安全决策报告

amber-hunter

A legitimate, well-documented local AI memory backend with strong E2E encryption. Minor documented fallbacks for headless Linux do not constitute hidden malicious behavior.

安装决策优先 来源: 手动上传 扫描时间: 2026/4/3
文件 29
IOC 8
越权项 0
发现 5

为什么得出这个结论

0/4 个维度触发
通过
声明与实际能力

声明资源与推断能力基本一致。

复核
隐藏执行与外联

提取到 8 个一般风险产物,需要结合上下文判断。

通过
攻击链与高危发现

没有形成明确的恶意路径。

复核
依赖与供应链卫生

发现 2 项需要关注的依赖或供应链线索。

风险分是怎么被拉高的

Broad dependency declarations +10

requirements.txt uses >= for all packages without version pins, enabling supply chain risk

Linux headless master_password plaintext fallback +10

core/keychain.py:164 — master_password stored in config.json for headless Linux, documented in SKILL.md but still stores sensitive credential in plaintext on disk

subprocess usage via curl for LLM calls +0

core/llm.py uses subprocess to call curl for API calls — documented and legitimate for a CLI tool

最关键的证据

中危

Unpinned Python dependencies

All packages in requirements.txt use >= version specifiers without upper bounds. This allows dependency confusion attacks and supply chain injection via package updates.

requirements.txt:1
Pin exact versions: sentence-transformers==2.7.0, numpy==1.26.4, etc.
低危

Linux headless stores master_password in plaintext

On headless Linux (VPS), master_password falls back to config.json in plaintext. While documented, this means the encryption key is stored unencrypted on disk.

core/keychain.py:164
Warn users explicitly at install time; consider requiring user acknowledgment
低危

master_password also written to config.json as fallback on all platforms

set_master_password_handler writes master_password to config.json even when OS keychain succeeds on macOS/Windows. The Keychain is primary but config.json serves as an unnecessary backup copy.

amber_hunter.py:2063
Only write to config.json when OS keychain fails, not as a parallel backup
提示

Reads API keys from OpenClaw config

core/llm.py auto-detects LLM API keys from ~/.openclaw/openclaw.json. This reads third-party credentials to auto-configure providers.

core/llm.py:524
This is documented and intentional — the skill needs LLM keys to power its AI features
提示

Session file access for proactive capture

core/session.py and proactive scripts read OpenClaw/Claude session .jsonl files to build conversation context. This is declared in SKILL.md as the core proactive capture feature.

core/session.py:60
No action needed — this is the stated purpose of the skill

声明能力 vs 实际能力

文件系统 通过
声明 READ
→
推断 READ
SKILL.md allowed-tools maps Read→filesystem:READ; code reads ~/.amber-hunter/, ~/.openclaw/, ~/.claude/
命令执行 通过
声明 WRITE
→
推断 WRITE
install.sh/freeze.sh are shell scripts; LLM providers use subprocess.run with curl for API calls
网络访问 通过
声明 READ
→
推断 READ
SKILL.md declares huper.org cloud sync; core/llm.py makes API calls to minimaxi.com, groq.com, anthropic.com, openai.com — all documented
数据库 通过
声明 READ
→
推断 WRITE
SKILL.md: Memory write via /ingest is a core capability; code writes to SQLite at ~/.amber-hunter/hunter.db
环境变量 通过
声明 NONE
→
推断 READ
core/llm.py:361 reads MINIMAX_API_KEY env var; core/keychain.py:115 reads AMBER_TOKEN — both documented credential sources

可疑产物与外联

中危 外部 URL
https://huper.org

CHANGELOG.md:275

中危 外部 URL
https://huper.org/dashboard

README.md:33

中危 外部 URL
https://huper.org/api

README.md:43

中危 外部 URL
https://huper.org/api/ingest

SKILL.md:68

中危 外部 URL
http://127.0.0.1:18998

amber_hunter.py:619

中危 外部 URL
https://api.minimaxi.com/anthropic/v1/messages

core/llm.py:130

中危 外部 URL
https://api.groq.com/openai/v1/chat/completions

core/llm.py:624

中危 外部 URL
https://api.minimaxi.com/anthropic

core/llm.py:692

依赖与供应链

包名版本来源漏洞备注
fastapi 0.115.0 pip 否 Lower bound only, no upper cap
uvicorn 0.30.0 pip 否 Lower bound only
pydantic 2.9.0 pip 否 Lower bound only
cryptography 43.0.0 pip 否 Lower bound only
httpx 0.27.0 pip 否 Lower bound only
sentence-transformers >=2.2.0 pip 否 Version not pinned, ~90MB ML model download at install time
numpy >=1.24.0 pip 否 Version not pinned
pytest >=8.0.0 pip 否 Test only, not shipped

文件构成

29 个文件 · 6548 行
Python 14 个文件 · 4387 行Markdown 7 个文件 · 1057 行JavaScript 3 个文件 · 606 行Shell 3 个文件 · 325 行TypeScript 1 个文件 · 161 行Text 1 个文件 · 12 行
需关注文件 · 7
amber_hunter.py Python · 2169 行
master_password also written to config.json as fallback on all platforms · http://127.0.0.1:18998
core/llm.py Python · 735 行
Reads API keys from OpenClaw config · https://api.minimaxi.com/anthropic/v1/messages · https://api.groq.com/openai/v1/chat/completions · https://api.minimaxi.com/anthropic
core/session.py Python · 450 行
Session file access for proactive capture
CHANGELOG.md Markdown · 287 行
https://huper.org
SKILL.md Markdown · 308 行
https://huper.org/api/ingest
core/keychain.py Python · 284 行
Linux headless stores master_password in plaintext
README.md Markdown · 261 行
https://huper.org/dashboard · https://huper.org/api
其他文件 · db.py · proactive-check.js · install.sh · proactive-check.js · handler.ts

安全亮点

E2E AES-256-GCM encryption with PBKDF2-HMAC-SHA256 key derivation (100k iterations)
master_password stored in OS Keychain (macOS security, Linux secret-tool, Windows cmdkey)
Local service restricted to localhost:18998 — no remote exposure
Cloud sync payload is E2E encrypted before upload; huper.org never sees plaintext
No base64/eval obfuscation or dynamic code execution patterns
No reverse shell, C2 infrastructure, or data exfiltration to unexpected hosts
All external network IOCs map to declared API endpoints (huper.org, LLM providers)
Review queue requires user approval before memories become permanent
SKILL.md is comprehensive and accurately describes capabilities
Comprehensive CORS restrictions to declared origins only