Back to plugin

Security audit

Nessie

Security checks for vulnerabilities and agentic risk

Overview

The skill coherently connects OpenClaw to the user's Nessie memory library, with sensitive read/write capabilities disclosed and write actions gated by explicit confirmation.

Install only if you trust Nessie Labs with access to the connected Nessie library and are comfortable with OpenClaw storing a local bearer key. Expect the agent to search/read personal and explicitly shared sources for prior-work questions, while creates, edits, moves, profile updates, and deletes should be previewed and confirmed before execution.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation guidance is extremely broad, telling the agent to use Nessie for many common prompts about prior work, notes, relationships, or anything the user may have discussed before. In practice, that can cause over-collection from a sensitive personal knowledge base for routine requests, increasing the chance of unnecessary access to private data and accidental disclosure in responses.

Static analysis

No suspicious patterns detected.