amber-hunter
A legitimate, well-documented local AI memory backend with strong E2E encryption. Minor documented fallbacks for headless Linux do not constitute hidden malicious behavior.
Why this conclusion was reached
0/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
8 lower-risk artifacts were extracted and still need context.
There is no explicit malicious chain in the report.
2 dependency or supply-chain issues need attention.
What drove the risk score up
requirements.txt uses >= for all packages without version pins, enabling supply chain risk
core/keychain.py:164 — master_password stored in config.json for headless Linux, documented in SKILL.md but still stores sensitive credential in plaintext on disk
core/llm.py uses subprocess to call curl for API calls — documented and legitimate for a CLI tool
Most important evidence
Unpinned Python dependencies
All packages in requirements.txt use >= version specifiers without upper bounds. This allows dependency confusion attacks and supply chain injection via package updates.
requirements.txt:1 Linux headless stores master_password in plaintext
On headless Linux (VPS), master_password falls back to config.json in plaintext. While documented, this means the encryption key is stored unencrypted on disk.
core/keychain.py:164 master_password also written to config.json as fallback on all platforms
set_master_password_handler writes master_password to config.json even when OS keychain succeeds on macOS/Windows. The Keychain is primary but config.json serves as an unnecessary backup copy.
amber_hunter.py:2063 Reads API keys from OpenClaw config
core/llm.py auto-detects LLM API keys from ~/.openclaw/openclaw.json. This reads third-party credentials to auto-configure providers.
core/llm.py:524 Session file access for proactive capture
core/session.py and proactive scripts read OpenClaw/Claude session .jsonl files to build conversation context. This is declared in SKILL.md as the core proactive capture feature.
core/session.py:60 Declared capability vs actual capability
SKILL.md allowed-tools maps Read→filesystem:READ; code reads ~/.amber-hunter/, ~/.openclaw/, ~/.claude/ install.sh/freeze.sh are shell scripts; LLM providers use subprocess.run with curl for API calls SKILL.md declares huper.org cloud sync; core/llm.py makes API calls to minimaxi.com, groq.com, anthropic.com, openai.com — all documented SKILL.md: Memory write via /ingest is a core capability; code writes to SQLite at ~/.amber-hunter/hunter.db core/llm.py:361 reads MINIMAX_API_KEY env var; core/keychain.py:115 reads AMBER_TOKEN — both documented credential sources Suspicious artifacts and egress
https://huper.org CHANGELOG.md:275
https://huper.org/dashboard README.md:33
https://huper.org/api README.md:43
https://huper.org/api/ingest SKILL.md:68
http://127.0.0.1:18998 amber_hunter.py:619
https://api.minimaxi.com/anthropic/v1/messages core/llm.py:130
https://api.groq.com/openai/v1/chat/completions core/llm.py:624
https://api.minimaxi.com/anthropic core/llm.py:692
Dependencies and supply chain
| Package | Version | Source | Known vuln | Notes |
|---|---|---|---|---|
| fastapi | 0.115.0 | pip | No | Lower bound only, no upper cap |
| uvicorn | 0.30.0 | pip | No | Lower bound only |
| pydantic | 2.9.0 | pip | No | Lower bound only |
| cryptography | 43.0.0 | pip | No | Lower bound only |
| httpx | 0.27.0 | pip | No | Lower bound only |
| sentence-transformers | >=2.2.0 | pip | No | Version not pinned, ~90MB ML model download at install time |
| numpy | >=1.24.0 | pip | No | Version not pinned |
| pytest | >=8.0.0 | pip | No | Test only, not shipped |
File composition
amber_hunter.py core/llm.py core/session.py CHANGELOG.md SKILL.md core/keychain.py README.md