Back to skill

Security audit

memU-lite

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is broadly purpose-aligned, but needs review because it creates durable agent memory and has under-scoped restore/sample-data behavior that can affect future sessions.

Review before installing. Use it only if you are comfortable storing long-term local memory under ~/.openclaw/workspace, remove or isolate the installed sample memories, avoid saving secrets or sensitive personal data, and do not restore backup archives unless you trust and inspect their contents first.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
tools/memu-backup.sh:121
Finding

Unvalidated Backup Archive Can Overwrite the OpenClaw Workspace

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
install.sh:45
Finding

Installer Seeds Fabricated User Attributes as High-Confidence Persistent Memory

Content
View full analysis
"$WORKSPACE_DIR/memory/items/preferences/P-20260302-001-开发偏好.md" << 'EOF' ## P-20260302-001 开发偏好 - **类型**: preference - **来源**: 示例记忆 - **日期**: 2026-03-02 - **置信度**: high - **标签**: #偏好 #开发 #示例 - **内容**: 1. 偏好 Python 和 JavaScript 2. 代码风格简洁、可读性强 3. 重视测试和文档 4. 喜欢使用开源工具 - **关联**: [[R-20260302-001]] EOF cat > "$WORKSPACE_DIR/memory/items/relationships/R-20260302-001-用户信息.md" << 'EOF' ## R-20260302-001 用户信息 - **类型**: relationship - **来源**: 示例记忆 - **日期**: 2026-03-02 - **置信度**: high - **标签**: #用户 #示例 - **内容**: - 时区:Asia/Shanghai - 位置:中国大陆 - 语言:简体中文 - 角色:开发者 - **关联**: [[P-20260302-001]] EOF ``` The installed records assert, as high-confidence facts, that the user prefers Python and JavaScript, uses a particular coding style, resides in mainland China, uses the Asia/Shanghai time zone, speaks Simplified Chinese, and is a developer. ### Technical Analysis The installation process writes generic demonstration data directly into the live long-term memory directory. Although the records identify their source as an example, they assign `high` confidence and use the same schema and location as genuine user memories. The installer also creates a top-level index that presents these records as active user preferences and relationship information. As a result, normal memory retrieval cannot reliably distinguish the demonstration data from verified user facts. Persistent Agent memory should contain information established from authenticated user input, trusted project material, or explicit user confirmation. Seeding assumptions about identity, location, language, and preferences violates that trust boundary. ### Attack Path 1. A user installs the Skill by running `install.sh`. 2. The installer writes the two example records into `~/.ope ...[truncated 1082 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
tools/memu-add.sh:52
Finding

Untrusted Input Is Stored as Agent-Readable Long-Term Memory Without a Trust Boundary

Content
View full analysis
/dev/null | grep "^$TYPE_PREFIX-$DATE" | wc -l) COUNT=$((COUNT + 1)) ID="${TYPE_PREFIX}-${DATE}-$(printf "%03d" $COUNT)" SLUG=$(echo "$TITLE" | tr ' ' '-' | tr -cd '[:alnum:]-' | tr '[:upper:]' '[:lower:]') FILENAME="$MEMORY_DIR/items/$TYPE/${ID}-${SLUG}.md" cat > "$FILENAME" << EOF ## $ID $TITLE - **类型**: $TYPE - **来源**: $SOURCE - **日期**: $(date +%Y-%m-%d) - **置信度**: high - **标签**: $TAGS EOF if [ -n "$EXPIRY" ]; then echo "- **过期日期**: $EXPIRY" >> "$FILENAME" fi cat >> "$FILENAME" << EOF - **内容**: ${CONTENT_SUMMARY:-$CONTENT} EOF if [ -n "$RELATIONS" ]; then echo "- **关联**: [[$RELATIONS]]" >> "$FILENAME" fi ``` The same unescaped values are subsequently inserted into the main index: ```bash TABLE_LINE="| $ID | $TYPE | $TITLE | $(date +%Y-%m-%d) | $TAGS |" sed -i "/^| - | - | - | - | - |$/a\\$TABLE_LINE" "$MEMORY_DIR/MEMORY.md" MONTH=$(date +%Y-%m) if grep -q "^### $MONTH" "$MEMORY_DIR/MEMORY.md"; then sed -i "/^### $MONTH/a\\- **$(date +%m-%d)**: 添加 $TYPE - $TITLE" "$MEMORY_DIR/MEMORY.md" else ...[truncated 2738 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PUSH_GUIDE.md (reported line 25)May include surrounding context.

md
如果提示认证:
- **用户名**: yoo-unison
- **密码**: 使用 GitHub Personal Access Token

### 方式二:GitHub Desktop

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is the memory system itself, focused on structured storage, categories, tag indexing, and retrieval. The supplied code does not implement memory storage or retrieval logic at all. Instead, it is an operational maintenance script for backing up and restoring an already-existing memory directory. It also performs destructive file operations during restore and cleanup, which are undeclared capabilities relative to the stated purpose. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a general structured memory system focused on storing memories with categories, tag indexing, and retrieval. The supplied code chunk does not implement storage, indexing, or retrieval. Instead, it is a maintenance/cleanup script for existing memory files: it scans markdown files under the memory directory, parses expiration metadata, and can archive or delete expired memories. That is a materially different purpose and includes destructive filesystem operations not reflected in the description. While related to the same memory domain, this code's primary behavior is lifecycle cleanup, not memory storage and retrieval as declared.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · install.sh (reported line 20)May include surrounding context.

sh
echo "  $SCRIPT_DIR/memory/TEMPLATE.md"
    echo ""
    echo "如需强制重新初始化,请先备份并删除:"
    echo "  rm -rf $WORKSPACE_DIR/memory/"
    echo "  然后重新运行此脚本"
    exit 0
fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The restore flow unconditionally executes 'rm -rf memory/' after changing into the workspace, deleting the current memory store before validating that extraction will succeed safely. If the backup archive is malformed, incomplete, or malicious, this can cause irreversible data loss, and because tar extraction is not constrained, a crafted archive may also write unexpected paths or symlink targets during restore.

Content

Scanner excerpt · tools/memu-backup.sh (reported line 157)May include surrounding context.

sh
echo ""
    echo -e "${BLUE}🔄 正在恢复备份...${NC}"
    cd "$WORKSPACE_DIR"
    rm -rf memory/
    tar -xzf "$BACKUP_FILE"
    
    if [ $? -eq 0 ]; then

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructions only in Chinese, which imposes a specific language on users without any opt-in or alternative. Under the policy, forced language or locale usage is a natural-language violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The documented setup creates a persistent memory store under ~/.openclaw, explicitly enabling session-to-session retention of raw records and structured memories. Persistence is core to the skill's purpose, but without security boundaries, retention controls, or warnings, it can preserve sensitive data longer than intended and make compromise or unauthorized local access more damaging.

Content

Scanner excerpt · README.md (reported line 41)May include surrounding context.

bash
# 创建记忆目录结构
mkdir -p ~/.openclaw/workspace/memory/{raw,items/{preferences,knowledge,relationships,tasks,skills},indexes}

2. 创建第一条记忆

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly encourages storing user preferences, relationships, project knowledge, and raw conversation records, but provides no privacy guidance, retention limits, consent requirements, or handling restrictions. In a memory skill, this omission can lead operators to persist sensitive personal data by default, increasing exposure from accidental disclosure, over-collection, or misuse across agents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language instructions, headings, and examples are predominantly Chinese, which effectively forces a specific language for users reading or operating the skill. There is no opt-in, bilingual alternative, or justification that this is a region-specific tool.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill creates a persistent workspace under the user's home directory, enabling information to survive across sessions. Persistence is core to the skill's purpose, but without consent controls or data-classification safeguards it increases privacy and data-retention risk, especially when used for user-specific memory.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

或手动创建:

bash
mkdir -p ~/.openclaw/workspace/memory/{raw,items/{preferences,knowledge,relationships,tasks,skills},indexes}

2. 创建第一条记忆

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to automatically record user and project information across sessions without any consent, sensitivity screening, or privacy warning. This can lead to persistent storage of personal, confidential, or regulated data that users did not expect to be retained.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow explicitly encourages routine retention of conversation data in persistent memory and raw logs, but gives no minimization policy, retention limit, or sensitivity restrictions. In practice, this creates a durable data-exposure surface where secrets, internal project details, and personal data may be stored and later retrieved or leaked.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The initialization script again provisions a long-lived storage location in the home directory, reinforcing cross-session retention. This is not malicious, but it is security-relevant because persistent storage of conversational memory can accumulate sensitive data and expand the blast radius of later compromise.

Content

Scanner excerpt · SKILL.md (reported line 378)May include surrounding context.

bash
#!/bin/bash
mkdir -p ~/.openclaw/workspace/memory/{raw,items/{preferences,knowledge,relationships,tasks,skills},indexes}
echo "memU-lite 记忆结构已创建"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer creates and populates multiple files under $HOME/.openclaw/workspace without an explicit confirmation step immediately before making changes. Although the writes are scoped to a predictable application directory and the script avoids overwriting an existing MEMORY.md, it still modifies persistent user data automatically, which can surprise users and create unintended state in a personal directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes example memory files that include user-profile style fields such as timezone, location, language, and role, but it does so without a privacy notice or consent prompt. Even though the data is labeled as example content, placing realistic personal-profile fields into a persistent memory store can mislead downstream tools or encourage storage of sensitive personal data without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The embedded sample relationship data hard-codes a specific locale/language context, including Asia/Shanghai, China, and Simplified Chinese, without user opt-in. This is not code-execution dangerous, but it can cause incorrect personalization, contaminate future memory retrievals, and bias systems that treat the installed memory as factual user data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s user-facing headings and instructions are written in Chinese throughout, with no indication that users can choose another language or that the locale restriction is required for a region-specific purpose. This can violate a language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script's comments, prompts, status messages, and usage text are all presented in Chinese, requiring users to interact in a specific language. Under the policy, forcing a specific language without user opt-in is a locale policy violation unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code creates a markdown file under the user's ~/.openclaw workspace and writes the entered title, content, source, tags, and relations into it. Although the script prints progress messages, it does not clearly disclose to the user that their input will be persisted as a local record, which is a user-data-affecting file write.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's title, help output, prompts, warnings, and status messages are written entirely in Chinese, which imposes a specific language on users. Under the policy, locale-specific behavior should either provide user choice or clearly document a justified regional constraint, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-facing comments, help text, prompts, warnings, and status output are presented entirely in Chinese throughout the script. Because the skill does not offer a language choice or state that it is intentionally limited to a Chinese-speaking environment, this creates a natural-language locale policy concern under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The help description says the cleanup tool checks memories with expiry dates and archives expired memories to the archive directory. However, the implementation also provides a force-delete mode that permanently removes expired memories, which directly contradicts the stated behavior in the inline documentation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes memU-lite as a lightweight structured memory system focused on atomic storage, categorization, tag-based indexing, and fast retrieval. This script adds a destructive cleanup capability that can permanently remove stored memories, which goes beyond the described behavior and is not implied by the manifest text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing name, help text, and examples are all presented in Chinese, and the same pattern continues throughout the file. This imposes a specific language on users without opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments, status messages, headings, and generated markdown content are all written in Chinese, which effectively forces a specific language for users. Under the policy, language constraints should either be optional/opt-in or clearly justified as region-specific, neither of which is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.