Back to skill

Security audit

MEMORY.md Manager - 长期记忆管理 (安全版)

Security checks for vulnerabilities and agentic risk

Overview

This memory-management skill has a coherent purpose, but it can automatically persist conversation-derived content and send filtered session log content with an API bearer key to a configured LLM endpoint without enough scoping or local redaction.

Install only if you are comfortable with a memory file retaining conversation-derived details and, when an API key is configured, with selected session-log lines being sent to the first configured LLM provider endpoint. Prefer disabling scheduled updates until you review the script, use a dedicated low-privilege API key, ensure the provider URL is trusted and HTTPS, and periodically inspect or purge MEMORY.md.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/update-memory.sh:52
Finding

Conversation Content and API Credentials Can Be Sent to an Unvalidated Endpoint

Content
View full analysis
/dev/null | head -n 30 || true) if [ -z "$MATCHED_CONTENT" ]; then echo "⏭️ 无匹配内容" exit 0 fi MATCH_COUNT=$(echo "$MATCHED_CONTENT" | wc -l) echo "📊 匹配:$MATCH_COUNT 行" ``` ```python data = { "model": model, "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content": content} ], "temperature": 0.3, "max_tokens": 800 } req = urllib.request.Request( ap ...[truncated 3684 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
scripts/update-memory.sh:162
Finding

Untrusted Conversation Content Can Poison Persistent Agent Memory

Content
View full analysis
/dev/null | head -n 30 || true) if [ -z "$MATCHED_CONTENT" ]; then echo "⏭️ 无匹配内容" exit 0 fi MATCH_COUNT=$(echo "$MATCHED_CONTENT" | wc -l) echo "📊 匹配:$MATCH_COUNT 行" ``` ```bash case "$RESULT" in *TIMEOUT*|*ERROR*|NO_API_KEY) if [ "$RESULT" = "NO_API_KEY" ]; then echo "⚠️ 未配置 API Key (降级规则模式)" else echo "⚠️ 调用失败 (降级规则模式)" fi echo -e "\n### $TODAY - 规则匹配" >> "$MEMORY_FILE" echo "$MATCHED_CONTENT" | head -n 10 | while IFS= read -r line; do [ -n "$line" ] && echo "- $line" >> "$MEMORY_FILE" done echo "$TODAY" > "$LAST_UPDATE_FILE" exit 0 ;; ``` ```bash { echo "" if [ "$SENSITIVE" = "true" ]; then echo "### ⚠️ $TODAY - $SUMMARY" echo "**敏感信息已脱敏**" else echo "### ✅ $TODAY - $SUMMARY" fi echo "" echo "$EVENTS_JSON" | jq -r '.[] | " - [\(.category)] \(.title): \(.detail)"' echo "" } >> "$MEMORY_FILE" echo "$TODAY" > "$LAST_UPDATE_FILE" echo "✅ 完成 | 敏感:$SENSITIVE" ``` The selected content is supplied to the remote model as untrusted user content: ```python data = { "model": model, "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content": content} ], "temperature": 0.3, "max_tokens": 800 } ``` ### Technical Analysis Daily conversation logs are untrusted input because their content can originate from users or other conversation participants. The script performs onl ...[truncated 2518 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/update-memory.sh:148
Finding

API Key Fragments Are Exposed in Execution Logs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script tells the user that sensitive information has been detected and redacted, but it never performs any local redaction on the LLM-returned event details before appending them to MEMORY.md. If the model echoes secrets from the session log or fails to redact reliably, the script will persist those secrets to disk, creating a durable leakage and false sense of safety.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README indicates that installation creates a cron job and that MEMORY.md will be updated automatically every midnight, but it does not prominently warn users that installing the skill establishes a persistent scheduled task that will modify files without further confirmation. In an agent-skill context, unattended background modification is security-relevant because it affects user data over time and may surprise users or mask later abuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill file is entirely written as a Chinese-only user-facing description, starting with a Chinese title, and does not mention any option for other languages or locale choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The recommended memory structure explicitly stores personal user details and system environment information in persistent memory. This broadens the blast radius of any compromise or accidental disclosure by centralizing identity, preferences, host details, and configuration data in a single long-lived file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The feature description at L084-L091 says daily automatic updates use rule pre-filtering, LLM analysis, and desensitization detection. But the later warning at L095 says automatic updates will not intelligently filter content, which directly contradicts the earlier behavior description and changes the user's understanding of what the skill actually does.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section instructs the skill to inspect session history and persist summaries into a long-term MEMORY.md file. Even if intended as a convenience feature, it creates ongoing collection and retention of conversational data, which increases the risk of storing secrets, personal data, or sensitive operational context beyond the original session lifecycle.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example encourages storing user preferences, timezone, host information, version data, and ongoing tasks in persistent memory. Concrete examples strongly shape operator behavior, so this increases the likelihood of unnecessary long-term retention of sensitive or deanonymizing information.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

  1. 隐私保护 - MEMORY.md 可能包含敏感信息,注意文件权限

    bash
    chmod 600 ~/.openclaw/workspace/MEMORY.md
    
  2. 文件大小 - 定期清理过时的待办事项,避免文件过大

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

bash
# 检查 memory/ 目录
ls -la ~/.openclaw/workspace/memory/

# 手动触发更新
./scripts/update-memory.sh

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest uses Chinese for the main description and summary fields, while English appears only in alternate fields. This can impose a specific language experience by default without explicit user opt-in or a documented region-specific justification, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated cron setup presents and emits a fixed timezone of "Asia/Shanghai" for the scheduled task. This is a natural-language locale policy issue because the skill does not ask the user for their preferred timezone or explain that the skill is intended only for a China-specific environment.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 67)May include surrounding context.

sh
echo "✅ MEMORY.md 已创建 (基础模板)"
fi

chmod 600 "$MEMORY_FILE"
echo "🔒 文件权限已设置为 600"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/init-memory.sh (reported line 42)May include surrounding context.

sh
echo "✅ MEMORY.md 已创建 (基础模板)"
fi

chmod 600 "$MEMORY_FILE"
echo "🔒 文件权限已设置为 600"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script reads local provider configuration and API credentials, then sends filtered session-log content to an external LLM endpoint selected from that configuration. Even though the data is pre-filtered and the feature appears intended to summarize memory, it still creates an outbound data-transfer path for potentially sensitive user/workspace content without strong scoping, local minimization, or explicit consent tied to each transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script transmits session content to an external LLM API but does not present an explicit consent prompt or clear warning at the point of transfer. Users may reasonably assume a local memory update, while in reality conversation excerpts are sent off-host to a provider derived from configuration, which can expose private operational or personal information.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script forwards session-log content to an external LLM for summarization, which is a direct data-exposure path for user-provided natural-language content. Because session logs may contain credentials, internal decisions, errors, or operational details, sending them to a remote service increases confidentiality risk even when the purpose is summarization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language content, including setup and operation instructions, is presented only in Chinese, which can impose a language constraint on users without opt-in. The policy allows language restrictions only when users are given a choice or when the locale limitation is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script's natural-language comments, status messages, and LLM system prompt are entirely in Chinese, with no indication that the user can select another language. This may violate language/locale policy where skills must not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.