Back to skill

Security audit

Llm Memory Publish

Security checks for vulnerabilities and agentic risk

Overview

This skill discloses memory features, but it also automatically downloads an unverified private add-on during installation and checks it at startup.

Review before installing. Use --no-hooks unless you explicitly trust the publisher and the CNB repository, and prefer a version that pins and verifies the private package. Treat the downloaded private component as separate executable code with possible native extensions and API access.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
hooks/postinstall.py:81
Finding

Automatic Retrieval of an Unpinned and Unverified Remote Code Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
_meta.json:42
Finding

Security Metadata Incorrectly Denies Remote Code and Native-Extension Capabilities

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (58)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description says the skill will automatically pull a private enhancement package from a CNB repository after installation. The supplied code instead runs as an on-startup hook, checks a local 'src/privileged' directory, queries Git state and upstream commit information, writes a status log, and tells the user to run commands manually for install or update. This is a material description-behavior mismatch in both primary behavior and trigger timing. While the code does interact with Git remotes, it does not actually perform the declared automatic pull/install action.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims post-install automatic behavior ('安装后自动从 CNB 仓库拉取私有增强包'), which would imply network access and install/automation logic. In the supplied code chunk, there is no such behavior: no hook registration, no subprocess/package manager invocation, no HTTP/git access, and no install-time execution. The code only re-exports interfaces and safe implementations, plus metadata including a URL for an optional private enhancement package. Therefore the declared description overstates capabilities and does not accurately represent the actual behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code chunk is limited to an init.py that re-exports interface definitions. While this is consistent with an 'interface layer,' it does not implement or indicate any automatic installation-time hook, private package retrieval, or CNB repository interaction described in the declared purpose. Therefore the description materially overstates behavior present in this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims install-time automated behavior and pulling a private package from a CNB repository, which would imply automation hooks and likely network/repository access. The actual code does none of that: it is a pure abstract interface definition for memory storage operations. While the code is related to 'memory' at a high level, its primary purpose is substantially different from the declared description. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes installation-time automation and automatic retrieval of a private package from a CNB repository. The supplied code only declares an abstract interface for memory/search operations and contains no implementation for hooks, package installation, repository access, or network communication. While the memory-related theme loosely overlaps, the primary described behavior is not represented by this code chunk, making this a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The description emphasizes installation-time automation and retrieval of private enhancement packages from a CNB repository. In contrast, the actual code is limited to an abstract interface for vector backend operations used in memory/search infrastructure. It neither implements hooks nor accesses external repositories or private packages. This is not merely an implementation detail omission; the primary stated capability is absent from the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description emphasizes an integration layer plus automated hooks that automatically retrieve a private enhancement package from a CNB repository after installation. The supplied code instead is a self-contained local implementation of memory storage and full-text search using SQLite. Its only 'triggers' are SQLite table triggers for maintaining the FTS index, which are unrelated to install-time automation hooks. There is no network access, repository interaction, package download, or private package integration. This is a clear description-to-behavior mismatch, with the actual code serving a different primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description emphasizes post-install automation and repository retrieval of a private package, implying network/repository access and install hooks. The actual code chunk is exclusively a test runner (unittest) for local modules under src/core, validating imports and basic behaviors such as ANN search, cosine similarity, NUMA/cache/IRQ/FMA/Kunpeng status checks, hugepage stats, and SQLite implementation detection. There are no triggers, package-install hooks, CNB interactions, network operations, or private package retrieval logic in this code. This is a material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description claims an interface-layer and automation-hook component for LLM memory integration that automatically fetches a private enhancement package from a CNB repository after installation. The supplied code does none of that. It is strictly a local test file for CI/CD validation: it manipulates Python import paths, imports internal modules, checks package exports and class inheritance, prints status lines, and exits with success/failure. There is no network access, repository interaction, package installation logic, post-install trigger, or memory-integration functionality. This is a clear material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document makes a materially misleading safety claim by labeling the public package as 'zero risk' and 'no network/subprocess use' while elsewhere documenting a postinstall hook that automatically performs a remote git clone. That behavior introduces network access, code retrieval, and likely subprocess execution at install time, which can conceal supply-chain risk from users and reviewers.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The explicit goal that 'users need not know the private package exists' is a major red flag because it normalizes covert acquisition of remote code unrelated to the visible public package boundary. In the context of an install/startup hook system, hidden retrieval of a private package materially increases supply-chain risk and undermines informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented behavior adds automatic cloning and deployment of a private package during installation, which materially expands the skill's effective behavior beyond what a normal public package description implies. Pulling additional code at install time introduces a supply-chain trust boundary and can bypass user expectations and some review controls applied only to the published package contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Advertising hidden post-install behavior as 'user-unnoticed' is especially dangerous because it frames stealthy environmental modification as a product advantage. In this context, the hidden action is remote code retrieval and deployment, which heightens the risk of covert supply-chain compromise and undermines informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document claims the public package has 'no network access' while elsewhere stating that an install hook automatically clones a private package from a remote CNB repository. This is a materially misleading security claim that can cause reviewers and users to underestimate supply-chain and post-install execution risk, especially because the network activity occurs automatically during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares powerful capabilities through metadata and lifecycle hooks, including network access, filesystem writes, and use of external binaries, but does not define a clear tool-scope/allowed-tools policy. Combined with automatic postinstall and startup execution that pulls a private package into a privileged path, this creates a supply-chain and arbitrary code execution risk with insufficient constraint visibility.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description includes Chinese-only text ('接口层 + 自动化钩子。安装后自动从 CNB 仓库拉取私有增强包。') while the rest of the skill metadata does not indicate that the skill is region-specific or that users can choose their preferred language. This creates a natural-language locale policy concern because the skill appears to impose a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest explicitly advertises automatic post-install retrieval of a private package from a remote CNB repository, but does not define clear user consent, integrity verification, version pinning, or activation constraints. In this skill’s context, that is dangerous because the downloaded 'privileged' package extends functionality outside the reviewed manifest and is written into a privileged path, creating a supply-chain and hidden-capability risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest explicitly advertises automatic post-install and startup hooks that fetch a private enhancement package from a remote CNB repository, while giving no activation constraints, integrity guarantees, or user-consent controls. In this skill context, that means installation can trigger hidden remote code introduction into a privileged local path, substantially increasing supply-chain and persistence risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Several user-facing manifest fields, including the main description and operational descriptions, are written in Chinese with no indication that the user can choose another language. For a general-purpose skill manifest, this constitutes a language/locale policy concern because it imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The stated purpose of the skill is an interface layer, but the documented design goal is to let users unknowingly receive a private enhancement package via lifecycle hooks. That mismatch is a transparency and trust-boundary problem because it obscures that installation includes hidden remote retrieval and deployment beyond the apparent feature scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes automatic network retrieval and deployment of a private package during installation but does not frame this with a strong user-facing warning about network access, code provenance, privilege implications, or filesystem modification. That omission increases the chance that users install the skill without understanding that installation changes system state and imports external code.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document presents inconsistent statements about update behavior: it says updates are not automatically executed, but also describes automatic startup-time update checks and highlights automated update detection as a core advantage. Even if code is not auto-executed, silent background version checks still create undeclared network activity and can mislead users about system behavior.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · docs/ARCHITECTURE.md (reported line 158)May include surrounding context.

检查:

bash
# 查看私有包目录
ls -la ~/.openclaw/workspace/skills/llm-memory-integration/src/privileged/

# 查看状态日志
cat ~/.openclaw/workspace/skills/llm-memory-integration/.privileged_status.log

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Describing the feature as requiring no user action and being 'unnoticed' while it silently retrieves and deploys a private package normalizes hidden installation-time behavior. That mismatch reduces informed consent and can conceal meaningful changes to the user's environment, increasing the risk of supply-chain abuse or unexpected code introduction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation promotes automatic network cloning and deployment during installation without an up-front warning proportionate to its impact. Users may install the skill believing it is a standard package, while it actually changes the system by downloading and deploying additional code from a remote source.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.