T03 · Remote Payload Retrieval and Execution
- Location
scripts/memory-restore.sh:43- Finding
Unverified Remote Repository Can Replace Persistent Configuration and Executable Skill Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed memory tool, but it adds ongoing session monitoring, cron persistence, and broad Git backup/restore that can expose or overwrite important OpenClaw data.
Review carefully before installing. Use this only if you want persistent memory plus background transcript monitoring. Avoid token-in-URL Git remotes, keep backups private and narrowly scoped, disable or remove cron if you do not want hourly background execution, and do not restore from any repository you have not personally verified.
scripts/memory-restore.sh:43Unverified Remote Repository Can Replace Persistent Configuration and Executable Skill Code
scripts/memory-backup.sh:16Broad Workspace and Sensitive Configuration Upload to a Git Remote
scripts/memory-auto-extract.js:18Persistent Monitoring and Extraction of Active and Reset Session Transcripts
scripts/memory-cron.sh:133Hourly Cron Persistence and Self-Restarting Background Watcher
Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.
Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.
Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.
Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.
Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.
Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.
Presenting the skill as a local memory guardian while it can restore an entire workspace from a remote GitHub repository significantly understates its power. Remote clone/pull plus config and crontab restoration can overwrite local state, import untrusted content, and broaden compromise from memory data to the full workspace.
Referenced artifact was not completely inspected
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |
Referenced artifact was not completely inspected
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |
Referenced artifact was not completely inspected
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |
Referenced artifact was not completely inspected
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |
Referenced artifact was not completely inspected
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |
Referenced artifact was not completely inspected
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |
Referenced artifact was not completely inspected
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |
Referenced artifact was not completely inspected
| Auto-write daily logs | ❌ | ✅ `memory-write.js` |
Referenced artifact was not completely inspected
| Health check + GC | ❌ | ✅ `memory-maintain.js` |
Referenced artifact was not completely inspected
| Health check + GC | ❌ | ✅ `memory-maintain.js` |
Referenced artifact was not completely inspected
| Health check + GC | ❌ | ✅ `memory-maintain.js` |
Referenced artifact was not completely inspected
| Health check + GC | ❌ | ✅ `memory-maintain.js` |
Referenced artifact was not completely inspected
| Health check + GC | ❌ | ✅ `memory-maintain.js` |
Referenced artifact was not completely inspected
| Health check + GC | ❌ | ✅ `memory-maintain.js` |
Referenced artifact was not completely inspected
| Health check + GC | ❌ | ✅ `memory-maintain.js` |
Referenced artifact was not completely inspected
| Health check + GC | ❌ | ✅ `memory-maintain.js` |
Referenced artifact was not completely inspected
node scripts/memory-migrate.js # preview changes
Referenced artifact was not completely inspected
node scripts/memory-migrate.js # preview changes
Detected: suspicious.dangerous_exec