Back to skill

Security audit

Agent Memory 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate local memory tool, but it needs review because it persistently stores potentially sensitive conversation facts in plaintext with weak disclosure and deletion guarantees.

Review this before installing if the agent may handle private conversations, personal details, credentials, business plans, or regulated data. Use a custom database path with restrictive filesystem permissions, avoid storing secrets, periodically inspect/export/purge the database, and do not rely on the current forget() implementation for complete removal until the FTS cleanup issue is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
src/memory.py:102
Finding

Persistent memory database is created without enforced restrictive filesystem permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/memory.py:337
Finding

Fact deletion leaves the deleted content in the full-text search index

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly promotes persistent cross-session storage of facts, lessons, and person-related attributes such as preferences, roles, timezones, and communication style, but it does not provide any meaningful warning about privacy, consent, retention, or sensitive-data handling. In an agent skill, this can normalize collecting and retaining personal or relationship data indefinitely in a local database, increasing the risk of privacy violations, over-collection, and unintended disclosure if the host system or database is accessed by others.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly promotes persistent storage of facts, lessons, and entity information across sessions, but it does not warn users that conversation-derived data may be retained on disk in a local database. This creates a real privacy and security risk because agents may store sensitive personal, project, or credential-adjacent information without informed consent or data-handling guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example explicitly initializes a persistent local database at /tmp/agent-memory-example.db and then stores user-like facts, lessons, and entity attributes, including personal and operational information. In an example or skill context, this can normalize unsafe handling of sensitive data without warning users about persistence, retention, or local exposure to other users/processes on the same system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module silently creates a persistent SQLite database under the user's home directory and stores arbitrary facts, lessons, and entity attributes that may contain sensitive personal or operational data. In an agent-memory context, this is dangerous because users may not realize their prompts, preferences, and observed details are being retained across sessions on disk, increasing privacy, compliance, and local data-exposure risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.