Back to skill

Security audit

Evomemory Core

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is mostly coherent, but it needs Review because it claims offline-only operation while the code supports an under-documented remote ChromaDB mode that can transmit memory data, queries, metadata, and an API key.

Review this skill carefully before installing. Use it only for local ChromaDB unless you intentionally configure a trusted remote server over secure transport, and avoid storing API keys in ordinary config. Back up important memory data before migration or deletion operations, and consider installing dependencies in a dedicated environment with pinned versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
install.sh:12
Finding

Unpinned Third-Party Dependencies Installed from Mutable Sources

Content
View full analysis

Vulnerability Details

File Location: install.sh, line 12
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable Code:

bash
pip3 install chromadb sentence-transformers pyyaml

Technical Analysis

The installation script installs three third-party packages without exact version constraints, integrity hashes, a lockfile, or an explicitly trusted package index. Consequently, the code installed and executed can change between installations without any modification to this project.

Python package installation may execute package-controlled build or installation logic with the privileges of the user running the installer. The documented minimum dependency versions in SKILL.md are also not enforced by this command. This can result in the installation of incompatible, vulnerable, or compromised future releases.

This finding does not establish that the named packages are currently malicious. The vulnerability is the absence of controls that ensure users receive the dependency versions reviewed and tested by the project.

Attack Path

  1. An attacker compromises an upstream package account, package release, distribution channel, or package-resolution environment.
  2. The attacker publishes or causes resolution to a malicious version of one of the unpinned dependencies.
  3. A user executes install.sh.
  4. pip3 resolves the mutable package name to the attacker-controlled release.
  5. Malicious installation or runtime code executes with the privileges of the user who invoked the script.

Impact Assessment

Successful exploitation can execute arbitrary code under the installing user's account. That code could access files and credentials available to that user, alter the OpenClaw installation, tamper with stored agent memory, or establish further persistence. If the installer is run with elevated privileges, the impact could extend to system-level resou ...[truncated 60 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every dependency to an exact, reviewed version.
  • Generate and commit a reproducible lockfile containing transitive dependencies.
  • Require cryptographic hashes during installation, such as through a hash-locked requirements file and pip install --require-hashes.
  • Configure an explicit trusted package index rather than relying on ambient pip configuration.
  • Install dependencies inside a dedicated virtual environment with least privilege.
  • Add automated dependency vulnerability and provenance checks to the release process.
  • Update the installation command to use the reviewed lockfile, for example:
    bash
    python3 -m pip install --require-hashes -r requirements.lock
    

T09 · Insecure Skill Coding Practices

Warning
Location
chromadb_plugin.py:18
Finding

Remote ChromaDB Mode Does Not Enforce Transport Encryption

Content
View full analysis

Vulnerability Details

File Location: chromadb_plugin.py, lines 18–23
Vulnerability Type: Plaintext exposure of credentials and agent-memory data
Risk Level: Medium

Vulnerable Code:

python
if host and port:
    # Cloud mode
    self.client = chromadb.HttpClient(
        host=host,
        port=port,
        headers={"Authorization": f"Bearer {api_key}"} if api_key else None
    )

Technical Analysis

When both host and port are configured, the plugin creates a remote ChromaDB HTTP client and optionally places an API key in an Authorization: Bearer header. The call does not explicitly require TLS or configure certificate verification.

Operations performed through this client can transmit stored documents, metadata, query text, and the bearer credential to the configured endpoint. If the connection uses plaintext HTTP, network traffic can be observed or modified by an on-path attacker. A malicious or attacker-influenced configuration can also direct sensitive memory operations to an untrusted server.

The existence of this remote mode conflicts with the unconditional “100% offline” representations in the documentation. Users relying on that claim may not anticipate that configuration can cause memory content to leave the local machine.

Attack Path

  1. Remote mode is enabled through configuration containing a host and port, either intentionally or after an attacker gains influence over configuration.
  2. The endpoint is reached without an authenticated, encrypted transport.
  3. The plugin attaches the bearer API key to requests and performs ChromaDB operations.
  4. Agent-memory documents, metadata, and query text are sent over the connection.
  5. An on-path attacker intercepts or modifies the traffic, or a malicious configured endpoint records the credentials and memory content.
  6. A captured bearer token may be reused against the ChromaDB service to the extent permitted by th ...[truncated 569 chars]
Remediation
View remediation

Remediation Suggestions

  • Keep local-only operation as the default and require explicit user consent before enabling remote mode.
  • Explicitly enable and require TLS for every non-loopback remote endpoint.
  • Enable certificate and hostname verification and reject invalid or self-signed certificates unless the user explicitly configures a trusted private certificate authority.
  • Reject plaintext remote endpoints when an API key or memory data would be transmitted.
  • Validate remote hosts against an administrator-controlled allowlist where practical.
  • Store API keys in a protected secret store or environment-based credential provider rather than ordinary configuration files.
  • Apply narrowly scoped, revocable credentials and rotate any credential suspected of plaintext exposure.
  • Clearly document that remote mode transmits memory and query content and qualify the existing offline-operation claims.
  • Add tests confirming that insecure remote connections fail closed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

When host and port are provided, the plugin initializes a ChromaDB HttpClient and may send documents, queries, and metadata to a remote service. The file contains no confirmation prompt, logging, or explicit warning comment/docstring disclosing that user data may leave the local system in cloud mode.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The delete method performs irreversible removal of documents by id or filter, but the file provides no warning beyond a terse method docstring. There is no confirmation, logging, or explanatory comment indicating that calling this method permanently deletes stored data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 20)May include surrounding context.

sh
fi

echo "[*] Copying plugin files..."
mkdir -p ~/.openclaw/extensions/chromadb
cp chromadb_plugin.py ~/.openclaw/extensions/chromadb/
cp README.md ~/.openclaw/extensions/chromadb/
cp -r docs ~/.openclaw/extensions/chromadb/

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring promises "100% data consistency guaranteed" and "rollback supported," but the implementation only compares final record counts and has no transactional rollback or cleanup on partial failure. This can mislead operators into running the tool under unsafe assumptions, causing silent partial migrations, duplicated/inconsistent destination state, or difficult recovery after interruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script performs bulk writes into the destination database as soon as it is executed, without an explicit confirmation, dry-run mode, or warning that existing destination data may be modified or merged. In a migration context this increases the risk of accidental data corruption, duplication, or overwriting due to operator error, especially because the tool presents itself as safe and rollback-capable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The feature list highlights 'BGE-M3 Chinese semantic vector optimization' and improved Chinese retrieval accuracy, which indicates a locale-specific optimization. The document does not explain whether non-Chinese users can choose another language profile or whether the Chinese focus is an intentional region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to run evomemory migrate to import existing memory data, which is an operation that affects user data. The surrounding documentation describes features and setup, but does not include any caution about reviewing the source/target data, backup considerations, or the effects of migration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The top-level documentation asserts full compatibility with an existing LanceDB interface, suggesting behavior limited to that interface. However, the class adds ChromaDB-exclusive methods such as create_collection, switch_collection, and hybrid_query, which means the implementation is not strictly just a compatible drop-in interface and the documentation overstates equivalence.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.