T09 · Insecure Skill Coding Practices
- Location
tools/memu-backup.sh:121- Finding
Unvalidated Backup Archive Can Overwrite the OpenClaw Workspace
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill is broadly purpose-aligned, but needs review because it creates durable agent memory and has under-scoped restore/sample-data behavior that can affect future sessions.
Review before installing. Use it only if you are comfortable storing long-term local memory under ~/.openclaw/workspace, remove or isolate the installed sample memories, avoid saving secrets or sensitive personal data, and do not restore backup archives unless you trust and inspect their contents first.
tools/memu-backup.sh:121Unvalidated Backup Archive Can Overwrite the OpenClaw Workspace
install.sh:45Installer Seeds Fabricated User Attributes as High-Confidence Persistent Memory
tools/memu-add.sh:52Untrusted Input Is Stored as Agent-Readable Long-Term Memory Without a Trust Boundary
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
如果提示认证:
- **用户名**: yoo-unison
- **密码**: 使用 GitHub Personal Access Token
### 方式二:GitHub Desktop
The declared description says this skill is the memory system itself, focused on structured storage, categories, tag indexing, and retrieval. The supplied code does not implement memory storage or retrieval logic at all. Instead, it is an operational maintenance script for backing up and restoring an already-existing memory directory. It also performs destructive file operations during restore and cleanup, which are undeclared capabilities relative to the stated purpose. This is a clear description-behavior mismatch.
The declared description presents a general structured memory system focused on storing memories with categories, tag indexing, and retrieval. The supplied code chunk does not implement storage, indexing, or retrieval. Instead, it is a maintenance/cleanup script for existing memory files: it scans markdown files under the memory directory, parses expiration metadata, and can archive or delete expired memories. That is a materially different purpose and includes destructive filesystem operations not reflected in the description. While related to the same memory domain, this code's primary behavior is lifecycle cleanup, not memory storage and retrieval as declared.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
echo " $SCRIPT_DIR/memory/TEMPLATE.md"
echo ""
echo "如需强制重新初始化,请先备份并删除:"
echo " rm -rf $WORKSPACE_DIR/memory/"
echo " 然后重新运行此脚本"
exit 0
fi
The restore flow unconditionally executes 'rm -rf memory/' after changing into the workspace, deleting the current memory store before validating that extraction will succeed safely. If the backup archive is malformed, incomplete, or malicious, this can cause irreversible data loss, and because tar extraction is not constrained, a crafted archive may also write unexpected paths or symlink targets during restore.
echo ""
echo -e "${BLUE}🔄 正在恢复备份...${NC}"
cd "$WORKSPACE_DIR"
rm -rf memory/
tar -xzf "$BACKUP_FILE"
if [ $? -eq 0 ]; then
This markdown file contains user-facing instructions only in Chinese, which imposes a specific language on users without any opt-in or alternative. Under the policy, forced language or locale usage is a natural-language violation unless the constraint is explicitly justified.
The documented setup creates a persistent memory store under ~/.openclaw, explicitly enabling session-to-session retention of raw records and structured memories. Persistence is core to the skill's purpose, but without security boundaries, retention controls, or warnings, it can preserve sensitive data longer than intended and make compromise or unauthorized local access more damaging.
# 创建记忆目录结构
mkdir -p ~/.openclaw/workspace/memory/{raw,items/{preferences,knowledge,relationships,tasks,skills},indexes}
The README explicitly encourages storing user preferences, relationships, project knowledge, and raw conversation records, but provides no privacy guidance, retention limits, consent requirements, or handling restrictions. In a memory skill, this omission can lead operators to persist sensitive personal data by default, increasing exposure from accidental disclosure, over-collection, or misuse across agents.
The natural-language instructions, headings, and examples are predominantly Chinese, which effectively forces a specific language for users reading or operating the skill. There is no opt-in, bilingual alternative, or justification that this is a region-specific tool.
The skill creates a persistent workspace under the user's home directory, enabling information to survive across sessions. Persistence is core to the skill's purpose, but without consent controls or data-classification safeguards it increases privacy and data-retention risk, especially when used for user-specific memory.
或手动创建:
mkdir -p ~/.openclaw/workspace/memory/{raw,items/{preferences,knowledge,relationships,tasks,skills},indexes}
The skill instructs the agent to automatically record user and project information across sessions without any consent, sensitivity screening, or privacy warning. This can lead to persistent storage of personal, confidential, or regulated data that users did not expect to be retained.
The workflow explicitly encourages routine retention of conversation data in persistent memory and raw logs, but gives no minimization policy, retention limit, or sensitivity restrictions. In practice, this creates a durable data-exposure surface where secrets, internal project details, and personal data may be stored and later retrieved or leaked.
The initialization script again provisions a long-lived storage location in the home directory, reinforcing cross-session retention. This is not malicious, but it is security-relevant because persistent storage of conversational memory can accumulate sensitive data and expand the blast radius of later compromise.
#!/bin/bash
mkdir -p ~/.openclaw/workspace/memory/{raw,items/{preferences,knowledge,relationships,tasks,skills},indexes}
echo "memU-lite 记忆结构已创建"
The installer creates and populates multiple files under $HOME/.openclaw/workspace without an explicit confirmation step immediately before making changes. Although the writes are scoped to a predictable application directory and the script avoids overwriting an existing MEMORY.md, it still modifies persistent user data automatically, which can surprise users and create unintended state in a personal directory.
The script writes example memory files that include user-profile style fields such as timezone, location, language, and role, but it does so without a privacy notice or consent prompt. Even though the data is labeled as example content, placing realistic personal-profile fields into a persistent memory store can mislead downstream tools or encourage storage of sensitive personal data without informed consent.
The embedded sample relationship data hard-codes a specific locale/language context, including Asia/Shanghai, China, and Simplified Chinese, without user opt-in. This is not code-execution dangerous, but it can cause incorrect personalization, contaminate future memory retrievals, and bias systems that treat the installed memory as factual user data.
The file’s user-facing headings and instructions are written in Chinese throughout, with no indication that users can choose another language or that the locale restriction is required for a region-specific purpose. This can violate a language/locale policy when a skill imposes a specific language without user opt-in.
The script's comments, prompts, status messages, and usage text are all presented in Chinese, requiring users to interact in a specific language. Under the policy, forcing a specific language without user opt-in is a locale policy violation unless the restriction is explicitly justified.
This code creates a markdown file under the user's ~/.openclaw workspace and writes the entered title, content, source, tags, and relations into it. Although the script prints progress messages, it does not clearly disclose to the user that their input will be persisted as a local record, which is a user-data-affecting file write.
The script's title, help output, prompts, warnings, and status messages are written entirely in Chinese, which imposes a specific language on users. Under the policy, locale-specific behavior should either provide user choice or clearly document a justified regional constraint, neither of which appears here.
User-facing comments, help text, prompts, warnings, and status output are presented entirely in Chinese throughout the script. Because the skill does not offer a language choice or state that it is intentionally limited to a Chinese-speaking environment, this creates a natural-language locale policy concern under the rule for forced language without user opt-in.
The help description says the cleanup tool checks memories with expiry dates and archives expired memories to the archive directory. However, the implementation also provides a force-delete mode that permanently removes expired memories, which directly contradicts the stated behavior in the inline documentation.
The manifest describes memU-lite as a lightweight structured memory system focused on atomic storage, categorization, tag-based indexing, and fast retrieval. This script adds a destructive cleanup capability that can permanently remove stored memories, which goes beyond the described behavior and is not implied by the manifest text.
The script's user-facing name, help text, and examples are all presented in Chinese, and the same pattern continues throughout the file. This imposes a specific language on users without opt-in, which matches the language/locale policy violation criteria.
The script's comments, status messages, headings, and generated markdown content are all written in Chinese, which effectively forces a specific language for users. Under the policy, language constraints should either be optional/opt-in or clearly justified as region-specific, neither of which is present here.
No suspicious patterns detected.