T09 · Insecure Skill Coding Practices
- Location
src/memory.py:100- Finding
Plaintext Persistent Memory Uses Process-Default Filesystem Permissions
- Content
View full analysis
Vulnerability Details
File Location:
src/memory.py:100-106
Vulnerability Type: Plaintext sensitive-data storage with insufficient permission hardening
Risk Level: Mediumpython if db_path is None: db_dir = Path.home() / ".agent-memory" db_dir.mkdir(exist_ok=True) db_path = str(db_dir / "memory.db") self.db_path = db_path self._init_db()Technical Analysis
AgentMemory persistently stores conversation facts, learned insights, personal entities, preferences, and arbitrary entity attributes in a plaintext SQLite database. The default storage directory is created without an explicit restrictive mode, and the database file is subsequently created by SQLite using permissions derived from the process environment and umask.
The implementation does not enforce a
0700directory mode or a0600database-file mode. It also accepts a caller-supplied database path without checking whether its parent directory or existing database is accessible by unintended users. Consequently, confidentiality depends entirely on external filesystem configuration.No encryption, sensitive-data filtering, or permission validation is applied. This does not grant remote access by itself; exploitation requires local filesystem access or an insecure custom storage location.
Attack Path
- An Agent uses the default database or supplies a path in a directory with permissive access controls.
- The Skill records sensitive conversation facts, lessons, identities, preferences, and attributes as plaintext SQLite values.
- The directory and database inherit process-default permissions because the Skill does not enforce restrictive modes.
- Another local account or process with filesystem access opens or copies the SQLite database.
- The attacker reads the stored facts, lessons, and entity records directly, without using the AgentMemory API.
Impact Assessment
A successful attacker can disclose all ...[truncated 579 chars]
- Remediation
View remediation
Remediation Suggestions
- Create the default directory with mode
0700and verify its final permissions:python db_dir.mkdir(mode=0o700, parents=True, exist_ok=True) db_dir.chmod(0o700) - After database creation, enforce mode
0600on the database file:python Path(db_path).chmod(0o600) - Account for SQLite sidecar files such as
-wal,-shm, and journal files by ensuring the containing directory is private. - For custom database paths, reject insecure parent directories or emit a clear security warning after checking ownership and permission bits.
- Refuse symbolic-link database paths where local link attacks are within the threat model, or securely validate the resolved destination.
- Document that stored memories are plaintext and may contain sensitive personal or operational data.
- Provide optional encryption at rest for deployments where local users or processes are not mutually trusted.
- Add configurable redaction or secret-detection controls to prevent credentials, tokens, and private keys from being persisted.
- Add tests confirming restrictive permissions for both the default database and its parent directory.
- Create the default directory with mode
