Back to skill

Security audit

Ollama Memory Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly purpose-aligned for setting up local Ollama memory search, but its installer path and endpoint handling need review before use.

Review before installing. The diagnostic mode is reasonable, but avoid running --install on Linux unless you are comfortable with the vendor curl-to-shell installer or replace it with a safer verified install. Keep --base-url at the default localhost value unless you have independently validated the destination, and be cautious with --apply-config because it persists the memory-search endpoint.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/check-ollama-memory.sh:90
Finding

Unverified Remote Installer Is Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: scripts/check-ollama-memory.sh:90; SKILL.md:83
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

scripts/check-ollama-memory.sh:90:

bash
curl -fsSL https://ollama.com/install.sh | sh

SKILL.md:83:

bash
curl -fsSL https://ollama.com/install.sh | sh

Technical Analysis

The installation workflow downloads mutable content from an external endpoint and passes it directly to sh. The retrieved code is not pinned to a reviewed version and is not verified using a checksum or cryptographic signature.

HTTPS provides transport protection, but it does not establish that the current response is identical to the script reviewed when this Skill was published. A compromise of the remote host, its deployment pipeline, DNS or certificate infrastructure, or an unexpected upstream modification could therefore change the code executed by this Skill.

Installing Ollama is relevant to the declared functionality and the executable path requires the explicit --install option. Nevertheless, directly piping a remote response into a shell exceeds the minimum safe privilege and trust boundary necessary to install the software. The documentation also encourages users to reproduce the same unsafe command manually.

Attack Path

  1. A user or Agent invokes scripts/check-ollama-memory.sh --install, or follows the installation command in SKILL.md.
  2. The script requests the current content of https://ollama.com/install.sh.
  3. The response is immediately supplied to sh without local review, version pinning, checksum validation, or signature verification.
  4. If the endpoint or delivery chain has been compromised or unexpectedly modified, attacker-controlled commands execute in the local shell.
  5. Those commands can access and modify resources available to the invoking account and may attempt to obtain additional ...[truncated 670 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh pipeline from both the executable script and documentation.
  2. Prefer a trusted operating-system package repository or another package manager that supports signed metadata and version pinning.
  3. If a vendor installer must be used:
    • Download it to a newly created temporary file with restrictive permissions.
    • Pin an expected installer version or immutable artifact URL.
    • Verify a vendor-published cryptographic signature or checksum obtained through an independent trusted channel.
    • Fail closed if verification cannot be completed.
    • Allow the user to inspect the downloaded file before execution.
    • Execute it as a separate, explicit step only after informed consent.
  4. Do not automatically elevate privileges. Explain any required privilege level and request approval at the point of elevation.
  5. Record the verified version and digest so the installation process is reproducible and auditable.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check-ollama-memory.sh:63
Finding

Private-Network URL Allowlist Can Accept Public Attacker-Controlled Hosts

Content
View full analysis

Vulnerability Details

File Location: scripts/check-ollama-memory.sh:63-69
Vulnerability Type: Inadequate URL and destination validation
Risk Level: Medium

Vulnerable Code

bash
case "$BASE_URL" in
  http://localhost:*|http://127.0.0.1:*|http://[::1]:*|http://localhost|http://127.0.0.1|http://[::1]) ;;
  http://10.*|http://172.16.*|http://172.17.*|http://172.18.*|http://172.19.*|http://172.20.*|http://172.21.*|http://172.22.*|http://172.23.*|http://172.24.*|http://172.25.*|http://172.26.*|http://172.27.*|http://172.28.*|http://172.29.*|http://172.30.*|http://172.31.*|http://192.168.*)
    warn "Using private-LAN Ollama base URL: $BASE_URL"
    ;;
  http://*.local:*|http://*.local)
    warn "Using .local Ollama base URL: $BASE_URL"
    ;;

Technical Analysis

The allowlist uses shell wildcard matching against the complete URL string rather than parsing the URL and validating its resolved destination. Patterns such as http://10.* and http://192.168.* only require matching textual prefixes. Consequently, public DNS names such as http://10.example.com or http://192.168.example.com may be accepted even though they are not RFC1918 IP addresses.

The .local patterns similarly trust the hostname suffix without confirming that the hostname resolves exclusively to loopback or private addresses. The validation also does not protect against DNS rebinding, where an initially acceptable hostname later resolves to a public or otherwise prohibited destination.

Once accepted, the URL is contacted by the API checks at lines 104 and 114 and by the Python embedding request at lines 134-142. When --apply-config is used, it is also stored as agents.defaults.memorySearch.remote.baseUrl at lines 154-167. The weakness therefore undermines the Skill's claim that it refuses non-local or non-private Ollama endpoints.

Attack Path

  1. An attacker persuades a user or Agent to supply a crafted value suc ...[truncated 1231 chars]
Remediation
View remediation

Remediation Suggestions

  1. Parse BASE_URL with a standards-compliant URL parser instead of shell wildcard matching.
  2. Require the http scheme unless TLS is deliberately supported and securely validated.
  3. Reject embedded credentials, fragments, unexpected paths, malformed ports, and ambiguous host encodings.
  4. Resolve the hostname and verify that every resulting address belongs to an explicitly permitted range:
    • IPv4 loopback or RFC1918 ranges.
    • IPv6 loopback or approved IPv6 private ranges.
    • Explicitly approved private hosts.
  5. Reject a hostname if any resolution result is public, link-local where inappropriate, unspecified, multicast, or otherwise outside the allowlist.
  6. Mitigate DNS rebinding by connecting to a validated resolved address while preserving the expected host semantics, or revalidating the peer destination at connection time.
  7. Default strictly to loopback. Require separate informed consent before accepting a private-LAN endpoint.
  8. Before persisting the endpoint with --apply-config, display the normalized destination and request confirmation.
  9. Add automated negative tests for deceptive values such as public domain names beginning with 10., 172.16., or 192.168..
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill recommends piping a remotely fetched installer script directly into the shell, which executes untrusted code from the network without prior verification. If the remote server, transport, DNS, or distribution path is compromised, the agent or user could execute arbitrary attacker-controlled commands with the current user's privileges.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

Linux:

bash
curl -fsSL https://ollama.com/install.sh | sh
ollama serve

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The command chaining remote content into sh removes any inspection point and turns network-delivered text into immediate code execution. In the context of an agent skill that may be followed semi-automatically, this pattern is especially dangerous because it normalizes unsafe execution and can lead to full system compromise.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

Linux:

bash
curl -fsSL https://ollama.com/install.sh | sh
ollama serve

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · references/troubleshooting.md (reported line 47)May include surrounding context.

Linux:

bash
systemctl --user restart ollama 2>/dev/null || sudo systemctl restart ollama 2>/dev/null || ollama serve

If Ollama was installed as a desktop app, open it once and retry.

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The script downloads a remote installer from https://ollama.com/install.sh and immediately executes it via the shell. This creates a supply-chain and remote-code-execution risk: if the remote server, network path, DNS, TLS trust chain, or installer content is compromised, arbitrary code will run on the host with the user's privileges.

Content

Scanner excerpt · scripts/check-ollama-memory.sh (reported line 89)May include surrounding context.

sh
command -v brew >/dev/null 2>&1 || { fail "Homebrew missing. Install Ollama manually: https://ollama.com"; exit 1; }
    brew install ollama
  else
    command -v curl >/dev/null 2>&1 || { fail "curl missing. Install curl or Ollama manually."; exit 1; }
    curl -fsSL https://ollama.com/install.sh | sh
  fi
else

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh construct executes network-fetched content without inspection, validation, or integrity checking. In a setup/repair skill that may be run with --install, this is especially dangerous because the script is explicitly designed to modify the local system, so successful exploitation would likely result in immediate arbitrary command execution.

Content

Scanner excerpt · scripts/check-ollama-memory.sh (reported line 90)May include surrounding context.

sh
brew install ollama
  else
    command -v curl >/dev/null 2>&1 || { fail "curl missing. Install curl or Ollama manually."; exit 1; }
    curl -fsSL https://ollama.com/install.sh | sh
  fi
else
  fail "ollama missing. Re-run with --install or install from https://ollama.com"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to use shell, network, and configuration-changing operations, but it declares no explicit tool scope or permissions boundaries. In an agent environment, this increases the chance that high-impact actions such as package installation, service startup, remote fetches, and config writes occur without clear authorization or containment.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 47)May include surrounding context.

Linux:

bash
systemctl --user restart ollama 2>/dev/null || sudo systemctl restart ollama 2>/dev/null || ollama serve

If Ollama was installed as a desktop app, open it once and retry.

Static analysis

No suspicious patterns detected.