Back to skill

Security audit

Supermemory

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it advertises, but it embeds an apparent real API key and encourages sending sensitive content to an external memory service without enough safeguards.

Review before installing. Use only your own freshly generated SuperMemory API key, do not copy the credential shown in the skill, and do not store passwords, API keys, private keys, tokens, regulated data, or confidential content unless you explicitly intend to send it to SuperMemory. The publisher should rotate the exposed credential, replace it with a placeholder, add privacy and secret-handling warnings, and build JSON requests with a serializer.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:12
Finding

Hardcoded SuperMemory API Credential in Documentation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-15
Vulnerability Type: Hardcoded secret
Risk Level: High

Vulnerable Code

bash
export SUPERMEMORY_API_KEY="[REDACTED_EXPOSED_TOKEN]"

The source contains a complete token beginning with the sm_ prefix. Its value is redacted in this report to avoid further credential exposure.

Technical Analysis

An apparent SuperMemory API credential is embedded directly in distributable documentation. Users, source repository readers, package recipients, and automated indexing systems can retrieve the credential without authorization.

The scripts subsequently use SUPERMEMORY_API_KEY as a bearer token:

bash
-H "Authorization: Bearer $API_KEY"

Bearer tokens grant their holder the token's associated capabilities without requiring additional proof of identity. Consequently, exposure of this value may permit third parties to invoke SuperMemory API operations under the affected account.

Attack Path

  1. An attacker downloads, clones, or otherwise obtains the skill package.
  2. The attacker reads the exported token from SKILL.md.
  3. The attacker supplies it in an Authorization: Bearer HTTP header.
  4. The attacker invokes SuperMemory API endpoints.
  5. Subject to the token's actual permissions, the attacker accesses, searches, or contaminates stored memory data and consumes account quotas.

Impact Assessment

The attacker may obtain all privileges assigned to the exposed API token. The potential scope includes unauthorized API usage, quota consumption, insertion of attacker-controlled memories, and disclosure of stored information if the token permits retrieval. The exact account and data scope depends on server-side permissions assigned to the credential.

Remediation
View remediation

Remediation Suggestions

  1. Revoke the exposed credential immediately through the SuperMemory account or credential-management interface.

  2. Generate a replacement token and ensure it is not committed to source control or included in documentation.

  3. Replace the example with a nonfunctional placeholder:

    bash
    export SUPERMEMORY_API_KEY="your-api-key"
    
  4. Load credentials from secure runtime configuration, such as an approved secret manager or protected environment injection mechanism.

  5. Review repository history, package releases, logs, and mirrors because deleting the current value does not remove earlier copies.

  6. Audit the affected account for unexpected API requests, memory additions, searches, and quota usage.

  7. Add secret-scanning checks to pre-commit and continuous-integration workflows.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/add-memory.sh:30
Finding

JSON Injection Through Unescaped User Input

Content
View full analysis

Vulnerability Details

File Locations: scripts/add-memory.sh, lines 30-36; scripts/search.sh, lines 26-31; scripts/chat.sh, lines 27-32
Vulnerability Type: Improper construction of JSON from user-controlled input
Risk Level: Medium

Vulnerable Code

scripts/add-memory.sh, lines 30-36:

bash
DATA=$(cat <<EOF
{
    "content": "$CONTENT",
    "customId": "memory_$(date +%s)",
    "containerTags": ["$SANITIZED_DESC"]
}
EOF
)

scripts/search.sh, lines 26-31:

bash
DATA=$(cat <<EOF
{
    "q": "$QUERY",
    "limit": 10
}
EOF
)

scripts/chat.sh, lines 27-32:

bash
DATA=$(cat <<EOF
{
    "q": "$QUESTION",
    "limit": 5
}
EOF
)

Technical Analysis

The scripts interpolate $CONTENT, $QUERY, and $QUESTION directly into JSON string literals. They do not encode quotation marks, backslashes, control characters, or newlines according to JSON escaping rules.

Ordinary input containing characters such as " can therefore produce malformed JSON. A deliberately crafted value can terminate the intended string and introduce additional JSON properties or duplicate existing properties. The resulting interpretation depends on the remote service's JSON parser and duplicate-key handling.

This defect is JSON injection rather than shell-command injection: the variables are quoted when passed to curl, and the reviewed code does not evaluate their contents as shell commands. Exploitation is limited to corrupting or manipulating the outbound API request.

Attack Path

  1. An attacker or untrusted caller supplies a memory, query, or question containing JSON syntax, including a closing quotation mark.
  2. The script interpolates the value into the here-document without JSON encoding.
  3. The resulting request is either invalid JSON or contains attacker-influenced fields and duplicate keys.
  4. curl sends the constructed body ...[truncated 561 chars]
Remediation
View remediation

Remediation Suggestions

Construct every request with a JSON serializer rather than string interpolation. For example:

bash
DATA=$(jq -n \
    --arg content "$CONTENT" \
    --arg custom_id "memory_$(date +%s)" \
    --arg tag "$SANITIZED_DESC" \
    '{content: $content, customId: $custom_id, containerTags: [$tag]}')

For searches and chat requests:

bash
DATA=$(jq -n --arg query "$QUERY" '{q: $query, limit: 10}')
bash
DATA=$(jq -n --arg question "$QUESTION" '{q: $question, limit: 5}')

Additional hardening should include:

  1. Declare jq as a required dependency and fail safely if it is unavailable.
  2. Validate any documented input-length and content limits before making a request.
  3. Use curl --fail-with-body --show-error --silent and verify HTTP status codes.
  4. Parse API responses as JSON instead of detecting errors through substring matching.
  5. Add tests covering quotes, backslashes, Unicode, multiline input, control characters, and attempted property injection.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:71
Finding

Documentation Encourages Storage of Reusable Credentials in an External Memory Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 71-73
Vulnerability Type: Unsafe handling of sensitive information
Risk Level: Medium

Vulnerable Code

text
**Store important information:**
- "Remember that my API key is xyz" → `supermemory add "My API key is xyz" --description "API credentials"`
- "Save this link for later" → `supermemory add "https://example.com" --description "Bookmarked link"`

Technical Analysis

The documentation explicitly recommends storing an API key as memory content. The add-memory.sh implementation transmits that content to https://api.supermemory.ai/v3/documents, where it may be retained outside the local system.

Although external memory storage is the declared purpose of the skill, reusable credentials require stronger handling than ordinary notes. Storing them in a general-purpose memory service expands the credential's exposure to the memory provider, the SuperMemory account, its bearer tokens, service logs, backups, and any users or integrations capable of searching the memory store.

Attack Path

  1. A user follows the documented example and passes a real API key to the add-memory command.
  2. add-memory.sh includes the key in the JSON content field.
  3. The script sends the content to the external SuperMemory API.
  4. The credential is retained as searchable memory data.
  5. An attacker who later compromises the SuperMemory account, an authorized token, or another permitted integration searches for credential-related memories.
  6. The attacker retrieves and reuses the stored credential against its original service.

Impact Assessment

The eventual privileges are those granted by the stored credential, potentially extending beyond SuperMemory itself. Depending on the credential supplied by the user, compromise could expose third-party accounts, data, infrastructure, or billing resources. The affected scope is not bounded by this skill beca ...[truncated 67 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the example that recommends storing an API key.
  2. Add a prominent warning that passwords, API keys, private keys, session tokens, recovery codes, and other reusable credentials must not be stored as memories.
  3. Direct users to an approved password manager or secret-management platform for credential storage.
  4. Add client-side detection for common secret formats and require explicit confirmation or reject likely credentials before transmission.
  5. Document the external destination, retention behavior, deletion process, and access controls before users submit sensitive information.
  6. Apply data minimization and redact secrets from command output, diagnostics, and logs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code chunk is narrowly focused on one function: adding a memory to SuperMemory using an API key and a POST request to /v3/documents. This is consistent with the 'store memories' portion of the description, but the broader declared description claims the skill can also retrieve/search memories and chat with the knowledge base. Those capabilities are not represented in the supplied code. There are no obvious unrelated or dangerous extra capabilities beyond the declared purpose, but the description overstates what this code chunk actually does, so this is a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The setup instructions embed what appears to be a real SuperMemory API key rather than a placeholder. Exposed API credentials can be abused by anyone who reads the skill to access the associated account, store or retrieve data, incur charges, or pivot into other connected resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples explicitly encourage storing an API key in the remote memory system without any warning or redaction guidance. In the context of a memory-syncing external service, this normalizes exfiltration of credentials and could directly lead to account compromise if users follow the example.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes shell scripts directly but does not declare any explicit tool scope or allowed-tools boundary. This weakens reviewability and containment, because consumers cannot easily tell that shell execution is required and an agent platform may grant broader execution capability than expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill promotes storing user content in SuperMemory but does not clearly warn that submitted data is sent to an external third-party API. This can mislead users into sharing sensitive internal or personal data under the assumption it remains local, creating confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script transmits arbitrary user-supplied content to a third-party API but provides no explicit runtime warning, confirmation, or data handling notice before exfiltrating that content. In a memory/storage skill this behavior is expected functionally, but it is still security-relevant because users may unknowingly send sensitive data off-host to an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This curl invocation sends the provided content and metadata to an external service using an API key, creating a clear data exfiltration path from the local environment to a third party. In the context of a 'store memory' skill, external transmission is expected, but it remains dangerous if the tool can be invoked on sensitive input without clear consent and data classification controls.

Content

Scanner excerpt · scripts/add-memory.sh (reported line 40)May include surrounding context.

sh
)

# Make the API request
RESPONSE=$(curl -s -X POST "$API_URL" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "$DATA")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends the user's question verbatim to a third-party service, but it does not provide a clear user-facing disclosure at the point of use that prompts may contain sensitive data and will leave the local environment. This creates a privacy and data-handling risk because users may unknowingly transmit secrets, personal information, or internal context to an external API.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This curl request transmits user-supplied content and an authorization token to an external network endpoint. In the context of a memory/chat skill this is expected functionality, but it is still a real security concern because sensitive prompts may be exfiltrated to a remote service and the script does not implement additional safeguards such as warning, minimization, or validation of what is sent.

Content

Scanner excerpt · scripts/chat.sh (reported line 36)May include surrounding context.

sh
)

# Make the API request
RESPONSE=$(curl -s -X POST "$API_URL" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "$DATA")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/add-memory.sh (reported line 27)May include surrounding context.

sh
fi

# SuperMemory API search endpoint
API_URL="https://api.supermemory.ai/v3/search"

# Prepare the request
DATA=$(cat <<EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/chat.sh (reported line 24)May include surrounding context.

sh
fi

# SuperMemory API search endpoint
API_URL="https://api.supermemory.ai/v3/search"

# Prepare the request
DATA=$(cat <<EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search.sh (reported line 23)May include surrounding context.

sh
fi

# SuperMemory API search endpoint
API_URL="https://api.supermemory.ai/v3/search"

# Prepare the request
DATA=$(cat <<EOF

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search.sh (reported line 35)May include surrounding context.

sh
)

# Make the API request
RESPONSE=$(curl -s -X POST "$API_URL" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "$DATA")

Static analysis

No suspicious patterns detected.