Back to skill

Security audit

agentmemory-mcp

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent memory purpose, but it combines persistent background execution, Docker-level access, automatic conversation capture, and privileged memory injection without enough scoping or safeguards.

Review carefully before installing. Use pinned package and image versions, avoid granting Docker socket access unless you fully trust the service, keep the server bound to localhost, do not import unreviewed MEMORY.md content, disable or restrict automatic capture if possible, and treat recalled memories as untrusted reference material rather than instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
references/openclaw-plugin/plugin.mjs:21
Finding

Persistent memory is injected into agent sessions with system-level authority

Content
View full analysis
0) { return { injected: response.data.memories.map(m => ({ role: 'system', content: `[agentmemory] Relevant memory: ${m.content}` })), source: 'agentmemory' }; } } catch (err) { ``` ### Technical Analysis The plugin retrieves persistent memory from the agentmemory server and assigns every returned item the `system` role. Memory content is not validated, sanitized, escaped, or separated from executable instructions. A system message generally has greater authority than user-provided content. Consequently, any actor capable of writing, importing, or modifying a memory can persist instructions that alter future agent behavior. Prefixing the content with `[agentmemory] Relevant memory:` does not create a security boundary. The plugin configuration declares a `token_budget`, but this value is not applied when constructing the injected messages. The server can therefore return content beyond the intended budget. This behavior is especially dangerous because the project exposes several write paths, including memory-saving tools, automatic post-session capture, and bulk import. The issue therefore supports persistent memory poisoning as well as instruction hijacking. ### Attack Path 1. An attacker causes crafted content to be stored through `memory_save`, bulk import, automatic capture, or direct access to the memory API. 2. The content inclu ...[truncated 914 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/openclaw-plugin/plugin.mjs:10
Finding

Automatic conversation capture can transmit sensitive content to an arbitrary configured endpoint

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
SKILL.md:92
Finding

Installation guidance enables login-independent persistent execution

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:48
Finding

Unpinned packages and a mutable Docker image are executed with access to the Docker control plane

Content
View full analysis
**Important**: `AGENTMEMORY_III_VERSION=latest` overrides the npm CLI's hardcoded `IIPINNED_VERSION=0.11.2`, ensuring the latest stable iii-engine (v0.11.6) is used instead of the older pinned version. ### Docker socket The service uses the system Docker socket at `/var/run/docker.sock` (owned by `root:docker`). Do NOT set `DOCKER_HOST` — the default socket path is correct. ``` ### Technical Analysis Both npm commands omit exact package versions and integrity verification. The MCP configuration additionally uses `npx -y`, allowing package acquisition and execution without an interactive confirmation. The documentation deliberately recommends overriding a pinned engine version with the mutable `latest` Docker tag. A mutable tag can resolve to different code after review, so the effective payload is not stable or reproducible. Access to `/var/run/docker.sock` is highly privileged. A process controlling the Docker daemon can commonly start privileged containers, mount host directories, modify files on the host, or execute commands with host-level effects. This exceeds the minimum privileges needed for a memory API if the service can instead use an isolated storage backend or a narrowly scoped container interface. ### Attack Path 1. An attacker compromises ...[truncated 936 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:215
Finding

Bulk memory migration expands access to potentially sensitive long-term context

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (36)

Docker Socket Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The skill normalizes use of /var/run/docker.sock, which effectively grants root-equivalent control over the host to processes that can access the Docker socket. If the memory service, its dependencies, or a connected agent are compromised, an attacker can start privileged containers, mount the host filesystem, and fully escape into the machine.

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
### Docker socket

The service uses the system Docker socket at `/var/run/docker.sock` (owned by `root:docker`). Do NOT set `DOCKER_HOST` — the default socket path is correct.

---

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill documents enabling third-party embedding providers for vector search but does not disclose that memory contents or derived text chunks may be sent to external services for embedding. This can silently exfiltrate sensitive project memory to vendors, which is especially risky for persistent cross-session data.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

Manual health check

bash
curl http://127.0.0.1:3111/agentmemory/health | python3 -m json.tool

Healthy response shows: {"status":"healthy","uptimeSeconds":...,"workers":[...]}

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 573)May include surrounding context.

Manual health check

bash
curl http://127.0.0.1:3111/agentmemory/health | python3 -m json.tool

Healthy response shows: {"status":"healthy","uptimeSeconds":...,"workers":[...]}

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

bash
systemctl --user stop agentmemory
systemctl --user disable agentmemory
rm ~/.config/systemd/user/agentmemory.service
pkill -f "agentmemory"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 592)May include surrounding context.

bash
systemctl --user stop agentmemory
systemctl --user disable agentmemory
rm ~/.config/systemd/user/agentmemory.service
pkill -f "agentmemory"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.

If api::graph-stats and other v0.11.6 functions are not registered:

bash
# Check current iii-engine version
curl -s http://127.0.0.1:3111/agentmemory/health | python3 -c "
import json,sys; d=json.load(sys.stdin)
for w in d['health']['workers']:
    print(w['name'], '→', w['version'])

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 622)May include surrounding context.

If api::graph-stats and other v0.11.6 functions are not registered:

bash
# Check current iii-engine version
curl -s http://127.0.0.1:3111/agentmemory/health | python3 -c "
import json,sys; d=json.load(sys.stdin)
for w in d['health']['workers']:
    print(w['name'], '→', w['version'])

Docker Socket Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

This duplicated Chinese section repeats the instruction to use the host Docker socket, carrying the same root-equivalent privilege escalation risk. In the context of a persistent memory service integrated with an agent framework, compromise could give durable host takeover.

Content

Scanner excerpt · SKILL.md (reported line 495)May include surrounding context.

md
> **重要**:`AGENTMEMORY_III_VERSION=latest` 用于绕过 npm CLI 硬编码的 `IIPINNED_VERSION=0.11.2`,确保使用最新的稳定版 iii-engine(v0.11.6)。

**Docker socket**:服务使用系统 Docker socket `/var/run/docker.sock`(属于 `root:docker` 组)。不要设置 `DOCKER_HOST` 环境变量,默认 socket 路径已正确。

---

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill contains numerous shell commands that install software, modify user configuration, enable services, and remove files, but it does not declare any tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and makes it easier for an agent to execute impactful local actions without an explicit safety boundary.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

Using npx @agentmemory/agentmemory without a pinned version causes execution of whatever package version is current at runtime. This creates a supply-chain risk where a compromised upstream release or dependency change can alter behavior or execute malicious code on the host.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

Copying a service file into ~/.config/systemd/user is part of establishing persistent background execution. In this skill's context it is functional rather than deceptive, but it still expands the system's persistence surface and deserves explicit disclosure and consent.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

Install service

bash
mkdir -p ~/.config/systemd/user
cp ./scripts/agentmemory.service ~/.config/systemd/user/
systemctl --user daemon-reload
systemctl --user enable agentmemory

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

Enabling a user systemd service creates persistence across sessions and, with linger, across reboots without login. While that is expected for a background service, persistence is a security-relevant capability that can make unwanted or compromised software remain active long-term.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
mkdir -p ~/.config/systemd/user
cp ./scripts/agentmemory.service ~/.config/systemd/user/
systemctl --user daemon-reload
systemctl --user enable agentmemory
systemctl --user start agentmemory

# Enable linger (boot without login)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill tells users to migrate MEMORY.md into agentmemory and view it in a dashboard, but it never warns that this may copy sensitive project notes, credentials, internal decisions, or personal data into a persistent searchable store. Cross-session retention and dashboard exposure increase the blast radius of accidental data ingestion.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The repeated unpinned npx @agentmemory/agentmemory invocation again allows retrieval and execution of the latest package version at runtime. In an agent-installation skill, this materially increases supply-chain exposure because users are instructed to run the command directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This occurrence also invokes the package through npx without version pinning, allowing runtime drift from the reviewed version in the document. That can lead to unexpected code execution or behavior changes across sessions and hosts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicated service installation sequence in Chinese again creates a persistent user service. The danger is contextual rather than overtly malicious, but persistence should be treated as a security-sensitive action.

Content

Scanner excerpt · SKILL.md (reported line 474)May include surrounding context.

安装服务:

bash
mkdir -p ~/.config/systemd/user
cp ./scripts/agentmemory.service ~/.config/systemd/user/
systemctl --user daemon-reload
systemctl --user enable agentmemory

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The Chinese section repeats instructions to enable a persistent user service, again establishing long-lived execution. Persistence is not inherently malicious here, but it does increase risk if the service or dependencies are later compromised.

Content

Scanner excerpt · SKILL.md (reported line 477)May include surrounding context.

md
mkdir -p ~/.config/systemd/user
cp ./scripts/agentmemory.service ~/.config/systemd/user/
systemctl --user daemon-reload
systemctl --user enable agentmemory
systemctl --user start agentmemory

# 启用 linger(开机免登录自动启动)

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The final duplicated command repeats the same supply-chain problem: the skill asks users to execute unpinned remote package code. Because this skill is meant for persistent infrastructure setup, compromise would have durable effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide promotes automatic conversation capture and cross-agent/session memory behavior but does not warn users that prompts, project details, credentials, or personal data may be retained and shared across contexts. This can lead to unexpected privacy exposure and improper handling of sensitive information.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill endorses automatic capture of conversations and session logs without any guidance to filter secrets, tokens, personal data, or other sensitive inputs before storage. This increases the chance that confidential material is persistently recorded and later surfaced through recall, migration, or cross-agent access.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

Persisting information to MEMORY.md beyond compaction creates durable storage of potentially sensitive user or project data, increasing the blast radius of accidental disclosure and making deletion harder. In this context, persistence is a product feature, but it still becomes risky when retention boundaries and content restrictions are not defined.

Content

Scanner excerpt · references/coordination.md (reported line 59)May include surrounding context.

md
### Session End

- OpenClaw auto-captures conversation via `plugins.slots.memory`
- Critical learnings → also write to MEMORY.md (persists beyond compaction)

---

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documentation instructs users to run an unpinned package via npx, which fetches and executes the latest published code at runtime. If the package is compromised, typo-squatted, or a malicious update is released, users may execute attacker-controlled code directly on their system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This command again uses npx without a version pin, creating a supply-chain execution risk during migration operations. Because migration may occur in environments containing sensitive memory files, compromise of the fetched package could expose or alter local data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents memory_forget as deleting memories by ID or pattern, but provides no warning about data loss, confirmation expectations, or reversibility. Because markdown files should warn about behaviors that can affect user data or system integrity, this omission is a semantic safety issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.