skills/delorenj/skills/hindsight/Gen Agent Trust Hub

hindsight

Fail

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The script scripts/audit_hindsight_memory.py attempts to access a configuration file at the hardcoded absolute path /home/delorenj/.openclaw/openclaw.json. This pattern exposes sensitive user-specific configuration and reflects poor security practices for a distributed skill.
  • [REMOTE_CODE_EXECUTION]: Documentation and setup guides repeatedly recommend executing remote shell scripts directly via piped commands (e.g., curl ... | bash). Specifically, scripts for the CLI, MCP server, and agent skill are fetched from hindsight.vectorize.io and executed without verification.
  • [DYNAMIC_EXECUTION]: The skill configuration supports the HINDSIGHT_API_EMBEDDINGS_LOCAL_TRUST_REMOTE_CODE environment variable, which enables the loading and execution of untrusted Python code embedded within machine learning models downloaded from the internet.
  • [INDIRECT_PROMPT_INJECTION]: The skill's architecture is inherently vulnerable to indirect prompt injection.
  • Ingestion points: Arbitrary content is ingested via hindsight memory retain as shown in SKILL.md and references/developer/api/retain.md.
  • Boundary markers: Explicit delimiters for ingested instructions are absent.
  • Capability inventory: The skill uses the hindsight CLI which has network and file system access capabilities.
  • Sanitization: External content is not sanitized before interpolation into prompts during recall or reflect operations.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — hindsight