanner excerpt · guides/MIGRATION.md (reported line 77)May include surrounding context.

bash
# 删除新目录
rm -rf memory/topics memory/transcripts

# 恢复备份
cp -r memory.backup.20260403/* memory/

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and main heading are written entirely in Chinese, which imposes a specific language on users without any stated opt-in or alternative. The policy explicitly calls out locale/language constraints as violations when the skill does not offer user choice or justify the restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L098 明确写明“本 Skill 是纯文档设计,memory-system 等工具不存在”,但 L086 又给出 openclaw cron add ... "memory-system auto-dream" 的可执行命令,表示存在可被调度执行的 memory-system 命令。这不是单纯信息缺失,而是文档内部对技能是否实际对应可执行能力产生直接矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

All user-facing instructional text in this example is presented only in Chinese, with no indication that language selection is optional or region-specific. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs appending raw user query data into local transcript log files without any warning, consent, retention limit, redaction guidance, or access control considerations. In a memory-management skill, this creates a realistic privacy and data-handling risk because users may enter secrets or sensitive personal data despite the later policy statement saying such data should not be stored.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The guide documents adding a cron-style scheduled task for automatic execution without warning that it will run continuously in the background. In this skill context, background automation can repeatedly process memory data or trigger side effects without user awareness, increasing privacy, operational, and debugging risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The rollback section includes a destructive rm -rf memory/topics memory/transcripts command with no safety warning, confirmation step, or path validation. In migration documentation, users often copy-paste commands directly; if run in the wrong context or against an unexpected directory layout, this can cause irreversible data loss beyond the intended rollback.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This design stores complete user conversation logs and then derives long-term facts, preferences, and decision rules from them, increasing both the amount of retained sensitive data and the chance of secondary disclosure or misuse. In the context of a memory-management skill handling topics like investments, health, assets, and social data, the extracted memory can become a concentrated repository of highly sensitive personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Transcript layer documents retention of raw conversation logs for 90 days followed by compressed archival, but there is no warning or policy indicating that user conversations will be stored persistently. Persistent retention of natural-language logs can expose sensitive information, especially when users may reasonably assume transient assistant interactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The architecture explicitly describes complete conversation logging, extraction of key facts into Topic files, and summarization into an always-loaded index, but it provides no user-facing consent, notice, or controls over retention. This creates a real privacy and data-governance risk because sensitive user content and inferred preferences may be persistently stored and propagated across layers without the user's awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation describes automated archival of old transcripts and removal/merging of duplicate memory items as part of a scheduled background job, but it does not prominently warn that stored user data may be modified without per-run confirmation. In a memory-management skill, this creates a real integrity risk: users may enable cron and later lose detail, provenance, or recoverability of conversation history due to deduplication, merging, or archiving behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation states that the skill performs file read/write operations and automatic cleanup/archive behavior, but it does not clearly warn users that local memory files may be modified, reorganized, compressed, or archived automatically. In a memory-management skill, this can lead to unintended data changes or perceived data loss because users may enable or schedule automation without understanding its side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON config applies a fixed timezone value of "Asia/Shanghai", which can amount to a locale policy constraint if used globally for scheduling behavior. The file does not indicate that users can choose a timezone or that the setting is justified as region-specific, so it risks forcing a locale without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes a write flow that appends to transcript logs and instructs editing topic and index files, which affects user data on disk. The examples do not include any warning or disclosure that running these steps will modify local files or persist information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill documentation is entirely in Chinese and does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific context. This can violate language/locale policy when users are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documentation appears to force a specific language for all users, and there is no indication that Chinese is optional or required for a region-specific reason. This can violate language/locale policy when users are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill is presented entirely in Chinese and uses a fixed China locale/timezone configuration (Asia/Shanghai) without indicating that language or locale is configurable or user-selected. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 适用于所有文件类型。L059 在配置示例中将时区固定为 Asia/Shanghai,且参数表 L144 也将其作为默认值,但文档未说明这是可选示例、未提供区域选择提示,也未给出该区域限制的明确业务依据。这样的默认区域设定可能构成未获用户选择的 locale 约束。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file contains user-facing specification text solely in Chinese, and there is no indication that users may choose another language or that the skill is explicitly limited to a Chinese-only audience. Under the policy rule for language/locale constraints, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.