Back to skill

Security audit

Agent Architecture Guide

Security checks for vulnerabilities and agentic risk

Overview

This guide is not malware, but it recommends broad, long-lived memory logging and remote indexing without enough privacy controls.

Install only if you want an agent architecture that relies heavily on persistent memory. Before using the memory and vector-search patterns, decide what may be stored, exclude secrets and sensitive personal data, set deletion or retention rules, and prefer local embeddings or a clearly approved remote provider.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:22
Finding

Excessive Persistent Conversation Logging and Unscoped Remote Memory Indexing

Content
View full analysis
60%, log every exchange to `memory/working-buffer.md`. 1. Check context via `session_status` 2. At 60%: create/clear working buffer 3. Every message after: append human message + your response summary 4. After compaction: read buffer FIRST 5. Never ask "what were we doing?" — the buffer has it ``` `SKILL.md`, lines 187–195: ```markdown Layer 0: memory/YYYY-MM-DD.md ← Raw daily logs, never delete (source of truth) Layer 1: MEMORY.md ← Active memory (recent 2 weeks: detailed) Layer 2: memory/archive-YYYY-MM.md ← Monthly archive (highly compressed + index) ``` ```markdown **Monthly archive flow (run at start of each month):** 1. Compress last month's daily logs into `memory/archive-YYYY-MM.md` 2. Refine corresponding old entries in MEMORY.md, add index pointers to archive/daily log 3. Keep raw daily log files intact (Layer 0 is immutable) 4. Append an index table at end of archive: date → source file → key topics ``` `SKILL.md`, lines 236–252: ```markdown **Solution:** Configure OpenClaw's built-in vector search with a lightweight embedding provider. This indexes all memory layers and enables semantic retrieval across the whole history. **Setup (no self-hosted infra required):** ```bash # 1. Get a Gemini API key from https://aistudio.google.com/apikey # 2. Configure OpenClaw openclaw config set agents.defaults. ...[truncated 3850 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

Solution: Check stats before installing:

bash
curl -s "https://clawhub.ai/api/v1/skills/SLUG" | python3 -c "
import sys,json
d=json.load(sys.stdin)['skill']
s=d.get('stats',{})

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The vector search setup recommends configuring remote embedding providers for memory indexing but does not disclose that memory contents may be transmitted to third-party services for embedding. In this skill's context, the indexed data includes layered memory files and daily logs, so the omission can expose a large body of potentially sensitive historical user data to external providers unintentionally.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 311)May include surrounding context.

md
# Operational Index

## Gateway Restart Flow
<!-- aliases: restart, how to restart, restart steps -->
1. Update NOW.md
2. Send notification + set recovery cron
3. Restart → verify exit code

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section instructs agents to write conversation-derived facts to persistent memory before responding, but it does not warn operators that this changes transient chat content into retained data. That omission can lead to silent storage of sensitive or personal information, especially because the trigger examples include preferences, proper nouns, and dates.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The WAL trigger list is broad enough to fire on routine conversation content such as corrections, preferences, names, and dates, which can cause over-collection of user data into persistent memory. In an agent architecture guide, this creates a realistic risk of unnecessary retention of sensitive conversational details and expands the privacy blast radius if memory is later searched, shared, or sent to other components.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The working buffer guidance recommends logging every exchange once context exceeds a threshold, which materially increases persistent retention of whole conversations without any accompanying privacy warning. Because this can capture broad conversational content rather than only durable facts, it raises the risk of storing secrets, personal data, or incidental sensitive context unnecessarily.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The section says to 'always include both languages inline' for certain facts, imposing a specific language behavior by default. This is a language policy concern because it forces bilingual output/storage without user opt-in or a documented requirement that the skill is specifically for a bilingual environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.