Back to plugin

Security audit

Lossless Context Management

Security checks for vulnerabilities and agentic risk

Overview

This plugin is a disclosed local conversation-memory/context manager; the main risk is that it intentionally keeps complete conversation history for recall.

Install only if you want OpenClaw to retain local long-term conversation memory. Review the database and large-files paths, configure ignoreSessionPatterns or statelessSessionPatterns for conversations you do not want stored, and pin the package version before running npx migration commands with --apply.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L03 explicitly says the system stores full conversation history, which is user data with clear privacy and retention impact. In this markdown file, there is no accompanying warning or disclosure about persistence, sensitivity, or handling of that stored data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skills/lossless-claw/references/config.md (reported line 170)May include surrounding context.

md
Why it matters:

- Larger chunks reduce summarization frequency.
- Smaller chunks create more summaries and more DAG fragmentation.
- The default is 20000 tokens.

Use this when:

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skills/lossless-claw/references/session-lifecycle.md (reported line 26)May include surrounding context.

md
- `/new` prunes active context but keeps the same LCM conversation row
- `/reset` archives the active LCM conversation row and creates a fresh active row
- ordinary chat/thread LCM history may continue in the same row across runtime `sessionId` changes when the stable `sessionKey` continues
- cron scheduler keys create fresh LCM rows per runtime run so prior runs do not enter the new run's assembled context

## Why

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The documentation instructs users to execute an npm package via npx using @latest and without a pinned version. This creates a supply-chain risk: a compromised publisher account, malicious new release, or dependency hijack could cause users to run unreviewed code on their system. In a skill context, copy-pasteable operational commands materially increase the chance of exploitation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command again uses npx with an unpinned package version and adds --apply, which increases risk because the fetched code will perform writes after execution. If an attacker can influence the published package or its dependency chain, users may execute arbitrary code and modify local state or databases. The presence of an explicit write mode makes the operational impact higher than a read-only example.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
docs/configuration.md:99
Evidence
the system prompt: