Back to skill

Security audit

Memory Auto Archive

Security checks for vulnerabilities and agentic risk

Overview

This skill automatically reads saved chats and persists selected excerpts, including credential-related content, without enough scoping, redaction, or user confirmation.

Review carefully before installing. This skill may be useful for local memory archiving, but it should be configured narrowly: disable startup archiving unless wanted, remove credential-related keywords, avoid AI refinement for sensitive workspaces, do not use unpinned npx in scheduled jobs, and periodically inspect or purge generated memory and log files.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
src/archiver.ts:101
Finding

Untrusted Transcript Content Is Persisted in Agent Memory Without Sanitization

Content
View full analysis
= []; let skipped = 0; for (const file of files) { try { const content = await fs.readFile(file, 'utf8'); const lines = content.split('\n').filter(l => l.trim()); for (const line of lines) { try { const msg = JSON.parse(line) as TranscriptMessage; if (msg.type !== 'message' || !msg.message) continue; // Parse UTC timestamp and convert to local const utc = new Date(msg.timestamp); const local = new Date(utc.getTime() + (utc.getTimezoneOffset() * 60000)); if (local >= startOfDay && local < endOfDay) { const textObj = msg.message.content.find(c => c.type === 'text'); if (textObj?.text) { messages.push({ role: msg.message.role, text: textObj.text, time: local }); } } } catch { skipped++; } } } catch { // Skip unreadable files } } ``` ```typescript for (const msg of messages) { for (const kw of keywords) { if (msg.text.toLowerCase().includes(kw.toLowerCase())) { const snippet = msg.text.substring(0, Math.min(80, msg.text.length)) + (msg.text.length > 80 ? '...' : ''); highlights.push({ role: msg.role, snippet }); break; // only first keyword per message } } } ``` ```typescript const highlightsText = daily.highlights.length > 0 ? daily.highlights.map(h => `- ${h.role === 'user' ? 'User' : 'Asst'}: ${h.snippet}`).join('\n') : 'No highlights'; const template = this.config.templates.dailyLog; return template .replace(/{date}/g, daily.date) .replace(/{userCount}/g, String(daily.userC ...[truncated 2449 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/defaults.ts:5
Finding

Credential-Related Messages Are Selected and Duplicated into Plaintext Archives

Content
View full analysis
80 ? '...' : ''); highlights.push({ role: msg.role, snippet }); break; // only first keyword per message } } } ``` ```typescript const content = this.renderDailyLog(dailyLog); await fs.mkdir(join(workspace, this.config.paths.memoryDir), { recursive: true }); await fs.writeFile(dailyFile, content, 'utf8'); this.logger(`[Archiver] Wrote: ${dailyFile}`); ``` ### Technical Analysis The default keyword list deliberately includes terms strongly associated with sensitive data, including `password`, `token`, `key`, `secret`, `API`, and their Chinese equivalents. Consequently, messages discussing credentials are more likely to be selected for long-term storage. The first 80 characters of a matching message are copied to an unencrypted Markdown file. The code performs no credential-pattern detection or redaction and does not request restrictive file permissions when creating the archive. No retention or secure-deletion policy is imp ...[truncated 1318 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
refine.js:20
Finding

File-Controlled Content Is Appended Directly to Authoritative Long-Term Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (50)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file documents automatic logging, startup checks, and optional AI refinement of user activity, including possible extraction of passwords and tokens, but does not provide a strong user-facing warning, consent flow, or data-handling safeguards. In this context, the skill is more dangerous because it is designed to persist conversational data over time, amplifying privacy harm if sensitive information is captured.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The configuration explicitly instructs the refinement model to extract and persist 'passwords' and 'tokens' into long-term memory. For an auto-memory/logging skill, collecting secrets is unnecessary and materially increases the chance of credential retention, later disclosure, prompt leakage, or accidental reuse in downstream contexts.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The default/example keyword list explicitly includes token, password, key, and secret, which prioritizes archiving messages likely to contain credentials or other highly sensitive material. In a memory/archive plugin, this directly increases the probability that secrets are copied into markdown logs and long-term memory files where they may be more broadly exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The optional AI refinement feature describes automatic updates to MEMORY.md using an external model identifier, but it does not explicitly warn that chat-derived content may be sent to a third-party model service. Because the source data comes from agent transcripts and memory logs, this can expose sensitive user or workspace data outside the local environment without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The AI refinement feature is described without a clear warning that conversation-derived content may be sent to an external model provider. Since the feature extracts long-term memories from logs and can include sensitive content, users may unknowingly transmit internal or personal data outside their environment, creating confidentiality, compliance, and third-party retention risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The changelog advertises automatic daily chat archiving from transcripts, which implies collection and persistence of potentially sensitive conversational data, but provides no warning about privacy, retention, consent, or storage scope. In a skill that processes chat transcripts, omitting these disclosures increases the risk that users or operators enable data collection without understanding the sensitivity or compliance implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Describing startup-triggered archiving without disclosing that it runs automatically in the background can mislead users about when data processing begins. Because transcript scanning and archiving may occur immediately on startup across multiple agents, this undocumented automatic behavior raises privacy and operational risk, especially in environments containing sensitive conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The keyword list includes very common terms such as 'task', 'important', 'plan', 'error', 'config', 'password', and 'token', making automatic capture likely to trigger during ordinary conversations. In a logging skill, overbroad triggers increase unintended collection of user activity and sensitive content, expanding the privacy and data-retention risk surface.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The wording 'be careful!' does not mitigate the fact that the prompt directly tells the model to extract sensitive credentials into a retained data store. This creates a misleading safety signal while operationally encouraging the exact unsafe behavior, which can normalize insecure handling of secrets.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises automatic startup archiving of conversations but does not give a prominent warning that local transcript files will be read and new memory/log files created or modified. In a plugin that processes private chats automatically, lack of explicit notice undermines informed consent and can lead to unintended collection of sensitive data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatically archiving daily conversations in a memory plugin changes transient chat content into retained artifacts, increasing the chance that sensitive user-provided data is stored, discoverable, or later reused out of context. In this skill context, the danger is amplified because the feature is universal, zero-config, and runs automatically on startup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The optional AI refinement feature references a cloud-capable model without clearly warning that conversation-derived content may be sent to an external provider depending on model configuration. Because archived chats can contain credentials, personal data, or business-sensitive content, undisclosed external transmission materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented workflow reads all session transcript files across agents and writes structured summaries, which creates a broad mechanism for collecting and retaining potentially sensitive conversational data. Since summaries can condense and surface secrets or sensitive decisions, this is not just passive storage but active redistribution of high-value information.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The use case suggesting archived logs can be shared across agents normalizes disclosure of conversation-derived data beyond its original context and audience. Even if intended for collaboration, cross-agent reuse can propagate sensitive or private information to components or operators that did not originally need access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README claims only keyword-matching messages are archived, but elsewhere shows summaries/highlights that imply broader transcript-derived content may be written. This mismatch can mislead users about the scope of data capture and retention, causing them to expose more conversation content than intended.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promotes automatic startup scanning of transcript files, archiving of selected content, and preparation of prompts for memory updates, but it does not present a clear upfront privacy warning. In this context, the plugin processes conversation transcripts that may contain secrets, personal data, or internal business information, so omission of explicit disclosure can lead to unsafe deployment and unintended retention.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The sample refinement prompt explicitly asks the model to extract and retain 'important data' and user preferences into long-term memory. In a memory plugin, that guidance materially increases the chance of storing secrets, personal information, or other sensitive context in persistent files, which broadens exposure and retention risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The README instructs users to execute the package via npx openclaw-memory-auto without pinning a specific version. That can cause users to fetch and run whatever package version is current at execution time, increasing supply-chain risk if a malicious or compromised release is published.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that it scans all transcript files and writes extracted content into archive files, but it does not present this as a clear privacy and data-retention warning. Because transcript data may include secrets, credentials, personal data, or internal discussions, silently normalizing bulk ingestion and persistence increases the risk of unintended retention and later exposure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The suggested refinement prompt explicitly asks the model to retain items like user preferences and important data in long-term memory, encouraging accumulation of potentially sensitive personal or operational information. In the context of a plugin that scans conversation transcripts, this increases privacy risk, broadens the blast radius of any compromise, and may violate data-minimization expectations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documented cron command uses npx openclaw-memory-auto without pinning a specific version, which can cause the latest published package to be fetched and executed at runtime. If the package is updated maliciously or a compromised version is published, users may unknowingly run unreviewed code with access to local workspace data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The inline comment at L29 describes concrete behavior: archiving yesterday's chat. However, this JavaScript code does not itself locate or archive chat content; it merely checks for a date-named markdown file and then invokes an external PowerShell script with execution policy bypass. That is an intent-level mismatch between the documented behavior in this file and what the file actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script launches powershell.exe with '-ExecutionPolicy Bypass', explicitly disabling a key safety control and then executes a local script without integrity validation or user confirmation. In a plugin/skill context, this makes any tampering with archive.ps1 or the plugin directory significantly more dangerous because the code forces execution even in environments that would otherwise restrict it.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:57