Back to skill

Security audit

Install Powermem Memory

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent PowerMem memory setup guide, but its shared HTTP setup can expose persistent conversation memory on all network interfaces with authentication described as optional.

Review before installing. Prefer the local CLI/SQLite mode, use a virtual environment, pin or verify package and plugin versions, disable autoCapture for secrets or regulated data, and do not run the HTTP server on 0.0.0.0 unless it is behind strong authentication and network restrictions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned Third-Party Packages and Mutable External Installer

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:30-58
Vulnerability Type: Supply-chain exposure through unpinned dependencies and a mutable external installer
Risk Level: Medium

Vulnerable Code

markdown
**Recommended order (TO C):** (1) OpenClaw installed and **default model + provider auth** configured. (2) **Python 3.10+ verified** (`python3 --version`) *before* venv / `pip install`. (3) `pip install powermem` and `pmem` available to the gateway (PATH or `pmemPath`). (4) Install the **memory-powermem** plugin.

The curl **`install.sh`** deploys the plugin and OpenClaw entries; with **`-y`** it may still create **`~/.openclaw/powermem/powermem.env`** as an *optional* template—it does **not** run `pip install powermem`.

`openclaw --version`. If missing: `npm install -g openclaw`, `openclaw onboard`.

- `pip install powermem`.

`openclaw plugins install /path/to/memory-powermem`, or **`install.sh`** from [INSTALL.md](https://github.com/ob-labs/memory-powermem/blob/main/INSTALL.md).

Equivalent unpinned installation instructions also appear in config-reference.md:10-10, config-reference.md:34-34, and powermem-intro.md:33-33.

Technical Analysis

The installation procedure does not pin powermem or openclaw to reviewed versions and does not require package hashes, signed artifacts, or lock files. Consequently, running the documented commands installs whichever package release the registries currently resolve.

The plugin installation is also delegated to instructions and an install.sh hosted in an external repository. The URL refers to the mutable main branch rather than a reviewed commit. Although the project itself does not contain or directly execute a remote script, following the documented external installation path allows its effective behavior to change after this skill has been audited.

This creates a supply-chain trust boundary in which registry maintainers, compromised publishe ...[truncated 1562 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every package to a reviewed version, for example by documenting exact powermem and openclaw versions.
  2. Use dependency lock files and cryptographic hashes, such as pip hash-checking mode, where supported.
  3. Reference the plugin repository by an immutable commit hash or signed release rather than the main branch.
  4. Include or vendor the reviewed installer in the audited artifact, or require users to download and inspect it before execution.
  5. Verify release signatures and published checksums before installation.
  6. Avoid global npm installation where possible. Install into a constrained user environment without administrator privileges.
  7. Run installation in a virtual environment or isolated container and apply least-privilege filesystem and network controls.
  8. Document the exact tested dependency versions and establish a controlled process for reviewing upgrades.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:54
Finding

Memory HTTP Service Bound to All Interfaces Without Mandatory Authentication

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:54-54
Vulnerability Type: Unsafe network exposure and optional access control
Risk Level: High

Vulnerable Code

markdown
- Same **Python 3.10+** requirement as CLI; then `pip install powermem`, `.env` in server working directory, `powermem-server --host 0.0.0.0 --port 8000`.

The HTTP configuration later describes authentication as optional:

markdown
Optional: `apiKey` if the server uses auth.

The same optional authentication behavior is documented in config-reference.md:46-46:

markdown
| `apiKey` | — | HTTP: optional PowerMem server API key. |

Technical Analysis

Binding powermem-server to 0.0.0.0 makes it listen on every available IPv4 network interface rather than limiting access to the local host. The documented configuration does not require an API key before using this non-loopback binding.

PowerMem is described as storing and searching persistent, conversation-derived memories. Therefore, exposing its API without mandatory authentication creates a potentially sensitive network service reachable from other hosts on the same network and, where routing or firewall configuration permits, from broader networks.

The precise operations exposed to an unauthenticated client depend on PowerMem's server-side endpoint protections. Nevertheless, the documented deployment pattern removes two important defensive controls: loopback-only binding and mandatory authentication.

Attack Path

  1. A user follows the HTTP installation instructions and starts the server with --host 0.0.0.0 --port 8000.
  2. The host firewall, container port mapping, cloud security group, or local network permits another system to reach TCP port 8000.
  3. The user does not configure an API key because the documentation describes it as optional.
  4. An attacker discovers the service through local-network scanning, cloud address scanning, or knowl ...[truncated 1046 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change the default command to bind only to loopback:
    bash
    powermem-server --host 127.0.0.1 --port 8000
    
  2. Require a strong API key or equivalent authenticated access before allowing any non-loopback binding.
  3. Fail closed when authentication configuration is absent rather than silently exposing unauthenticated endpoints.
  4. Place shared deployments behind a TLS-enabled reverse proxy and reject plaintext remote connections.
  5. Restrict ingress with host firewalls, cloud security groups, container networking rules, or a private VPN.
  6. Apply authorization per user and agent namespace rather than relying only on server-wide authentication.
  7. Add rate limiting, request-size limits, audit logging, and alerts for repeated authentication failures or unusual memory operations.
  8. Explicitly warn that 0.0.0.0 must not be used on an untrusted or publicly reachable network without authentication and network controls.
  9. Document procedures for key generation, secure storage, rotation, and revocation.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly states that the plugin can automatically capture valuable user/assistant text after conversations and inject recalled memories into future context, but it does not prominently warn about privacy, consent, retention, or sensitive-data handling. This can lead users to enable persistent collection and re-use of potentially sensitive conversation content without informed consent or clear data-governance expectations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
**Recommended order (TO C):** (1) OpenClaw installed and **default model + provider auth** configured. (2) **Python 3.10+ verified** (`python3 --version`) *before* venv / `pip install`. (3) `pip install powermem` and `pmem` available to the gateway (PATH or `pmemPath`). (4) Install the **memory-powermem** plugin. **No `powermem.env` is required** for the default path.

The curl **`install.sh`** deploys the plugin and OpenClaw entries; with **`-y`** it may still create **`~/.openclaw/powermem/powermem.env`** as an *optional* template—it does **not** run `pip install powermem`. That file is **not** required if the user relies on **OpenClaw-injected** LLM + default SQLite.

1. **Check OpenClaw**  
   `openclaw --version`. If missing: `npm install -g openclaw`, `openclaw onboard`.

Static analysis

No suspicious patterns detected.