Back to skill

Security audit

Session Persistence 会话上下文持久化

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a local session-memory helper, but it automatically saves and reloads conversation summaries without enough controls or complete install instructions.

Install only if you are comfortable with OpenClaw saving and reusing local conversation summaries. Review any AGENTS.md changes manually before applying them, avoid saving secrets or sensitive business/personal data, and periodically inspect or delete the ./memory files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill states that persistence actions are 'automatically triggered' but does not define the trigger conditions, scope, or opt-out boundaries. In a persistence-oriented skill, ambiguous automation can lead to unintended data collection, file writes, or context loading across sessions, which increases the risk of privacy leaks and unsafe behavior propagation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The markdown describes automatic reading and writing of session summaries without clearly warning users that conversation data will be persisted. Because the skill's core purpose is storing and restoring prior context, failure to disclose persistence behavior can cause unintentional retention of sensitive prompts, secrets, or personal data across sessions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.