Back to skill

Security audit

memory-m3e - Semantic Memory Plugin

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is purpose-aligned, but it can send private memory text and API credentials over unsecured HTTP and can delete the top semantic match without confirmation.

Review before installing. Use only an HTTPS or trusted localhost embedding endpoint, assume stored memories and search/delete queries are sent to that service, avoid storing secrets or regulated data, disable or scope autoCapture/autoRecall unless you understand their triggers, and prefer deleting by exact memory ID rather than vague queries.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
index.ts:20
Finding

Embedding API credentials and memory contents may be transmitted over plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: index.ts:20-24 and index.ts:32-47
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: High

Vulnerable Code

typescript
const DEFAULT_CONFIG = {
  embedding: {
    apiKey: '',
    baseUrl: 'http://your-api-server:3000/v1',
    model: 'm3e-large'
  },
  dbPath: '~/.openclaw/data/memory-m3e.db',
  autoCapture: false,
  autoRecall: false,
  indexInterval: 600000
};
typescript
async function getEmbedding(text, config) {
  const response = await fetch(`${config.embedding.baseUrl}/embeddings`, {
    method: 'POST',
    headers: {
      'Authorization': `Bearer ${config.embedding.apiKey}`,
      'Content-Type': 'application/json'
    },
    body: JSON.stringify({
      model: config.embedding.model,
      input: [text]  // array format
    })
  });

  if (!response.ok) {
    const errText = await response.text();
    throw new Error(`Embedding API error: ${response.status} ${errText}`);
  }

  const data = await response.json();
  return data.data[0].embedding;
}

The insecure HTTP configuration is also promoted in SKILL.md:24:

json
"baseUrl": "http://your-embedding-server"

Technical Analysis

The plugin sends an API credential in the Authorization header and user-controlled memory or query text in the request body. The default configuration and documented setup permit and promote an http:// embedding endpoint, while the implementation performs no protocol validation.

HTTP does not provide transport encryption, endpoint authentication, or message integrity. An attacker with a network position between the OpenClaw host and the embedding service can inspect the bearer token and text, modify requests or responses, or impersonate the embedding service.

The affected flows include:

  • memory_store, which sends the complete text being persisted.
  • `memory_r ...[truncated 1550 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require https:// embedding endpoints during plugin registration and reject insecure schemes before any tool is exposed.
  2. If local development requires plaintext HTTP, permit it only through an explicit opt-in setting and restrict it to loopback addresses such as 127.0.0.1, ::1, or localhost.
  3. Replace all documented HTTP examples with HTTPS endpoints and clearly state that memory contents are sent to the configured external service.
  4. Use standard TLS certificate verification. If private certificate authorities are required, configure a trusted CA rather than disabling certificate checks.
  5. Scope API keys to the minimum required service permissions, rotate any credential previously transmitted over HTTP, and impose usage limits where supported.
  6. Consider applying request timeouts and response-size limits to reduce exposure to a malicious or compromised endpoint.
  7. Avoid propagating complete remote response bodies in errors because they may contain sensitive service data that could subsequently enter logs.

Example validation:

typescript
function validateEmbeddingUrl(baseUrl) {
  const url = new URL(baseUrl);

  if (url.protocol !== 'https:') {
    const isLoopback =
      url.hostname === 'localhost' ||
      url.hostname === '127.0.0.1' ||
      url.hostname === '::1';

    if (!isLoopback) {
      throw new Error('The embedding baseUrl must use HTTPS.');
    }
  }

  return url.toString().replace(/\/$/, '');
}
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The forget tool can delete a memory automatically based on the single top semantic match for a query, with no confirmation step and no threshold to ensure the match is correct. This creates a high risk of unintended data loss, because vague or adversarial queries can delete the wrong memory and the action is immediately destructive.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly advertises automatic conversation capture and use of an external embedding API, but provides no privacy warning, consent guidance, or explanation that conversation content may be transmitted off-host and stored persistently. In a memory plugin context, this can cause users to unknowingly send sensitive prompts, secrets, or personal data to a third-party service and retain them locally, increasing confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

1. 安装

bash
mkdir -p ~/.openclaw/extensions/memory-m3e
cd ~/.openclaw/extensions/memory-m3e
npm install

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

1. 安装

bash
mkdir -p ~/.openclaw/extensions/memory-m3e
cd ~/.openclaw/extensions/memory-m3e
npm install

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly sends user text to an external embedding API and supports deletion of stored memories, but the documentation does not warn that sensitive content may leave the local environment or that delete operations can cause irreversible data loss. In a memory plugin, users are especially likely to store personal, confidential, or operationally sensitive information, so omission of privacy and deletion warnings materially increases the risk of unsafe use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The tool sends user-provided memory text to an external embedding API during storage, which can expose sensitive long-term memory contents to a third-party service without explicit user notice or consent. In a memory plugin, stored content is especially likely to contain personal, proprietary, or credential-like data, making silent exfiltration materially risky even if done for legitimate functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The recall path sends search queries to the external embedding API, which can leak sensitive user intent, internal project names, or secret fragments embedded in queries. Because this is a memory-search feature, users may naturally search for private information and may not realize those queries are being transmitted externally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest exposes autoCapture and autoRecall as configurable behaviors, but provides no natural-language description of when they activate, what content they apply to, or any exclusion conditions. In a manifest file, that lack of trigger specificity can lead to overly broad or unintended invocation of memory behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language instructions and usage documentation are presented exclusively in Chinese, and there is no indication that the user can choose another language or that the locale limitation is intentional and justified. This can violate language/locale policy requirements when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
61% confidence
Finding

The description specifies use of the m3e-large embedding API as a fixed choice, but this is a model-selection detail rather than a language or locale policy issue. Because SQP-3 is limited to natural-language language/locale policy violations, this is at most a weak concern and may reflect an inflexible default rather than a true policy breach.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"type": "module",
  "description": "Semantic memory plugin using m3e-large embedding API + SQLite",
  "dependencies": {
    "@sinclair/typebox": "^0.34.48",
    "better-sqlite3": "^11.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"description": "Semantic memory plugin using m3e-large embedding API + SQLite",
  "dependencies": {
    "@sinclair/typebox": "^0.34.48",
    "better-sqlite3": "^11.0.0"
  }
}

Static analysis

No suspicious patterns detected.