Back to skill

Security audit

Llm Memory V8 Fix

Security checks for vulnerabilities and agentic risk

Overview

This skill discloses its memory features, but it automatically downloads unaudited code from a remote Git repository during install, which needs careful review before use.

Review this skill before installing. Only use it if you trust the remote CNB repository and are comfortable with install-time git cloning of mutable, unaudited code into the skill directory. Prefer disabling hooks or requiring a pinned, signed, hash-verified package before enabling the private enhancement component.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
hooks/postinstall.py:57
Finding

Automatic Installation of an Unpinned and Unverified Remote Code Package

Content
View full analysis

Vulnerability Details

File Location: hooks/postinstall.py:57-58, 80-91, 110-128
Vulnerability Type: Unverified remote payload retrieval and installation
Risk Level: High

Vulnerable Code

python
def get_privileged_url() -> str:
    """获取私有包 URL"""
    return "https://cnb.cool/llm-memory-integrat/llm.git"
python
try:
    # 如果目标目录已存在,先删除
    if target_dir.exists():
        log(f"目标目录已存在,删除旧版本...")
        shutil.rmtree(target_dir)
    
    # 克隆仓库
    result = subprocess.run(
        ["git", "clone", "--depth", "1", url, str(target_dir)],
        capture_output=True,
        text=True,
        timeout=120
    )
    
    if result.returncode != 0:
        log(f"克隆失败: {result.stderr}", "ERROR")
        return False
    
    log(f"克隆成功!")
    return True
python
def verify_privileged_package(target_dir: Path) -> bool:
    """
    验证私有包完整性
    
    Args:
        target_dir: 私有包目录
    
    Returns:
        bool: 是否有效
    """
    required_files = [
        "README.md",
        "hybrid_memory_search.py",
        "smart_memory_update.py"
    ]
    
    for file in required_files:
        if not (target_dir / file).exists():
            log(f"缺少必需文件: {file}", "WARN")
            return False
    
    log("私有包验证通过")
    return True

Technical Analysis

The post-installation lifecycle hook automatically clones the current default branch of an external private repository into src/privileged. The clone is not pinned to an immutable commit or signed release. Consequently, the code installed for two users—or for the same user at different times—can differ even though the reviewed public Skill package has not changed.

The integrity check only confirms that three expected filenames exist. It does not verify file hashes, a signed manifest, a trusted Git commit, repository ownership, or the contents of any Python or ...[truncated 2746 chars]

Remediation
View remediation

Remediation Suggestions

  1. Avoid post-review code retrieval

    • Package and audit all required implementation files as part of the published Skill.
    • Do not automatically install executable remote content during a lifecycle hook.
  2. Pin an immutable artifact

    • If remote retrieval is unavoidable, pin a specific full Git commit hash rather than cloning the mutable default branch.
    • Prefer a versioned, immutable release artifact over a shallow branch clone.
  3. Perform cryptographic verification

    • Publish a signed manifest containing a hash for every downloaded file.
    • Verify the manifest with a trusted publisher public key embedded in the reviewed package.
    • Reject and remove the payload if signature, commit, or hash validation fails.
    • Do not treat filename existence as integrity verification.
  4. Require explicit user consent

    • Disable remote package installation by default.
    • Present the exact source, version, commit hash, permissions, native-code status, and integrity information before download.
    • Require a separate explicit action to install or activate the privileged implementation.
  5. Use safe installation semantics

    • Download into a newly created staging directory.
    • Verify the complete staged package before replacing an existing installation.
    • Atomically move the verified directory into place.
    • Preserve the previous trusted version if retrieval or verification fails.
  6. Restrict runtime exposure

    • Keep downloaded code outside automatically importable package paths until verification and activation are complete.
    • Run privileged or native components in a sandbox with minimal filesystem, credential, subprocess, and network permissions.
  7. Correct security metadata

    • Declare that the optional package contains executable code and may contain native extensions.
    • Clearly distinguish the reviewed public package from the s ...[truncated 41 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description’s key promise is automatic retrieval of a private enhancement package from a CNB repository after installation. The code does something materially different: on each startup it checks for a local 'src/privileged' directory, determines whether it is a Git repo, runs Git commands to inspect current and upstream commits, and writes a '.privileged_status.log' file. If missing or outdated, it only prints manual commands ('python3 hooks/postinstall.py' or 'git pull'); it does not perform an automatic pull or installation. This is a meaningful description-behavior mismatch because the primary behavior is startup-time monitoring/status reporting, not automatic package fetching.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description claims two notable behaviors beyond being an interface layer: '自动化钩子' and automatic pulling of a private enhancement package from CNB after installation. In the provided code chunk, the package acts as an interface/export module and metadata container. It imports and re-exports interfaces and safe implementations, defines version/author data, and stores the CNB URL as a string constant labeled as optional private enhancement package information. There is no code for network access, package download, install hooks, subprocess execution, or any automation mechanism. Therefore, the description materially overstates the behavior present in this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description includes significant behavior beyond an interface definition layer, specifically automatic retrieval of a private enhancement package from a CNB repository after installation. The supplied code chunk does not implement installation hooks, network access, repository access, or package pulling. It only exposes interface symbols for search, memory, and vector components. While the interface-layer portion loosely matches, the claimed automatic hook/install behavior is not represented, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes automatic installation-time behavior and pulling a private enhancement package from a CNB repository. The actual code chunk is limited to an abstract interface definition for memory storage operations. While the memory-related aspect loosely aligns with 'memory integration,' the primary declared behavior—automatic hook execution and private package retrieval—is not present at all. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description emphasizes automatic installation-time behavior and fetching a private enhancement package from a CNB repository. The supplied code does not implement any such behavior. Instead, it only declares an abstract interface for memory/search operations (search, add, delete, get). This is a materially different primary purpose and omits the claimed repository/network automation entirely, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description emphasizes automatic installation-time behavior and fetching a private package from a CNB repository. The supplied code does not implement any of that. Instead, it is only an abstract interface definition for vector storage/search backends used in memory systems. This is a materially different purpose and omits the declared network/repository automation capabilities entirely.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description centers on installation-time integration behavior—specifically automatic retrieval of a private enhancement package from a CNB repository. The supplied code does nothing related to installation hooks, remote repositories, networking, package retrieval, authentication, or private package integration. Instead, it provides a self-contained local memory/search implementation using SQLite and FTS5. This is a materially different primary purpose, and the actual code introduces a significant undeclared capability (persistent local memory storage and search). Therefore the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description emphasizes an interface layer plus automation hooks that automatically download a private enhancement package from CNB after installation. The actual code chunk is strictly a test runner (tests/test_all.py) for validating imports and basic behaviors of various modules such as ANN indexes, vector ops, SQLite extensions, NUMA/cache/IRQ/FMA/hugepage optimizers, and Kunpeng detection. There is no network access, repository pull, package installation, hook registration, or installation-triggered logic. Because the code's primary purpose is materially different from the declared purpose and the claimed auto-fetch capability is absent, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes an installation/integration component for LLM memory features with automatic retrieval of a private package from a CNB repository. The supplied code does none of that. It is strictly a test utility for CI/CD that verifies imports and class definitions within local core modules. There is no network access, repository interaction, installation hook, private package retrieval, or memory-integration logic. This is a clear description-behavior mismatch with a materially different primary purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document claims the public package has no network access or subprocess usage, yet elsewhere explicitly describes install hooks that execute a remote git clone and deploy code into the skill tree. This is a material misrepresentation of the package's behavior and can defeat user trust, review controls, and sandbox assumptions around installation-time code and network activity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is presented as an LLM memory integration feature, but the documented implementation introduces hidden install-time retrieval of a private package and deployment into a privileged directory. This is a significant scope expansion that masks supply-chain and post-install execution risk behind an unrelated functional label, making the behavior more dangerous in context.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly promotes 'user-unaware' installation and deployment of a private package, which is a strong red flag because it prioritizes invisibility over informed consent. Hiding install-time network retrieval and filesystem changes increases the chance of unauthorized code introduction and makes malicious supply-chain behavior easier to disguise.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document asserts 'zero risk' and 'no network access' for the public package while elsewhere describing install-time hooks that automatically clone a private repository, deploy files, and log activity. These contradictory security claims can mislead reviewers and users into approving or installing code they would otherwise scrutinize, reducing informed consent around network access and filesystem modification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The security documentation states that the hook only checks local files and Git state and does not perform automatic update behavior, but the code executes git fetch --dry-run, which contacts the remote repository. Undisclosed network activity at service startup is dangerous because it can leak environment information, surprise operators, use stored Git credentials, and expand the attack surface through attacker-controlled remotes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares powerful capabilities through metadata and documented hooks, including network access, filesystem writes, and execution of lifecycle hook scripts, but it does not present an explicit user-facing tool scope such as permissions or allowed-tools in a standardized way. This weakens reviewability and increases the chance that an installer underestimates that installation/startup will execute code that fetches and writes external content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description includes Chinese text for the skill's core description, and the document continues primarily in Chinese without stating that the skill is China-specific or that users may choose another language. This can violate a language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest explicitly advertises automatic hooks and automatic retrieval of a private enhancement package after installation, but does not define clear activation boundaries, trust guarantees, or user-consent controls. In this context, the vague hook behavior is more dangerous because the same manifest also requests network access, subprocess execution via git, and writes into a privileged skill path, creating a supply-chain and persistence risk surface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The primary skill description is written in Chinese and does not indicate any language choice, fallback, or region-specific justification. This can violate language/locale policy when a skill presents user-facing instructions or behavior in a fixed language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest explicitly defines automatic lifecycle hooks and describes them as automatically pulling a private package from a remote CNB repository at install/startup time, without any stated trigger constraints, integrity checks, or user approval. In this skill’s context, that broad auto-activation is especially dangerous because it combines network access, subprocess execution, and privileged write paths, enabling remote code or package delivery into the local skill environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The architecture is presented as a simple interface layer, but it is designed to automatically pull an undisclosed private enhancement package from an external repository during installation. Hidden retrieval and deployment of additional code expands the trust boundary and creates a supply-chain risk because users may install one package while actually receiving code from another source.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Promoting automatic cloning of a private package during install without a clear user-facing warning creates an unsafe installation flow with non-obvious side effects. Users and administrators may reasonably expect installation of a public skill not to initiate remote code retrieval and deployment unless this is clearly disclosed and consented to.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · docs/ARCHITECTURE.md (reported line 158)May include surrounding context.

检查:

bash
# 查看私有包目录
ls -la ~/.openclaw/workspace/skills/llm-memory-integration/src/privileged/

# 查看状态日志
cat ~/.openclaw/workspace/skills/llm-memory-integration/.privileged_status.log

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation describes automatic cloning and deployment during installation without a prominent pre-install warning that network access and local file changes will occur. Users and reviewers may therefore treat the package as a normal documentation or integration update, when it actually performs supply-chain relevant actions during install.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The startup-hook section says updates are only suggested, but the broader architecture emphasizes automatic, user-unaware private package handling. This inconsistency obscures the true automation level and can hide how much code or state is managed without user visibility, undermining transparency for security review.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · hooks/onStartup.py (reported line 74)May include surrounding context.

python
try:
        # 获取当前 commit
        current = subprocess.run(
            ["git", "rev-parse", "HEAD"],
            cwd=str(privileged_dir),
            capture_output=True,

Static analysis

No suspicious patterns detected.