amber-hunter
A legitimate, well-documented local AI memory backend with strong E2E encryption. Minor documented fallbacks for headless Linux do not constitute hidden malicious behavior.
为什么得出这个结论
0/4 个维度触发声明资源与推断能力基本一致。
提取到 8 个一般风险产物,需要结合上下文判断。
没有形成明确的恶意路径。
发现 2 项需要关注的依赖或供应链线索。
风险分是怎么被拉高的
requirements.txt uses >= for all packages without version pins, enabling supply chain risk
core/keychain.py:164 — master_password stored in config.json for headless Linux, documented in SKILL.md but still stores sensitive credential in plaintext on disk
core/llm.py uses subprocess to call curl for API calls — documented and legitimate for a CLI tool
最关键的证据
Unpinned Python dependencies
All packages in requirements.txt use >= version specifiers without upper bounds. This allows dependency confusion attacks and supply chain injection via package updates.
requirements.txt:1 Linux headless stores master_password in plaintext
On headless Linux (VPS), master_password falls back to config.json in plaintext. While documented, this means the encryption key is stored unencrypted on disk.
core/keychain.py:164 master_password also written to config.json as fallback on all platforms
set_master_password_handler writes master_password to config.json even when OS keychain succeeds on macOS/Windows. The Keychain is primary but config.json serves as an unnecessary backup copy.
amber_hunter.py:2063 Reads API keys from OpenClaw config
core/llm.py auto-detects LLM API keys from ~/.openclaw/openclaw.json. This reads third-party credentials to auto-configure providers.
core/llm.py:524 Session file access for proactive capture
core/session.py and proactive scripts read OpenClaw/Claude session .jsonl files to build conversation context. This is declared in SKILL.md as the core proactive capture feature.
core/session.py:60 声明能力 vs 实际能力
SKILL.md allowed-tools maps Read→filesystem:READ; code reads ~/.amber-hunter/, ~/.openclaw/, ~/.claude/ install.sh/freeze.sh are shell scripts; LLM providers use subprocess.run with curl for API calls SKILL.md declares huper.org cloud sync; core/llm.py makes API calls to minimaxi.com, groq.com, anthropic.com, openai.com — all documented SKILL.md: Memory write via /ingest is a core capability; code writes to SQLite at ~/.amber-hunter/hunter.db core/llm.py:361 reads MINIMAX_API_KEY env var; core/keychain.py:115 reads AMBER_TOKEN — both documented credential sources 可疑产物与外联
https://huper.org CHANGELOG.md:275
https://huper.org/dashboard README.md:33
https://huper.org/api README.md:43
https://huper.org/api/ingest SKILL.md:68
http://127.0.0.1:18998 amber_hunter.py:619
https://api.minimaxi.com/anthropic/v1/messages core/llm.py:130
https://api.groq.com/openai/v1/chat/completions core/llm.py:624
https://api.minimaxi.com/anthropic core/llm.py:692
依赖与供应链
| 包名 | 版本 | 来源 | 漏洞 | 备注 |
|---|---|---|---|---|
| fastapi | 0.115.0 | pip | 否 | Lower bound only, no upper cap |
| uvicorn | 0.30.0 | pip | 否 | Lower bound only |
| pydantic | 2.9.0 | pip | 否 | Lower bound only |
| cryptography | 43.0.0 | pip | 否 | Lower bound only |
| httpx | 0.27.0 | pip | 否 | Lower bound only |
| sentence-transformers | >=2.2.0 | pip | 否 | Version not pinned, ~90MB ML model download at install time |
| numpy | >=1.24.0 | pip | 否 | Version not pinned |
| pytest | >=8.0.0 | pip | 否 | Test only, not shipped |
文件构成
amber_hunter.py core/llm.py core/session.py CHANGELOG.md SKILL.md core/keychain.py README.md