Back to skill

Security audit

Chromadb Memory Pub

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is coherent, but it automatically reuses stored memory in every turn with broad, under-scoped data-flow and prompt-injection risks.

Install only if you trust the ChromaDB collection, the OpenClaw plugin configuration, and the Ollama/Chroma endpoints. Prefer disabling autoRecall until configured, keeping endpoints local or explicitly trusted, isolating collections per user/project, avoiding secrets in stored memories, and pinning the ChromaDB image version.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
scripts/index.ts:399
Finding

Untrusted ChromaDB Content Is Injected into the Agent Context

Content
View full analysis
`- [${r.source}] ${r.text.slice(0, 300)}${r.text.length > 300 ? "..." : ""}`, ) .join("\n"); _consecutiveFailures = 0; // Reset on success api.logger.info( `chromadb-memory: auto-recall injecting ${relevant.length} memories (best: ${relevant[0].score.toFixed(3)} from ${relevant[0].source})`, ); return { prependContext: `\nRelevant context from long-term memory (ChromaDB):\n${memoryContext}\n`, }; ``` ### Technical Analysis Documents returned by ChromaDB are inserted verbatim into `prependContext` before the agent begins processing the current turn. The implementation does not distinguish trusted instructions from untrusted retrieved data, sanitize structural delimiters, validate document provenance, or warn the model that directives contained in memories must not be followed. The XML-like `` wrapper is not a security boundary. A stored document can contain instruction-like text or closing tags that alter the apparent structure of the context. Because semantic retrieval is automatic and enabled by default, poisoned content may be introduced without a manual tool call. This is classified as skill instruction hijacking because attacker-controlled retrieved text can alter the active agent session when the skill loads recalled context. The underlying ChromaDB record is persistent, but this plugin does not itself write the malicious record. ### Attack Path 1. An attacker obtains the ability to add or modify a document in the indexed collection or an upstream source processed by the ChromaDB indexer. 2. The attacker stores content containing model-directed instructions, such as requests to ignore current goals, disclose a ...[truncated 1285 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/index.ts:48
Finding

Unrestricted Embedding Endpoint Can Receive Complete User Prompts

Content
View full analysis
; return { chromaUrl: (cfg.chromaUrl as string) || "http://localhost:8100", collectionId: (cfg.collectionId as string) || "", collectionName: (cfg.collectionName as string) || "longterm_memory", ollamaUrl: (cfg.ollamaUrl as string) || "http://localhost:11434", embeddingModel: (cfg.embeddingModel as string) || "nomic-embed-text", autoRecall: cfg.autoRecall !== false, autoRecallResults: (cfg.autoRecallResults as number) || 3, minScore: (cfg.minScore as number) || 0.5, }; } ``` ```ts async function getEmbedding( ollamaUrl: string, model: string, text: string, ): Promise { const resp = await fetch(`${ollamaUrl}/api/embeddings`, { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ model, prompt: text }), }); if (!resp.ok) { throw new Error(`Ollama embedding failed: ${resp.status} ${resp.statusText}`); } const data = (await resp.json()) as { embedding: number[] }; return data.embedding; } ``` ```ts const embedding = await getEmbedding( cfg.ollamaUrl, cfg.embeddingModel, event.prompt, ); ``` ### Technical Analysis The `ollamaUrl` setting accepts an arbitrary string and is concatenated directly with `/api/embeddings`. During automatic recall, the complete user prompt is placed in the JSON request body and sent to that endpoint. Although the default points to localhost, the implementation does not enforce a loopback destination, restrict permitted hosts, validate the URL scheme, require TLS for remote hosts, or require explicit acknow ...[truncated 1694 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly advertises automatic memory injection on every turn, but it does not clearly warn that prior conversations or stored data may be surfaced back into future prompts automatically. In an agent skill, this can expose sensitive information unexpectedly to downstream tools, other users, or model outputs, especially when the backing ChromaDB server may be remote.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration example enables autoRecall: true by default without an explicit warning that the agent will automatically retrieve and inject memories from a local or remote vector store. This increases the chance of unintended disclosure of secrets, personal data, or irrelevant prior context because users may adopt the sample configuration verbatim.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents network-dependent behavior (ChromaDB and Ollama HTTP endpoints) but does not declare any explicit tool scope or allowed network permissions. This weakens reviewability and least-privilege enforcement, making it harder for operators to understand that every turn may trigger local HTTP requests and increasing the risk of unintended network access if configuration is changed from localhost to a remote endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill enables automatic embedding of every user message, querying of long-term memory, and injection of matched memories into the prompt context each turn, but it does not present this as a prominent user warning or consent boundary. In a memory skill, this is especially sensitive because private or unrelated past content can be surfaced into future prompts, creating confidentiality and context-leak risks even when everything is local.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The installation instructions use the floating image tag chromadb/chroma:latest, which makes deployments non-reproducible and can silently pull changed or compromised images over time. If the upstream image is replaced, vulnerable, or malicious, users may run unexpected code with local access to stored memory data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

bash
# 1. Copy the plugin extension
mkdir -p ~/.openclaw/extensions/chromadb-memory
cp {baseDir}/scripts/index.ts ~/.openclaw/extensions/chromadb-memory/
cp {baseDir}/scripts/openclaw.plugin.json ~/.openclaw/extensions/chromadb-memory/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The auto-recall hook sends every sufficiently long agent prompt to the local Ollama embedding endpoint without any user-facing notice or consent flow. Even though the service is described as self-hosted, prompts may contain sensitive data, and this design causes implicit transmission of that data to another service component before each turn.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The plugin description explicitly states that relevant memories are automatically injected before each turn, but the manifest does not provide a clear privacy warning, consent mechanism, or explanation of what prior data may be surfaced into future prompts. In a long-term memory skill, this can cause sensitive prior user content to be reintroduced unexpectedly into model context, increasing the risk of inadvertent disclosure to the model, tools, or downstream outputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.