T02 · Agent Memory Poisoning
- Location
scripts/memory_store.py:96- Finding
Unauthenticated Persistent Agent Memory Poisoning
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real persistent memory store, but it exposes private memory data through an unauthenticated network service and can send memory text to OpenAI without clear user-facing disclosure.
Review before installing or running this skill. Only run it on a trusted, isolated host unless authentication, loopback binding, owner-level authorization, deletion controls, request limits, and clear opt-in for OpenAI embeddings are added. Do not store secrets or sensitive user data in it as currently implemented.
scripts/memory_store.py:96Unauthenticated Persistent Agent Memory Poisoning
scripts/memory_store.py:80Unauthenticated Disclosure and Deletion of Private Memories
scripts/memory_store.py:35Undisclosed External Transmission of Memory Content and Search Queries
scripts/memory_store.py:81Unbounded Request Processing and Dataset-Wide Search Enable Denial of Service
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
req = urllib.request.Request(
"https://api.openai.com/v1/embeddings", data=payload,
headers={"Authorization": f"Bearer {OPENAI_KEY}", "Content-Type": "application/json"})
with urllib.request.urlopen(req, timeout=8) as r:
vec = json.loads(r.read())["data"][0]["embedding"]
return struct.pack(f"{len(vec)}f", *vec)
except: return None
The documented purpose understates materially sensitive behavior: an unauthenticated HTTP server, optional outbound calls to the OpenAI embeddings API, destructive delete functionality, and health/status disclosure. This mismatch can mislead users into deploying the skill without understanding its exposure, data flow, and attack surface, especially given that it persists cross-agent memory to disk.
The skill exposes network and environment-related capabilities but does not declare any tool scope or permissions boundary. That omission weakens reviewability and containment, making it easier for a skill to access networking or secrets in ways a user or platform operator did not explicitly approve.
The skill stores agent memories on disk and examples include potentially sensitive preference data, but the description does not clearly warn users about persistence or privacy implications. In a shared cross-agent memory context, this increases the chance that sensitive user or agent data is retained longer than expected and accessed by unintended parties.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Store a memory
curl -X POST http://localhost:8768/memories \
-H "Content-Type: application/json" \
-d '{"owner":"my-agent","content":"user prefers SOL payments","ttl_seconds":86400,"public":false}'
The code introduces capabilities beyond a simple local memory store by reading an API key and making outbound network requests to a third party. While not inherently malicious, this broader capability increases data-exposure risk because memory contents and queries may leave the local environment.
The skill advertises a shared memory store but also sends stored/query text to OpenAI for embeddings, which expands the data-handling scope beyond local persistence. In a memory system, this can expose potentially sensitive cross-agent data to an external service without clear boundary enforcement or explicit disclosure at the API level.
Memory content is transmitted to the OpenAI embeddings API without any user-facing warning or consent mechanism at the point of use. Because a memory store may contain sensitive agent data, this silent external transmission creates privacy and compliance risk even if the destination is legitimate.
The code performs external transmission to OpenAI's API, sending text derived from stored memories or queries off-host. In the context of an agent memory store, this is a meaningful privacy and data-boundary concern because the service processes potentially sensitive shared content.
try:
payload = json.dumps({"input": text[:2000], "model": "text-embedding-3-small"}).encode()
req = urllib.request.Request(
"https://api.openai.com/v1/embeddings", data=payload,
headers={"Authorization": f"Bearer {OPENAI_KEY}", "Content-Type": "application/json"})
with urllib.request.urlopen(req, timeout=8) as r:
vec = json.loads(r.read())["data"][0]["embedding"]
The delete endpoint irreversibly removes memories with no confirmation, soft-delete, or access control. Combined with the unauthenticated network service, this enables trivial destructive actions by any reachable party, causing loss of shared state and denial of service to dependent agents.
The server binds to 0.0.0.0 and exposes read/write/delete memory operations without any authentication or authorization checks. In a shared-memory context this is especially dangerous because any reachable client can enumerate, insert, or delete memories across agents, undermining confidentiality and integrity.
No suspicious patterns detected.