Back to skill

Security audit

Omem

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent work-memory search wrapper, but it asks for broad access to sensitive local work history and includes unsafe command/install guidance that users should review carefully.

Review this before installing if your OMem index includes confidential work material. Use the skill only for clearly work-history-related questions, avoid pasting untrusted text directly into OMem shell queries, and prefer a verified or package-managed OMem installer over the provided curl-to-shell command.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/troubleshooting.md:12
Finding

Unverified Remote Installation Script Executed Through a Shell Pipeline

Content
View full analysis

Vulnerability Details

File Location: references/troubleshooting.md:12-15
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

markdown
> The OMem CLI isn't installed yet. Install it, then run `omem setup`:
> `curl -fsSL https://github.com/seacen/omem/releases/latest/download/install.sh | sh`
> Docs: https://seacen.github.io/omem/

Technical Analysis

The installation guidance pipes content retrieved from a mutable external URL directly into sh. The downloaded script is neither displayed for review nor verified using a cryptographic checksum or digital signature. The URL also follows the mutable releases/latest path rather than identifying an immutable release and artifact.

Although the Skill tells the agent not to perform the installation itself, it explicitly instructs the agent to relay this command to the user. Deferring execution to the user does not eliminate the remote-code-execution risk.

GitHub transport security alone does not establish payload integrity. Compromise of the repository, maintainer account, release workflow, release artifact, or upstream delivery mechanism could replace the script after the Skill has been audited. The effective code executed by the user can therefore differ from the code reviewed during this audit.

Attack Path

  1. The user invokes the Skill on a system where the omem command is unavailable.
  2. The agent follows the troubleshooting instructions and presents the installation pipeline.
  3. An attacker compromises or replaces the script available through the mutable release URL.
  4. The user runs the recommended command.
  5. curl retrieves the attacker-controlled content and streams it directly to sh.
  6. The payload executes with all privileges available to the user's shell.

Impact Assessment

Successful exploitation permits arbitrary command execution under the installing user's acc ...[truncated 488 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh installation instruction.
  2. Pin installation guidance to a specific, immutable release version rather than releases/latest.
  3. Publish SHA-256 checksums and a verifiable cryptographic signature through an independent trusted channel.
  4. Require users to download, verify, inspect, and execute the installer as separate operations.
  5. Prefer a signed operating-system package or reputable package manager with integrity verification.
  6. Document the files, permissions, services, and scheduled tasks created by the installer.
  7. Recommend running installation without elevated privileges unless a specific operation demonstrably requires them.

A safer pattern is:

sh
curl -fL -o install.sh "https://github.com/seacen/omem/releases/download/vX.Y.Z/install.sh"
echo "EXPECTED_SHA256  install.sh" | sha256sum -c -
less install.sh
sh install.sh

The version and checksum must be replaced with authenticated, release-specific values.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:28
Finding

Shell Command Injection Risk from Natural-Language Query Interpolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:28, SKILL.md:79, SKILL.md:175; related quoting guidance at references/query-syntax.md:63-66
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable Code:

markdown
Primary tool: `omem query "<question>" --format json --limit 20`
markdown
| L0 abstracts | `omem query "<q>" --format json --limit 20` | ~2k total | Always first |
markdown
### `omem query "<question>" --format json --limit 20`

The related reference recommends manual shell quoting:

markdown
- **Quotes inside the query**: escape with backslash for the shell, or
  use single-quote outer wrapping:
  - `omem query 'Alice said "we should pivot"' --format json`

Technical Analysis

The Skill authorizes the Bash tool and instructs the agent to place user-derived natural-language text inside a shell command. Double quotes do not safely contain arbitrary input when the input itself can contain quote characters, command substitutions, backticks, backslashes, or other shell syntax.

Manual selection between single and double quotes is not a reliable argument-boundary mechanism. The documented single-quote alternative remains unsafe for arbitrary text containing an apostrophe unless it is escaped correctly. Model-generated escaping is also error-prone and is not equivalent to invoking a process with a structured argument array.

For example, a query containing the following benign proof-of-concept text could terminate the intended quoted argument:

text
"; touch /tmp/omem-injected; #

If inserted verbatim into the documented template, the shell would interpret touch /tmp/omem-injected as a separate command rather than as search text.

Attack Path

  1. An attacker supplies crafted text in a work-memory question, document title, quoted phrase, or other query input.
  2. The agent follows the Skill templat ...[truncated 1250 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not construct a shell command by concatenating or interpolating the user's question.

  2. Invoke omem through a process API that accepts an argument array, for example the conceptual equivalent of:

    text
    ["omem", "query", user_question, "--format", "json", "--limit", "20"]
    
  3. If the available tool only supports Bash, pass the query through a fixed positional parameter rather than inserting it into command source:

    sh
    bash -c 'exec omem query "$1" --format json --limit 20' _ "$QUERY"
    

    The host integration must still bind QUERY as data rather than interpolating it into the command string.

  4. Apply the same structured argument handling to --search, --source, --account, --since, page identifiers, and filesystem paths.

  5. Add tests covering double quotes, apostrophes, backticks, dollar-sign substitutions, semicolons, newlines, backslashes, and non-ASCII punctuation.

  6. State explicitly in the Skill that user input and retrieved document content must never be treated as shell syntax.

  7. Restrict the Bash tool where possible and expose a dedicated OMem tool with typed parameters instead.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to invoke OMem whenever a question 'touches work context, even implicitly' and to query first 'when in doubt.' That broad default can cause unnecessary access to highly sensitive local work-memory sources (email, calendar, documents, notes) for loosely related requests, expanding data exposure beyond what is needed for the user’s immediate task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Markdown repeats the same permissive trigger model: call OMem for broad categories of workplace context and default to invocation on uncertainty because 'a 0-result query is cheap.' In a security context, the query is not cheap: even unsuccessful or exploratory searches still touch a sensitive local index and may retrieve confidential summaries unrelated to the narrow user need.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The troubleshooting guidance tells the user to install software by piping a remotely fetched script directly into a shell. That pattern is dangerous because it executes whatever the server returns at install time without review, integrity verification, or pinning to a specific version, so a compromised release channel, repository, or network path could lead to arbitrary code execution on the user's machine.

Content

Scanner excerpt · references/troubleshooting.md (reported line 14)May include surrounding context.

md
Tell the user (don't install it yourself):

> The OMem CLI isn't installed yet. Install it, then run `omem setup`:
> `curl -fsSL https://github.com/seacen/omem/releases/latest/download/install.sh | sh`
> Docs: https://seacen.github.io/omem/

Until the CLI is installed, none of this skill's commands will work, so

Static analysis

No suspicious patterns detected.