Skill Trust Decision

amber-hunter

A legitimate, well-documented local AI memory backend with strong E2E encryption. Minor documented fallbacks for headless Linux do not constitute hidden malicious behavior.

Install decision first Source: Manual upload Scanned: Apr 3, 2026
Files 29
Artifacts 8
Violations 0
Findings 5

Why this conclusion was reached

0/4 dimensions flagged
Pass
Declared vs actual capability

Declared resources and inferred behavior are broadly aligned.

Review
Hidden execution and egress

8 lower-risk artifacts were extracted and still need context.

Pass
Attack chain and severe findings

There is no explicit malicious chain in the report.

Review
Dependencies and supply chain hygiene

2 dependency or supply-chain issues need attention.

What drove the risk score up

Broad dependency declarations +10

requirements.txt uses >= for all packages without version pins, enabling supply chain risk

Linux headless master_password plaintext fallback +10

core/keychain.py:164 — master_password stored in config.json for headless Linux, documented in SKILL.md but still stores sensitive credential in plaintext on disk

subprocess usage via curl for LLM calls +0

core/llm.py uses subprocess to call curl for API calls — documented and legitimate for a CLI tool

Most important evidence

Medium

Unpinned Python dependencies

All packages in requirements.txt use >= version specifiers without upper bounds. This allows dependency confusion attacks and supply chain injection via package updates.

requirements.txt:1
Pin exact versions: sentence-transformers==2.7.0, numpy==1.26.4, etc.
Low

Linux headless stores master_password in plaintext

On headless Linux (VPS), master_password falls back to config.json in plaintext. While documented, this means the encryption key is stored unencrypted on disk.

core/keychain.py:164
Warn users explicitly at install time; consider requiring user acknowledgment
Low

master_password also written to config.json as fallback on all platforms

set_master_password_handler writes master_password to config.json even when OS keychain succeeds on macOS/Windows. The Keychain is primary but config.json serves as an unnecessary backup copy.

amber_hunter.py:2063
Only write to config.json when OS keychain fails, not as a parallel backup
Info

Reads API keys from OpenClaw config

core/llm.py auto-detects LLM API keys from ~/.openclaw/openclaw.json. This reads third-party credentials to auto-configure providers.

core/llm.py:524
This is documented and intentional — the skill needs LLM keys to power its AI features
Info

Session file access for proactive capture

core/session.py and proactive scripts read OpenClaw/Claude session .jsonl files to build conversation context. This is declared in SKILL.md as the core proactive capture feature.

core/session.py:60
No action needed — this is the stated purpose of the skill

Declared capability vs actual capability

Filesystem Pass
Declared READ
→
Inferred READ
SKILL.md allowed-tools maps Read→filesystem:READ; code reads ~/.amber-hunter/, ~/.openclaw/, ~/.claude/
Shell Pass
Declared WRITE
→
Inferred WRITE
install.sh/freeze.sh are shell scripts; LLM providers use subprocess.run with curl for API calls
Network Pass
Declared READ
→
Inferred READ
SKILL.md declares huper.org cloud sync; core/llm.py makes API calls to minimaxi.com, groq.com, anthropic.com, openai.com — all documented
Database Pass
Declared READ
→
Inferred WRITE
SKILL.md: Memory write via /ingest is a core capability; code writes to SQLite at ~/.amber-hunter/hunter.db
Environment Pass
Declared NONE
→
Inferred READ
core/llm.py:361 reads MINIMAX_API_KEY env var; core/keychain.py:115 reads AMBER_TOKEN — both documented credential sources

Suspicious artifacts and egress

Medium External URL
https://huper.org

CHANGELOG.md:275

Medium External URL
https://huper.org/dashboard

README.md:33

Medium External URL
https://huper.org/api

README.md:43

Medium External URL
https://huper.org/api/ingest

SKILL.md:68

Medium External URL
http://127.0.0.1:18998

amber_hunter.py:619

Medium External URL
https://api.minimaxi.com/anthropic/v1/messages

core/llm.py:130

Medium External URL
https://api.groq.com/openai/v1/chat/completions

core/llm.py:624

Medium External URL
https://api.minimaxi.com/anthropic

core/llm.py:692

Dependencies and supply chain

PackageVersionSourceKnown vulnNotes
fastapi 0.115.0 pip No Lower bound only, no upper cap
uvicorn 0.30.0 pip No Lower bound only
pydantic 2.9.0 pip No Lower bound only
cryptography 43.0.0 pip No Lower bound only
httpx 0.27.0 pip No Lower bound only
sentence-transformers >=2.2.0 pip No Version not pinned, ~90MB ML model download at install time
numpy >=1.24.0 pip No Version not pinned
pytest >=8.0.0 pip No Test only, not shipped

File composition

29 files · 6548 lines
Python 14 files · 4387 linesMarkdown 7 files · 1057 linesJavaScript 3 files · 606 linesShell 3 files · 325 linesTypeScript 1 files · 161 linesText 1 files · 12 lines
Files of concern · 7
amber_hunter.py Python · 2169 lines
master_password also written to config.json as fallback on all platforms · http://127.0.0.1:18998
core/llm.py Python · 735 lines
Reads API keys from OpenClaw config · https://api.minimaxi.com/anthropic/v1/messages · https://api.groq.com/openai/v1/chat/completions · https://api.minimaxi.com/anthropic
core/session.py Python · 450 lines
Session file access for proactive capture
CHANGELOG.md Markdown · 287 lines
https://huper.org
SKILL.md Markdown · 308 lines
https://huper.org/api/ingest
core/keychain.py Python · 284 lines
Linux headless stores master_password in plaintext
README.md Markdown · 261 lines
https://huper.org/dashboard · https://huper.org/api
Other files · db.py · proactive-check.js · install.sh · proactive-check.js · handler.ts

Security positives

E2E AES-256-GCM encryption with PBKDF2-HMAC-SHA256 key derivation (100k iterations)
master_password stored in OS Keychain (macOS security, Linux secret-tool, Windows cmdkey)
Local service restricted to localhost:18998 — no remote exposure
Cloud sync payload is E2E encrypted before upload; huper.org never sees plaintext
No base64/eval obfuscation or dynamic code execution patterns
No reverse shell, C2 infrastructure, or data exfiltration to unexpected hosts
All external network IOCs map to declared API endpoints (huper.org, LLM providers)
Review queue requires user approval before memories become permanent
SKILL.md is comprehensive and accurately describes capabilities
Comprehensive CORS restrictions to declared origins only