Back to skill

Security audit

Mimir

Security checks for vulnerabilities and agentic risk

Overview

This skill’s memory purpose is coherent, but its install and privacy guidance need Review because it recommends unverified executable/package installs and overstates encryption/local-only protections.

Install only after reviewing the upstream project and verifying the exact binary or building from a pinned, trusted release. Prefer a user-local install path over sudo, protect ~/.openclaw/.env and the database with restrictive permissions, configure an encryption key before storing sensitive memories, and avoid exporting memories to shared/cloud/git locations unless separately protected.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:98
Finding

Unverified Mutable Remote Binary Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 98–101
Vulnerability Type: Remote executable retrieved from a mutable URL without integrity verification
Risk Level: High

Vulnerable Code:

bash
# Linux x86_64
curl -L https://github.com/Perseus-Computing-LLC/mimir/releases/latest/download/mimir-linux-x86_64 -o mimir
chmod +x mimir
sudo mv mimir /usr/local/bin/

Technical Analysis

The installation procedure retrieves an executable from a mutable latest release URL, marks it executable, and installs it into the system-wide /usr/local/bin directory. It does not pin an audited release version or verify a cryptographic checksum or signature.

Consequently, the effective executable can change after the Skill has been reviewed. Compromise of the upstream repository, release account, release artifact, or download path could cause users to install an attacker-controlled binary. Although the command does not execute the binary immediately, later setup instructions and MCP configuration cause it to run as the invoking user.

The use of sudo to place the executable in a system-wide location also exceeds the minimum privileges needed for the declared functionality. Mimir could instead be installed and executed from a user-owned directory.

Attack Path

  1. An attacker compromises the upstream release process, maintainer account, or downloadable latest artifact.
  2. The attacker replaces the binary with a malicious executable.
  3. A user follows the documented installation procedure and downloads the altered artifact without integrity verification.
  4. The user marks the artifact executable and installs it into /usr/local/bin.
  5. OpenClaw or the user subsequently invokes mimir as an MCP server.
  6. The malicious binary executes with the permissions of the OpenClaw process or invoking user, gaining access to files, environment variables, agent memories, and reachable local services availab ...[truncated 732 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin a specific audited release version instead of using the mutable latest URL.
  • Publish an expected SHA-256 or stronger digest through a separately protected channel and verify it before setting executable permissions.
  • Prefer cryptographically signed releases and validate the signature against a documented maintainer key.
  • Abort installation if checksum or signature verification fails.
  • Install the executable in a user-owned directory such as ~/.local/bin instead of using sudo and /usr/local/bin.
  • Document the exact reviewed version and provide an explicit upgrade procedure that repeats integrity verification.
  • For source builds, pin a release tag or commit and verify the signed tag or commit before building.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:113
Finding

Unpinned Python Dependency Installed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 113
Vulnerability Type: Unpinned third-party package installation
Risk Level: Medium

Vulnerable Code:

bash
pip install mimir-client

Technical Analysis

The optional Python client is installed by package name without a pinned version or package hash. The installed code is therefore determined by the package index at installation time and may differ from the version that existed when the Skill was audited.

Python packages can execute build or installation logic and later execute with the permissions of the importing process. A compromised publisher account, malicious future release, or package-index supply-chain incident could introduce attacker-controlled code. Installing outside an isolated virtual environment may also modify the user’s broader Python environment and create dependency conflicts.

Attack Path

  1. An attacker compromises the package publisher account or upstream release process for mimir-client.
  2. The attacker publishes a malicious package version under the same package name.
  3. A user executes the unpinned pip install mimir-client command.
  4. Pip selects and downloads the attacker-controlled release.
  5. Malicious installation logic or imported client code executes with the user’s permissions.
  6. The code can access files, environment variables, OpenClaw configuration, memory databases, and network resources available to that user.

Impact Assessment

Exploitation could result in arbitrary Python or native-code execution as the installing or importing user. The accessible scope includes that user’s files, local credentials, environment secrets, agent data, and reachable services. The package is documented as optional, so accepting this supply-chain exposure is not necessary for Mimir’s core MCP operation.

Remediation
View remediation

Remediation Suggestions

  • Pin the client to a specifically audited version.
  • Use a lock file or requirements file containing trusted hashes, and install with pip --require-hashes.
  • Install the package in a dedicated virtual environment rather than the system or general user environment.
  • Review package provenance, maintainer identity, release history, and distribution metadata before recommending it.
  • Prefer signed provenance or reproducible artifacts where available.
  • Clearly retain the “optional” designation and avoid installing the client when only MCP server functionality is required.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:145
Finding

Encryption Key Persisted Without File-Permission Hardening

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 145–147
Vulnerability Type: Insecure plaintext secret storage and duplicate configuration handling
Risk Level: Medium

Vulnerable Code:

bash
# Generate a 32-byte key
MIMIR_ENCRYPTION_KEY=$(openssl rand -hex 32)
echo "MIMIR_ENCRYPTION_KEY=$MIMIR_ENCRYPTION_KEY" >> ~/.openclaw/.env

Technical Analysis

Generating an encryption key is necessary for the declared encryption-at-rest feature. However, the instructions append the plaintext key to ~/.openclaw/.env without first creating the directory and file with restrictive permissions or verifying the permissions of an existing file.

Shell redirection respects the process umask when creating a new file and preserves existing permissions when appending to a file. On a system with a permissive umask or an already overexposed .env file, other local accounts or processes may be able to read the key.

Repeated execution also appends multiple definitions of MIMIR_ENCRYPTION_KEY. Depending on the environment-file parser, either the first or last definition may be selected. Unintended key rotation or ambiguous selection can make previously encrypted memories inaccessible.

Attack Path

  1. The user has a permissive umask, or ~/.openclaw/.env already has permissions that allow another local principal to read it.
  2. The user follows the setup instructions and appends the generated encryption key.
  3. Another local user or compromised process reads the plaintext key from the environment file.
  4. The attacker obtains access to the Mimir database or a copy of it.
  5. The attacker uses the exposed key to decrypt stored agent memories.

A reliability-related path also exists:

  1. The user runs the key-generation commands more than once.
  2. Multiple conflicting key definitions are appended.
  3. Mimir loads a different key from the one used to encrypt existing records.
  4. Existing encrypte ...[truncated 581 chars]
Remediation
View remediation

Remediation Suggestions

  • Create the configuration directory and file under a restrictive umask:
    bash
    umask 077
    mkdir -p ~/.openclaw
    touch ~/.openclaw/.env
    chmod 600 ~/.openclaw/.env
    
  • Replace an existing MIMIR_ENCRYPTION_KEY entry atomically instead of appending duplicate definitions.
  • Prefer an operating-system keychain, credential store, or dedicated secret manager over a plaintext environment file.
  • Never print the key to terminal logs, shell tracing, CI output, or diagnostic reports.
  • Document secure backup and recovery procedures because loss of the key makes encrypted memories unrecoverable.
  • Validate ownership and permissions before Mimir starts, and fail closed when the secret file is accessible by unauthorized users.
  • Restrict permissions on the Mimir database and its parent directory in addition to protecting the key.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
71% confidence
Finding

The instructions place the encryption key into a .env file, which can be acceptable, but they do not warn about file permissions, accidental inclusion in backups, or exposure through other local processes and tooling. Poor secret-handling guidance can undermine the claimed at-rest protection if the key is stored insecurely.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

bash
# Generate a 32-byte key
MIMIR_ENCRYPTION_KEY=$(openssl rand -hex 32)
echo "MIMIR_ENCRYPTION_KEY=$MIMIR_ENCRYPTION_KEY" >> ~/.openclaw/.env

Without an encryption key, Mimir stores data unencrypted (still local).

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation makes a strong blanket claim that all stored memories are AES-256-GCM encrypted, but later states encryption is optional and plaintext storage is used when no key is configured. This can cause users to store sensitive data under a false assumption of confidentiality, leading to inadvertent exposure on disk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
- `mimir_compact` — Archive memories below a decay threshold

### Knowledge graph
- `mimir_link` — Create relationships between memories
- `mimir_unlink` — Remove stale relationships
- `mimir_traverse` — Walk the relationship graph from any memory

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

The skill instructs users to move a downloaded binary into /usr/local/bin using sudo, which normalizes privileged execution of an unverified artifact. If the binary or download source is malicious or tampered with, this can facilitate full system compromise.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

Linux x86_64

curl -L https://github.com/Perseus-Computing-LLC/mimir/releases/latest/download/mimir-linux-x86_64 -o mimir chmod +x mimir sudo mv mimir /usr/local/bin/

text

**Build from source (requires Rust):**

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
82% confidence
Finding

The build-from-source path culminates in copying the built binary into a privileged system directory with sudo. While common, it still elevates risk because users may treat the entire workflow as trusted without validating source provenance or reviewing build scripts and dependencies.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

git clone https://github.com/Perseus-Computing-LLC/mimir.git cd mimir cargo build --release sudo cp target/release/mimir /usr/local/bin/

text

**Python client (optional, for scripts):**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill recommends exporting memories to markdown for backup or sharing, but exported files may no longer benefit from database-level encryption controls and can be copied, committed, or synced broadly. Sensitive agent memories could therefore be exposed outside the protected local store.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that no data leaves the environment and implies no network exposure, yet later documents use of an LLM endpoint and a web dashboard listening on a local port. Even if these features are optional or local-only, the inconsistency can mislead operators about attack surface and data flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The instructions encourage downloading and executing a binary directly from a release URL without mentioning signature, checksum, or provenance verification. This increases supply-chain risk if the distribution channel or local download path is compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.