Back to skill

Security audit

MemClawz Connect

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes a shared-memory integration, but it encourages broad automatic reading and writing of agent work to an unauthenticated or plaintext memory service.

Install only if you control the MemClawz service and are comfortable with agents sharing work summaries across sessions. Do not use the documented remote HTTP/no-auth pattern for private projects; require authentication, HTTPS or private networking, project isolation, redaction, and explicit approval before writing sensitive task details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:29
Finding

Persistent Cross-Agent Instruction and Memory Poisoning

Content
View full analysis
&limit=5" ### After completing ANY significant work: Write results to shared memory: curl -s -X POST $MEMCLAWZ_URL/api/v1/add \ -H "Content-Type: application/json" \ -d '{"content": "", "agent_id": "$MEMCLAWZ_AGENT_ID", "memory_type": ""}' ``` ``` ### Technical Analysis The skill requires an agent to query a shared memory service before every task and use returned content as operational context. It provides no trust validation, provenance enforcement, content sanitization, or separation between informational memory and executable agent instructions. The instructions also direct users to append this behavior to `AGENTS.md`. That change persists beyond the current skill invocation and causes future sessions to continue retrieving and consuming shared content. An attacker who can submit memories can store instruction-like text designed to alter agent behavior, override task objectives, request sensitive information, or induce unsafe tool calls. Because the same service supports both writing and searching memories, malicious content can propagate between agents. The persistence in `AGENTS.md` expands the issue from a single-s ...[truncated 1482 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:41
Finding

Automatic Disclosure of Task Results and Internal Configuration

Content
View full analysis
", "agent_id": "$MEMCLAWZ_AGENT_ID", "memory_type": ""}' ``` ### Technical Analysis The skill establishes a write-after-completion workflow that transmits task results to a shared service. It expressly identifies discovered endpoints, software versions, configurations, deployment procedures, architectural decisions, and completed actions as information suitable for storage. There are no requirements for user consent, data classification, secret detection, redaction, destination verification, retention limits, or project-level access control before transmission. Consequently, an agent applying the instructions to a confidential project may send internal technical details to a service accessible by other agents or an external ope ...[truncated 1489 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:12
Finding

Unauthenticated Shared-Memory API over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest advertises very broad trigger phrases such as 'shared memory', 'search memory', and 'remember this across sessions', which can match many ordinary user requests and cause the skill to activate unexpectedly. Because the skill then instructs agents to query and write to a cross-agent memory service, accidental invocation can expand data exposure and persistence beyond the user's intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

Health Check

bash
curl -s "$MEMCLAWZ_URL/health"
# {"status":"ok","version":"...","qdrant":"connected"}

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The protocol instructs agents to search shared memory before every task and write back after completing work, creating a bidirectional flow of potentially sensitive context without any trust boundaries or filtering requirements. This is especially dangerous in a cross-agent memory system because one agent's confidential inputs or flawed outputs can propagate to others and persist across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The write-back guidance tells agents to POST completed work into shared memory but gives no warning to exclude secrets, personal data, proprietary content, or user-confidential outputs. In a shared, long-term memory bus, this can leak sensitive task data across agents, sessions, and potentially hosts, especially since the setup notes that default installs may have no API key.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

Stats

bash
curl -s "$MEMCLAWZ_URL/api/v1/stats"

List Agents

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to write back after 'any significant work' encourages indiscriminate logging of agent activity and outputs into shared memory. Without scope limits, this can capture internal reasoning summaries, user-provided confidential material, infrastructure details, or security-relevant changes that should not be broadly shared or retained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The AGENTS.md integration normalizes automatic write-back after 'ANY significant work' without any privacy, secrecy, or retention caveats. Embedding this into agent operating instructions makes broad persistence more likely at scale, turning routine work products into shared telemetry that may expose sensitive business context or user information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.