Back to skill

Security audit

Agent Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local persistent memory library for agents, and its main risks are expected for that purpose but should be handled carefully.

Install only if you want an agent to keep local cross-session memory. Do not store secrets, credentials, regulated data, or sensitive personal information unless you have reviewed the storage path and local filesystem protections. Treat JSON exports and the SQLite database as private data, and use the forget/cleanup commands carefully because deletion is permanent.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/memory.py:100
Finding

Plaintext Persistent Memory Uses Process-Default Filesystem Permissions

Content
View full analysis

Vulnerability Details

File Location: src/memory.py:100-106
Vulnerability Type: Plaintext sensitive-data storage with insufficient permission hardening
Risk Level: Medium

python
if db_path is None:
    db_dir = Path.home() / ".agent-memory"
    db_dir.mkdir(exist_ok=True)
    db_path = str(db_dir / "memory.db")

self.db_path = db_path
self._init_db()

Technical Analysis

AgentMemory persistently stores conversation facts, learned insights, personal entities, preferences, and arbitrary entity attributes in a plaintext SQLite database. The default storage directory is created without an explicit restrictive mode, and the database file is subsequently created by SQLite using permissions derived from the process environment and umask.

The implementation does not enforce a 0700 directory mode or a 0600 database-file mode. It also accepts a caller-supplied database path without checking whether its parent directory or existing database is accessible by unintended users. Consequently, confidentiality depends entirely on external filesystem configuration.

No encryption, sensitive-data filtering, or permission validation is applied. This does not grant remote access by itself; exploitation requires local filesystem access or an insecure custom storage location.

Attack Path

  1. An Agent uses the default database or supplies a path in a directory with permissive access controls.
  2. The Skill records sensitive conversation facts, lessons, identities, preferences, and attributes as plaintext SQLite values.
  3. The directory and database inherit process-default permissions because the Skill does not enforce restrictive modes.
  4. Another local account or process with filesystem access opens or copies the SQLite database.
  5. The attacker reads the stored facts, lessons, and entity records directly, without using the AgentMemory API.

Impact Assessment

A successful attacker can disclose all ...[truncated 579 chars]

Remediation
View remediation

Remediation Suggestions

  • Create the default directory with mode 0700 and verify its final permissions:
    python
    db_dir.mkdir(mode=0o700, parents=True, exist_ok=True)
    db_dir.chmod(0o700)
    
  • After database creation, enforce mode 0600 on the database file:
    python
    Path(db_path).chmod(0o600)
    
  • Account for SQLite sidecar files such as -wal, -shm, and journal files by ensuring the containing directory is private.
  • For custom database paths, reject insecure parent directories or emit a clear security warning after checking ownership and permission bits.
  • Refuse symbolic-link database paths where local link attacks are within the threat model, or securely validate the resolved destination.
  • Document that stored memories are plaintext and may contain sensitive personal or operational data.
  • Provide optional encryption at rest for deployments where local users or processes are not mutually trusted.
  • Add configurable redaction or secret-detection controls to prevent credentials, tokens, and private keys from being persisted.
  • Add tests confirming restrictive permissions for both the default database and its parent directory.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly encourages storing persistent facts, lessons, entities, and personal preferences across sessions, including examples about a boss's communication style and named individuals, but it does not warn users that this creates a local retention store containing potentially sensitive personal data. In an agent-memory skill, this omission is security-relevant because operators may unknowingly accumulate sensitive or regulated data that can later be queried, leaked, or mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises an export_json() capability for exporting all stored memory data without cautioning that the export may include sensitive conversation history, preferences, entity attributes, or other personal information. In this skill's context, bulk export amplifies the risk of accidental disclosure because it centralizes all retained memory into a portable artifact that may be copied, logged, or shared insecurely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly promotes persistent storage of facts, lessons, and entity data across sessions, but it does not disclose privacy, consent, retention, or sensitivity risks. In practice, users may store conversation-derived personal, confidential, or regulated data into a local database without understanding that it will persist beyond the current session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The session-end workflow tells the agent to extract durable facts from conversations and store them persistently, but it omits any warning that user conversation content may be retained. This creates a meaningful privacy risk because operators may inadvertently persist sensitive user inputs, internal business data, or personal information without notice or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The forget subcommand performs a bulk-destructive operation immediately based on a user-supplied age threshold, with no confirmation prompt, dry-run mode, or preview of affected records. In a CLI handling persistent agent memory, an accidental invocation, typo, or automation mistake could irreversibly delete large amounts of data and impair system behavior or auditability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module silently creates a persistent SQLite database under the user's home directory and stores conversational facts, lessons, and entity data without any notice, consent flow, or visibility mechanism. In an agent context, this can lead to unexpected retention of sensitive personal or operational information on disk, increasing privacy and compliance risk if users do not realize memory is persistent across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The memory API exposes permanent deletion paths such as deleting facts and stale-memory cleanup without any confirmation, soft-delete, undo, or safety interlock. In an agent environment, an unintended call, prompt injection chain, or logic bug could irreversibly erase accumulated memory and degrade system behavior or destroy user data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.