T09 · Insecure Skill Coding Practices
- Location
SKILL.md:22- Finding
Excessive Persistent Conversation Logging and Unscoped Remote Memory Indexing
- Content
View full analysis
60%, log every exchange to `memory/working-buffer.md`. 1. Check context via `session_status` 2. At 60%: create/clear working buffer 3. Every message after: append human message + your response summary 4. After compaction: read buffer FIRST 5. Never ask "what were we doing?" — the buffer has it ``` `SKILL.md`, lines 187–195: ```markdown Layer 0: memory/YYYY-MM-DD.md ← Raw daily logs, never delete (source of truth) Layer 1: MEMORY.md ← Active memory (recent 2 weeks: detailed) Layer 2: memory/archive-YYYY-MM.md ← Monthly archive (highly compressed + index) ``` ```markdown **Monthly archive flow (run at start of each month):** 1. Compress last month's daily logs into `memory/archive-YYYY-MM.md` 2. Refine corresponding old entries in MEMORY.md, add index pointers to archive/daily log 3. Keep raw daily log files intact (Layer 0 is immutable) 4. Append an index table at end of archive: date → source file → key topics ``` `SKILL.md`, lines 236–252: ```markdown **Solution:** Configure OpenClaw's built-in vector search with a lightweight embedding provider. This indexes all memory layers and enables semantic retrieval across the whole history. **Setup (no self-hosted infra required):** ```bash # 1. Get a Gemini API key from https://aistudio.google.com/apikey # 2. Configure OpenClaw openclaw config set agents.defaults. ...[truncated 3850 chars]- Remediation
View remediation
