Back to skill

Security audit

Memory Engine

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed memory tool, but it adds ongoing session monitoring, cron persistence, and broad Git backup/restore that can expose or overwrite important OpenClaw data.

Review carefully before installing. Use this only if you want persistent memory plus background transcript monitoring. Avoid token-in-URL Git remotes, keep backups private and narrowly scoped, disable or remove cron if you do not want hourly background execution, and do not restore from any repository you have not personally verified.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/memory-restore.sh:43
Finding

Unverified Remote Repository Can Replace Persistent Configuration and Executable Skill Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/memory-backup.sh:16
Finding

Broad Workspace and Sensitive Configuration Upload to a Git Remote

Content
View full analysis
"$WORKSPACE/crontab.backup" 2>/dev/null || true # Check for changes git add -A if git diff --cached --quiet; then echo "[backup] No changes to push" exit 0 fi # Commit and push TIMESTAMP=$(date '+%Y-%m-%d %H:%M') git commit -m "auto-backup: $TIMESTAMP" --quiet git push origin main --quiet 2>&1 && echo "[backup] Pushed at $TIMESTAMP" || echo "[backup] Push failed (check network)" ``` The documentation additionally recommends a credential-bearing remote URL: ```bash git remote add origin https://@github.com//openclaw-workspace.git ``` ### Technical Analysis The script copies OpenClaw configuration and the complete user crontab into the workspace and then runs `git add -A`. This stages every unignored file in the workspace rather than a narrowly defined set of memory files. Potentially uploaded material includes: - conversation-derived memory; - `USER.md` profile information; - OpenClaw configuration; - API credentials or provider settings stored in configuration; - crontab commands; - agent behavior files; - installed skills and executable code; - unrelated files or secrets placed anywhere in the workspace. The destination is whatever repository is configured as `origin`; the script does not verify repository ownership, privacy, transport policy, or an expected host. The documented token-in-URL pattern can also leave the access token in `.git/config`, command history, process-related records, or copied diagnostics. The automatic invocation block in the reviewed `memory-cron.sh` uses an undefined `DIR` variable, so that particul ...[truncated 1347 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/memory-auto-extract.js:18
Finding

Persistent Monitoring and Extraction of Active and Reset Session Transcripts

Content
View full analysis
f.includes('.reset.') && f.endsWith('.jsonl.reset.' + f.split('.reset.').pop())) .concat(fs.readdirSync(SESSIONS_DIR).filter(f => f.match(/\.jsonl\.reset\.\d{4}/))); // Actually just get all reset files properly const allFiles = fs.readdirSync(SESSIONS_DIR).filter(f => f.includes('.reset.')); let totalExtracted = 0; for (const f of allFiles) { if (tracked[f]) continue; const fp = path.join(SESSIONS_DIR, f); const entries = extractFromSessionFile(fp); if (entries.length > 0) { console.log(`[auto-extract] ${f}: ${entries.length} events`); writeExtractedToLog(entries); totalExtracted += entries.length; } tracked[f] = { extractedAt: new Date().toISOString(), count: entries.length }; } ``` Active-session scanning: ```js } else if (scanActive) { // P1: Incremental extraction from active sessions (reads only new lines since last offset) if (!fs.existsSync(SESSIONS_DIR)) { console.log('[auto-extract] No sessions directory.'); process.exit(0); } const offsetFile = path.join(workspace, '.memory', 'active-extract-offset.json'); ...[truncated 3450 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
scripts/memory-cron.sh:133
Finding

Hourly Cron Persistence and Self-Restarting Background Watcher

Content
View full analysis
/dev/null; echo "0 * * * * $(pwd)/scripts/memory-cron.sh") | crontab - ``` The cron script ensures the watcher is running: ```bash # 7. Ensure watcher is running (P0: session reset hook) WATCHER_PID_FILE="$WORKSPACE/.memory/watcher.pid" WATCHER_ALIVE=false if [ -f "$WATCHER_PID_FILE" ]; then WATCHER_PID=$(cat "$WATCHER_PID_FILE") if kill -0 "$WATCHER_PID" 2>/dev/null; then WATCHER_ALIVE=true fi fi if ! $WATCHER_ALIVE; then nohup bash "$SCRIPT_DIR/memory-watcher.sh" >> "$WORKSPACE/.memory/watcher.log" 2>&1 & echo "[$(date '+%Y-%m-%d %H:%M:%S')] watcher restarted (PID: $!)" >> "$LOG" else echo "[$(date '+%Y-%m-%d %H:%M:%S')] watcher alive (PID: $WATCHER_PID)" >> "$LOG" fi ``` The watcher then runs indefinitely: ```bash # Daemon mode echo $$ > "$PID_FILE" log "watcher started (PID: $$, interval: ${POLL_INTERVAL}s)" # Cleanup on exit trap 'log "watcher stopped (PID: $$)"; rm -f "$PID_FILE"; exit 0' SIGTERM SIGINT EXIT while true; do check_new_resets sleep "$POLL_INTERVAL" done ``` Migration can also rewrite an existing cron schedule in `scripts/memory-migrate.js:198-212`: ```js if (change.action === 'cron-update') { try { const { execSync } = require('child_process'); const crontab = execSync('crontab -l', { encoding: 'utf8' }); const updated = crontab.replace( /0 \*\/6 \* \* \* (.*memory-cron\.sh)/, '0 * * * * $1' ); execSync(`echo '${updated.replace(/'/g, "'\\''")}' | crontab -`); cronUpdated = true; console.log(` ✅ ${change.desc}`); } catch (e) { console.log(` ❌ ${change.desc}: ${e.message.slice(0, 60)}`); } continue; } `` ...[truncated 2017 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (112)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
| Health check + GC | ❌ | ✅ `memory-maintain.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

md
| Health check + GC | ❌ | ✅ `memory-maintain.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

md
| Health check + GC | ❌ | ✅ `memory-maintain.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

md
| Health check + GC | ❌ | ✅ `memory-maintain.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

md
| Health check + GC | ❌ | ✅ `memory-maintain.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

md
| Health check + GC | ❌ | ✅ `memory-maintain.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 266)May include surrounding context.

md
| Health check + GC | ❌ | ✅ `memory-maintain.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
| Health check + GC | ❌ | ✅ `memory-maintain.js` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
node scripts/memory-migrate.js # preview changes

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
node scripts/memory-migrate.js # preview changes

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-boot.js:62

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-compact.js:146

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-cron.sh:115

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-index.js:11

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-maintain.js:15

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-migrate.js:55

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-resume.js:111

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-search.js:21

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/memory-write.js:55