Back to skill

Security audit

记忆索引管理器

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is purpose-aligned overall, but it includes under-scoped background scheduled processing of long-term memory.

Review this before installing if your OpenClaw memory may contain sensitive personal, business, or credential-adjacent information. The skill's memory indexing is understandable, but the scheduled daily flush and LaunchAgent references should be opt-in, auditable, and easy to disable or remove.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
SKILL.md:120
Finding

Persistent Scheduled Processing of Long-Term Agent Memory

Content
View full analysis
marker 3. Execute OpenClaw native memory storage: - Append to yesterday's file - Archive any in-memory context from yesterday 4. Execute Skill index update: - Scan yesterday's file for index-worthy topics - Update INDEX.md with yesterday's date - Check if any topic needs consolidation (>3 days) 5. Initialize today's memory file (if not exists) 6. Log flush completion ``` **Daily Flush Script**: `~/.openclaw/scripts/daily-flush.sh` **Launchd Config**: `~/Library/LaunchAgents/com.openclaw.daily-flush.plist` ``` ### Technical Analysis The Skill specifies a recurring system-level scheduled workflow implemented through a daily flush script and a macOS LaunchAgent. A LaunchAgent survives individual Skill invocations and conversation sessions, allowing the workflow to execute every day without a contemporaneous user request. The scheduled workflow is instructed to read conversation-memory files, archive in-memory context, create or modify daily memory files, and update persistent indexes and consolidations. This creates an autonomous cross-session processing mechanism over potentially sensitive conversation history. The referenced `daily-flush.sh` script and LaunchAgent property list are not included in the audited package. Consequently, the actual commands, filesystem restrictions, error handling, and integrity of the scheduled implementation cannot be verified. The audit found no evidence of network exfiltration or privilege elevation, but the persistence mechanism itself falls within the system-persiste ...[truncated 1510 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

text
1. Identify yesterday's date (YYYY-MM-DD)
2. Check if yesterday's memory file exists
   - If not: create empty file with <!-- DAILY_FLUSH --> marker
3. Execute OpenClaw native memory storage:
   - Append <!-- NATIVE_FLUSH --> to yesterday's file
   - Archive any in-memory context from yesterday

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill describes passive/background maintenance and automatic index upkeep but does not clearly warn users that it may create and update files in memory storage outside explicit recall requests. This can mislead users about when persistence occurs, causing unintended retention of sensitive conversation data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This section confirms automatic writing of conversation-derived content into persistent memory files during native flushes or on 'remember this', which expands session data retention. In the context of a memory-management skill, persistence is expected, but the risk remains because sensitive data may be stored longer than the user anticipates.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

c. (Optional) Propose adding to index if significant

text

### 2. Native Write (Automatic)

**Trigger**: OpenClaw pre-compaction flush or user says "remember this"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The daily scheduled flush explicitly archives conversation memory at 11:00 AM even when the user did not say 'remember', yet the skill does not present this as a prominent warning or consent boundary. That creates a significant privacy risk because users may reasonably believe memory access is only activated by explicit recall phrases.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

The referenced daily-flush script and launchd job establish unattended scheduled persistence of session memory, including cases where the user never explicitly requested remembrance. This increases privacy and data-retention risk because background automation can archive context without active user awareness at the time of storage.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

text

**Daily Flush Script**: `~/.openclaw/scripts/daily-flush.sh`
**Launchd Config**: `~/Library/LaunchAgents/com.openclaw.daily-flush.plist`

**Purpose**: Ensure yesterday's memory is properly archived even if:
- User didn't explicitly say "remember"

Static analysis

No suspicious patterns detected.