Back to skill

Security audit

人脑系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned as a memory and self-maintenance system, but it broadly persists, copies, recalls, and backs up private workspace and cross-skill state with insufficient scoping.

Install only if you explicitly want a local agent memory system that writes durable files and may duplicate private workspace state. Review or remove the cross-skill authority reads, broad backup scope, raw recall outputs, watcher behavior, and PID shell check before using it in a sensitive workspace.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/brain_fullness.py:23
Finding

Shell Command Injection Through Unvalidated PID File Content

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
scripts/remember.py:6
Finding

Persistent Agent Memory Poisoning Through Arbitrary Recall Content

Content
View full analysis
", file=sys.stderr) raise SystemExit(2) ws = Path('/root/.openclaw/workspace') today = datetime.now().strftime('%Y-%m-%d') entry = f"- {datetime.now().strftime('%Y-%m-%d %H:%M:%S')} — {text}\n" for rel in ['memory/DO_NOT_FORGET.md', f'memory/{today}.md']: p = ws / rel p.parent.mkdir(parents=True, exist_ok=True) with p.open('a', encoding='utf-8') as f: f.write('\n' + entry if p.stat().st_size else entry) print('remembered:', text) ``` ### Technical Analysis The utility accepts arbitrary command-line text and stores it in both pinned memory and the daily memory log. It does not distinguish facts from instructions, record the source or trust level, require approval, filter secrets, or assign an expiration policy. Other project components automatically recall `memory/DO_NOT_FORGET.md`. Consequently, attacker-controlled content written by this utility can continue influencing future sessions after the original invocation has ended. The input is also echoed to stdout, which can place sensitive content in execution logs. ### Attack Path 1. An attacker or untrusted workflow causes the agent to invoke `remember.py` with adversarial content. 2. The content is appended to `memory/DO_NOT_FORGET.md` and the current daily log. 3. `boot_recall.py`, `recall_core.py`, checkpoint creation, consolidation, or dream generation subsequently reads that content. 4. The content is reintroduced into future agent context as durable memory. 5. The agent may follow the stored instruction, disclose context, change behavior, or propagate the content into additional files. ### Impact Assessment The vulnerability can persistently manipulate future agent decisions and con ...[truncated 298 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/boot_recall.py:6
Finding

Raw Private Memory and Cross-Skill Authority State Exposed Through Recall Output

Content
View full analysis
6000: txt = '[tail only]\n' + txt[-6000:] print(f'\n## {rel}\n```\n{txt}\n```') ckpts = sorted(glob.glob(str(ws / 'context-checkpoints' / 'checkpoint-*.md'))) if ckpts: p = Path(ckpts[-1]); txt = p.read_text(errors='replace') print(f'\n## latest checkpoint: {p.name}\n```\n{txt[-6000:]}\n```') ``` `scripts/recall_core.py`: ```python files = [ 'memory/DO_NOT_FORGET.md', 'skills/brain-system/state/brain-state.json', 'skills/server-body-ops/state/authority.json', 'TOOLS.md', ] for rel in files: p = ws / rel if p.exists(): print(f'\n===== {rel} =====') txt = p.read_text(errors='replace') print(txt[-8000:] if len(txt) > 8000 else txt) ``` ### Technical Analysis Both recall utilities read broad, raw content from private memory, tool configuration, task/checkpoint state, and another skill's authority state. The only data minimization is a character limit; there is no field allowlist, secret redaction, purpose check, or authorization boundary. Printing this data to stdout can expose it to terminal history, process supervisors, agent execution logs, remote observability systems, or downstream model context. Reading `skills/server-body-ops/state/authorit ...[truncated 851 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/context_checkpoint.py:19
Finding

Unredacted Sensitive State Duplicated Into Checkpoints, Consolidations, and Dream Files

Content
View full analysis
12000: txt = txt[-12000:] txt = '[truncated: kept tail]\n' + txt parts.append(f'## {rel}\n```\n{txt}\n```\n') out.write_text('\n'.join(parts), encoding='utf-8') ``` `scripts/sleep_consolidate.py`: ```python sections = [f'# Sleep Consolidation {today}\n'] for rel in ['memory/DO_NOT_FORGET.md', 'skills/brain-system/state/brain-state.json', 'skills/server-body-ops/state/authority.json', 'skills/brain-system/state/task-queue.json']: p = ws / rel if p.exists(): txt = p.read_text(errors='replace') if len(txt) > 4000: txt = '[tail only]\n' + txt[-4000:] sections.append(f'## {rel}\n```\n{txt}\n```\n') ckpts = sorted(glob.glob(str(ws / 'context-checkpoints' / 'checkpoint-*.md'))) if ckpts: sections.append(f'## Latest checkpoint\n- {ckpts[-1]}\n') out.write_text('\n'.join(sections), encoding='utf-8') ``` `scripts/autoclaw_dream.py`: ```python texts=[] for rel in ['memory/DO_NOT_FORGET.md', f"memory/{datetime.now().strftime('%Y-%m-%d')}.md", 'skills/brain-system/state/brain-state.json', 'skills/server-body-ops/state/authority.json']: p=ws/rel if p.exists(): texts.append((rel,p.read_text(errors='replace')[-8000:])) content='\n'.join(f'## {r} ...[truncated 2692 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/brain_backup.sh:3
Finding

Overbroad Unencrypted Backup of Private and Cross-Skill Workspace Data

Content
View full analysis
/tmp/brain-backup-warn.log || true if [ ! -s "$out" ]; then tar -czf "$out" -C /root/.openclaw/workspace memory skills/brain-system skills/server-body-ops context-checkpoints fi echo "$out" ``` ### Technical Analysis The backup includes user profiles, agent instructions, tool configuration, long-term memory, all brain-system files, another skill's files, and checkpoints. This scope is substantially broader than the minimum data required to back up brain-system state. The archive is compressed but not encrypted. Its access permissions depend on the process umask because the script does not set a restrictive umask or explicitly set archive permissions. The warning log is also written to the shared `/tmp` directory. The use of `|| true` suppresses archive errors, which can result in incomplete backups being accepted as successful if a nonempty partial archive remains. ### Attack Path 1. A privileged user or agent invokes the backup script. 2. Sensitive workspace data is aggregated into a single archive. 3. Another process or account with access to the archive path, workspace, or backup artifact copies the file. 4. The attacker decompresses the archive without needing a key. 5. The attacker obtains private memory, user data, operational configuration, agent instructions, and cross-skill state. ### Impact Assessment Compromise of one archive can disclose a large portion of the agent workspace. Depending on the contents of `TOOLS.md`, memory, o ...[truncated 216 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
scripts/status_dashboard.py:12
Finding

Unnecessary Privilege and Host Reconnaissance in Status Dashboard

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill describes itself as a cognitive operating protocol, but also references file monitoring, hot-reload watching, event logging, and automatic subprocess execution across other resources. This materially changes the risk profile from passive guidance to active automation, creating opportunities for unintended code execution chains and persistent surveillance of workspace changes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill describes itself as a cognitive operating protocol, but also references file monitoring, hot-reload watching, event logging, and automatic subprocess execution across other resources. This materially changes the risk profile from passive guidance to active automation, creating opportunities for unintended code execution chains and persistent surveillance of workspace changes.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 400)May include surrounding context.

md
- Skill installed → expect directory and `SKILL.md` to exist.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/brain_fullness.py (reported line 28)May include surrounding context.

python
lob(str(ws/'skills/brain-system/backups/openclaw-brain-backup-*.tar.gz')))))
pidfile=ws/'skills/brain-system/state/hot-reload.pid'
hot=False
if pidfile.exists():
    pid=pidfile.read_text().strip()
    hot=subprocess.run(['bash','-lc',f'kill -0 {pid}'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL).returncode==0
checks.append(('hot reload running', hot))
cron=subprocess.run(['bash','-lc','crontab -l 2>/dev/null | grep -q OPENCLAW_BRAIN_SYSTEM'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL).returncode==0
checks.append(('cron installed', cron))
score=sum(v for _,v in checks); total=len(checks)
print(f'brain_fullness={score}/{total} ({score/total*10:.1f}/10)')
for k,v in checks: print(('✅' if v else '❌'), k)

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code intentionally aggregates sensitive durable state into a daily markdown file, including authority and task-queue information that may reveal privileges, internal policies, plans, or other operationally sensitive context. Consolidation amplifies risk because it centralizes disparate secrets or sensitive metadata into an easy-to-find, human-readable artifact that could be exfiltrated or misused if accessed.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill repeatedly instructs the agent to read, write, checkpoint, back up, and run local scripts, yet the manifest does not declare any explicit tool scope or permissions. That mismatch weakens operator visibility and review, making it easier for a broadly triggered skill to access or mutate workspace state without clear user awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are extremely broad, including everyday terms like memory, reflection, optimization, and attention management. Broad activation increases the chance the skill engages in contexts where users did not intend persistent memory, maintenance actions, or script-backed workflow changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill strongly promotes episodic, semantic, and procedural memory storage into multiple files, but does not present an upfront warning that user/project data may be persisted across sessions. This is risky because users may disclose sensitive information under the assumption of transient chat behavior while the skill externalizes it into durable storage.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The guidance to 'fix the issue first' and 'act directly' encourages the agent to take autonomous action based on inferred user preference, which can bypass meaningful confirmation in ambiguous situations. In a skill that also supports persistent memory, configuration changes, installs, and maintenance actions, this increases the chance of unauthorized or overly broad changes.

Content

Scanner excerpt · SKILL.md (reported line 430)May include surrounding context.

md
- Fix the issue first, then summarize evidence.
- Convert the correction into a durable rule if likely to recur.
- Match verbosity to the user’s current preference; if they ask “just do it”, act directly.
- Avoid defensiveness and avoid claiming success without verification.

## Goal Stack

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The maintenance stack includes backup, consolidation, dashboard, queue, and hot-reload scripts that can write files and create archives, yet this behavior is not surfaced as a clear warning before use. Users may therefore enable a seemingly organizational skill without understanding that autonomous maintenance can create additional copies of workspace data and modify local state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script copies content from multiple durable memory/state files, including authority-related state, into a new markdown file under workspace storage without minimization, consent, or access-control checks. This creates data propagation and retention risk: sensitive operational context may be duplicated into a broader or less-governed location, increasing exposure if other skills, users, or processes can read the dreams directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script enumerates and prints multiple workspace state files that are likely to contain sensitive internal context, including pinned memory, checkpoints, authority state, task queue contents, and tool metadata. Even though it only reads local files, its purpose is to surface potentially confidential data into agent-visible/output-visible context without access control, minimization, or user disclosure, which can enable prompt/context exfiltration and leakage of secrets, system state, or privileged operational instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script creates a compressed backup of workspace files that appear to include memory, context, agent instructions, and other potentially sensitive operational data, and stores it on disk under a predictable root-owned path. Even though this looks like a maintenance feature rather than malicious behavior, writing such archives without explicit consent, retention controls, or permission hardening increases the risk of sensitive data exposure if the host is later accessed, backed up elsewhere, or the archive is mishandled.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/brain_fullness.py (reported line 7)May include surrounding context.

python
ws=Path('/root/.openclaw/workspace')
checks=[]
def exists(label, rel): checks.append((label, (ws/rel).exists()))
exists('brain skill', 'skills/brain-system/SKILL.md')
exists('brain state', 'skills/brain-system/state/brain-state.json')
exists('server authority', 'skills/server-body-ops/state/authority.json')
exists('pinned memory', 'memory/DO_NOT_FORGET.md')

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/hot_reload_watch.py (reported line 18)May include surrounding context.

python
ws=Path('/root/.openclaw/workspace')
checks=[]
def exists(label, rel): checks.append((label, (ws/rel).exists()))
exists('brain skill', 'skills/brain-system/SKILL.md')
exists('brain state', 'skills/brain-system/state/brain-state.json')
exists('server authority', 'skills/server-body-ops/state/authority.json')
exists('pinned memory', 'memory/DO_NOT_FORGET.md')

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
87% confidence
Finding

The script reads a PID from a workspace file and interpolates it directly into a bash -lc command. If an attacker can tamper with skills/brain-system/state/hot-reload.pid, they could inject shell metacharacters and execute arbitrary commands in the script's security context.

Content

Scanner excerpt · scripts/brain_fullness.py (reported line 26)May include surrounding context.

python
hot=False
if pidfile.exists():
    pid=pidfile.read_text().strip()
    hot=subprocess.run(['bash','-lc',f'kill -0 {pid}'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL).returncode==0
checks.append(('hot reload running', hot))
cron=subprocess.run(['bash','-lc','crontab -l 2>/dev/null | grep -q OPENCLAW_BRAIN_SYSTEM'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL).returncode==0
checks.append(('cron installed', cron))

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/brain_fullness.py (reported line 28)May include surrounding context.

python
pid=pidfile.read_text().strip()
    hot=subprocess.run(['bash','-lc',f'kill -0 {pid}'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL).returncode==0
checks.append(('hot reload running', hot))
cron=subprocess.run(['bash','-lc','crontab -l 2>/dev/null | grep -q OPENCLAW_BRAIN_SYSTEM'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL).returncode==0
checks.append(('cron installed', cron))
score=sum(v for _,v in checks); total=len(checks)
print(f'brain_fullness={score}/{total} ({score/total*10:.1f}/10)')

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/brain_fullness.py (reported line 28)May include surrounding context.

python
pid=pidfile.read_text().strip()
    hot=subprocess.run(['bash','-lc',f'kill -0 {pid}'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL).returncode==0
checks.append(('hot reload running', hot))
cron=subprocess.run(['bash','-lc','crontab -l 2>/dev/null | grep -q OPENCLAW_BRAIN_SYSTEM'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL).returncode==0
checks.append(('cron installed', cron))
score=sum(v for _,v in checks); total=len(checks)
print(f'brain_fullness={score}/{total} ({score/total*10:.1f}/10)')

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/hot_reload_watch.py (reported line 20)May include surrounding context.

python
WATCH_PATHS = [
    WS / 'skills/brain-system/SKILL.md',
    WS / 'skills/brain-system/state/brain-state.json',
    WS / 'skills/server-body-ops/SKILL.md',
    WS / 'skills/server-body-ops/state/authority.json',
    WS / 'memory/DO_NOT_FORGET.md',
    WS / 'TOOLS.md',

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/hot_reload_watch.py (reported line 73)May include surrounding context.

python
]
    for cmd in cmds:
        try:
            subprocess.run(cmd, cwd=str(WS), check=False, stdout=subprocess.PIPE, stderr=subprocess.STDOUT, text=True, timeout=30)
        except Exception as e:
            log(f'refresh command failed {cmd}: {e}')
    log('hot-reloaded changed=' + ','.join(Path(p).name for p in changed))

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The recall script for the brain-system skill reads and prints skills/server-body-ops/state/authority.json, which belongs to a different skill and is outside the stated memory-recovery scope. This creates an unnecessary cross-skill data exposure path: when invoked for session recovery, it can disclose sensitive authority or privilege state to logs, downstream agents, or users who should only receive brain-system context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads multiple durable state files, including memory, authority, and task data, and republishes their contents into a single markdown consolidation note. This increases exposure of sensitive internal state, creates a secondary copy that may have weaker access controls, and does so without minimization, consent, or disclosure boundaries.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/status_dashboard.py (reported line 14)May include surrounding context.

python
print('🧠 OpenClaw Brain/Body Dashboard')
print('workspace=', ws)
print('\n== root ==')
subprocess.run(['id'])
print('\n== exec policy ==')
subprocess.run(['openclaw','exec-policy','show'], stdout=subprocess.PIPE, stderr=subprocess.STDOUT, text=True)
brain=load('skills/brain-system/state/brain-state.json') or {}

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The dashboard exposes host identity and execution-policy details that exceed the stated cognitive/status purpose of the skill. In an agent environment, this kind of environmental reconnaissance can help map privileges, execution constraints, and operating context for later misuse or chaining with other capabilities.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Host-level inspection via id and execution-policy queries is not clearly aligned with the advertised 'brain-system' function and adds unnecessary reconnaissance capability. In context, this makes the skill more dangerous because it normalizes gathering environment and privilege data under a benign-looking dashboard label.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.