hindsight
Fail
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/audit_hindsight_memory.pyattempts to access a configuration file at the hardcoded absolute path/home/delorenj/.openclaw/openclaw.json. This pattern exposes sensitive user-specific configuration and reflects poor security practices for a distributed skill. - [REMOTE_CODE_EXECUTION]: Documentation and setup guides repeatedly recommend executing remote shell scripts directly via piped commands (e.g.,
curl ... | bash). Specifically, scripts for the CLI, MCP server, and agent skill are fetched fromhindsight.vectorize.ioand executed without verification. - [DYNAMIC_EXECUTION]: The skill configuration supports the
HINDSIGHT_API_EMBEDDINGS_LOCAL_TRUST_REMOTE_CODEenvironment variable, which enables the loading and execution of untrusted Python code embedded within machine learning models downloaded from the internet. - [INDIRECT_PROMPT_INJECTION]: The skill's architecture is inherently vulnerable to indirect prompt injection.
- Ingestion points: Arbitrary content is ingested via
hindsight memory retainas shown inSKILL.mdandreferences/developer/api/retain.md. - Boundary markers: Explicit delimiters for ingested instructions are absent.
- Capability inventory: The skill uses the
hindsightCLI which has network and file system access capabilities. - Sanitization: External content is not sanitized before interpolation into prompts during
recallorreflectoperations.
Recommendations
- AI detected serious security threats
Audit Metadata