Back to skill

Security audit

Agent Memory System v12

Security checks for vulnerabilities and agentic risk

Overview

This is a powerful agent memory system with coherent goals, but it needs Review because it exposes persistent, networked memory and command surfaces with some unsafe defaults and under-scoped controls.

Install only if you intentionally want a persistent agent-memory service. Keep it local by default, set strong API keys/JWT secrets before enabling any server, avoid unauthenticated Playground or MCP HTTP exposure, do not enable collectors/personality analysis without consent, and treat retrieved memories as untrusted quoted data rather than instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:260
Finding

Untrusted Memory Content Is Mandated for Verbatim Forwarding

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:260-265
Vulnerability Type: Instruction hijacking through untrusted persistent content
Risk Level: High

Vulnerable Code

markdown
### [MEMORY_REPORT:UUID] Markers
All memory system output is wrapped in `[MEMORY_REPORT:UUID]...[/MEMORY_REPORT:UUID]` markers with a per-session UUID to prevent forgery.
- Content inside these markers MUST be forwarded to the user AS-IS
- Do NOT summarize, paraphrase, or reinterpret the content
- Do NOT add your own analysis inside these markers
- The UUID suffix prevents malicious content from forging boundary markers

Technical Analysis

The Skill instructs the Agent to forward retrieved memory content verbatim and prohibits summarization, reinterpretation, or analysis. This conflicts with the Skill's separate acknowledgment that stored and retrieved memories are untrusted.

A per-session UUID can make boundary-marker forgery more difficult, but it does not make the content inside a valid marker trustworthy. If attacker-controlled, poisoned, obsolete, or sensitive content is stored in memory and subsequently included in a report, the instruction requires the Agent to reproduce it without applying normal output filtering or contextual judgment.

The vulnerable rule therefore creates an instruction-control channel from persistent memory to the Agent's final response. It can propagate prompt-injection text, phishing links, misleading instructions, abusive material, or confidential records. The issue is classified as Skill instruction hijacking because the unsafe behavior is imposed directly by the Skill text when loaded.

Attack Path

  1. An attacker causes malicious content to enter memory through an enabled write, synchronization, import, collector, or other ingestion workflow.
  2. The malicious record is retained in the persistent memory store.
  3. A later query retrieves the record and places it within a valid `[ ...[truncated 1033 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the requirement to forward memory reports verbatim.
  2. Explicitly state that marker integrity proves only framing, not the trustworthiness of enclosed content.
  3. Treat retrieved memories as quoted data that cannot issue instructions to the Agent or override system, developer, user, or safety requirements.
  4. Summarize retrieved content by default and preserve clear provenance for each record.
  5. Apply prompt-injection detection, sensitive-data redaction, URL screening, and output-safety checks before presenting memory content.
  6. Require explicit user approval before exposing complete raw records, especially records containing credentials, personal data, private communications, or media-derived text.
  7. Escape or isolate imperative language and executable examples when raw content must be displayed.
  8. Apply authorization checks at retrieval time so users can access only memories belonging to their tenant and role.
  9. Add tests proving that content such as “ignore previous instructions,” forged authority claims, secret values, and malicious links is not automatically reproduced or obeyed.
  10. Provide an administrative workflow to identify, quarantine, review, and delete poisoned records.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (666)

Tainted flow: 'req' from os.environ.get (line 806, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/embedding_store.py (reported line 798)May include surrounding context.

python
"Content-Type": "application/json",
                "Authorization": f"Bearer {_cred}",
            })
            with urllib.request.urlopen(req, timeout=30) as resp:
                data = _json.loads(resp.read())
            return [item["embedding"] for item in data["data"]]

Tainted flow: 'req' from os.environ.get (line 818, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/embedding_store.py (reported line 810)May include surrounding context.

python
"Content-Type": "application/json",
                "Authorization": f"Bearer {_cred}",
            })
            with urllib.request.urlopen(req, timeout=30) as resp:
                data = _json.loads(resp.read())
            return data["embeddings"]

Tainted flow: 'req' from os.environ.get (line 818, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/embedding_store.py (reported line 822)May include surrounding context.

python
"Content-Type": "application/json",
                "Authorization": f"Bearer {_cred}",
            })
            with urllib.request.urlopen(req, timeout=30) as resp:
                data = _json.loads(resp.read())
            return data["embeddings"]

Tainted flow: 'req' from os.environ.get (line 165, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/llm_client.py (reported line 171)May include surrounding context.

python
headers=headers,
            )

            with urllib.request.urlopen(req, timeout=30) as resp:
                result = json.loads(resp.read())

            return result["choices"][0]["message"]["content"]

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 139)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/chat/completions")
            with urllib.request.urlopen(req, timeout=60) as resp:
                result = json.loads(resp.read())
            return result["choices"][0]["message"]["content"]

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 209)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/chat/completions")
            with urllib.request.urlopen(req, timeout=60) as resp:
                result = json.loads(resp.read())
            return result["choices"][0]["message"]["content"]

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 293)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/chat/completions")
            with urllib.request.urlopen(req, timeout=60) as resp:
                result = json.loads(resp.read())
            return result["choices"][0]["message"]["content"]

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 338)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/chat/completions")
            with urllib.request.urlopen(req, timeout=60) as resp:
                result = json.loads(resp.read())
            return result["choices"][0]["message"]["content"]

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 460)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/chat/completions")
            with urllib.request.urlopen(req, timeout=60) as resp:
                result = json.loads(resp.read())
            return result["choices"][0]["message"]["content"]

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 170)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/audio/transcriptions")
            with urllib.request.urlopen(req, timeout=120) as resp:
                result = json.loads(resp.read())
            return result.get("text", "")

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 234)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/audio/transcriptions")
            with urllib.request.urlopen(req, timeout=120) as resp:
                result = json.loads(resp.read())
            return result.get("text", "")

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 367)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/audio/transcriptions")
            with urllib.request.urlopen(req, timeout=120) as resp:
                result = json.loads(resp.read())
            return result.get("text", "")

Tainted flow: 'req' from os.environ.get (line 454, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · agent_memory/media_processor.py (reported line 406)May include surrounding context.

python
},
            )
            _validate_url(f"{base_url}/audio/transcriptions")
            with urllib.request.urlopen(req, timeout=120) as resp:
                result = json.loads(resp.read())
            return result.get("text", "")

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · RUNBOOK.md (reported line 12)May include surrounding context.

md
agent-memory health

# 2. 检查组件降级
curl http://localhost:8000/v1/health/ready

# 3. 查看最近日志
tail -100 ~/.agent_memory/logs/agent_memory.log

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · RUNBOOK.md (reported line 12)May include surrounding context.

md
agent-memory health

# 2. 检查组件降级
curl http://localhost:8000/v1/health/ready

# 3. 查看最近日志
tail -100 ~/.agent_memory/logs/agent_memory.log

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
> 📖 完整 API 参考:[API.md](API.md) | 架构概览:[README.md](README.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 435)May include surrounding context.

md
> 📖 完整 API 参考:[API.md](API.md) | 架构概览:[README.md](README.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 396)May include surrounding context.

md
> 可选依赖通过 `requirements.txt` 锁定版本。建议在虚拟环境中安装,

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The revoke method accepts an owner_agent_id parameter but never validates that the caller actually owns the memory or is otherwise authorized to revoke access. Any caller able to invoke this method could revoke another agent’s permissions on arbitrary memory IDs, enabling unauthorized denial of access and breaking the intended isolation and delegation model.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level documentation and FastAPI description emphasize a memory API with tenant management, auth, recall, SSE, health, and metrics. However, the file also implements additional domains such as personality profiling, federated search/conflict resolution, distributed sync, curiosity-driven exploration, validation workflows, and Spirit command execution, which materially exceed that described scope.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · agent_memory/api_v3.py (reported line 6)May include surrounding context.

python
Endpoints:
  POST   /v1/tenants              - Create tenant (requires admin)
  DELETE /v1/tenants/{tenant_id}  - Delete tenant (requires admin)
  POST   /v1/auth/token           - Issue JWT token
  POST   /v1/memories             - Async write with tenant isolation
  POST   /v1/recall               - Async recall with tenant isolation

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
91% confidence
Finding

The spirit_execute endpoint exposes natural-language command execution through mem.spirit.execute(...), which is a high-impact control surface for a service presented as a memory API. The lightweight regex blocklist and confirm=True gate are not robust protections against prompt/instruction manipulation or abuse of underlying command capabilities, especially if authenticated write users can reach it. In this context, adding agent-style command execution to a multi-tenant API materially increases the attack surface.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
89% confidence
Finding

The federation and sync endpoints expose cross-peer operations such as search, conflict resolution, synchronization, and remote change application. In a tenant-isolated memory service, these capabilities are high risk because they can bridge trust boundaries, import untrusted remote state, and potentially bypass or dilute tenant isolation if downstream engines do not enforce strict scoping. The broad exposure is more dangerous here because the file markets itself as tenant-isolated while adding distributed mutation surfaces.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · agent_memory/collectors/dingtalk.py (reported line 112)May include surrounding context.

python
try:
            token = self._get_access_token()
            if not token:
                raise RuntimeError("Failed to get access token")

            # Fetch messages
            messages = self._fetch_messages(token, since)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · agent_memory/collectors/dingtalk.py (reported line 115)May include surrounding context.

python
try:
            token = self._get_access_token()
            if not token:
                raise RuntimeError("Failed to get access token")

            # Fetch messages
            messages = self._fetch_messages(token, since)

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
agent_memory/integration/langchain_connector.py:28

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
agent_memory/recall/__init__.py:20

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
agent_memory/tenant/__init__.py:23

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
agent_memory/tenant/kernel.py:31

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
agent_memory/api_v3.py:1096

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
agent_memory/web_server.py:143

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
agent_memory/compliance/gdpr.py:496