Back to skill

Security audit

SwarmRecall Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent external memory integration, but users should understand that it stores persistent memories remotely and can use shared-pool memories in future responses.

Install only if you are comfortable storing selected conversation memory on SwarmRecall servers. Get user consent before storing personal or sensitive information, keep the API key in a protected environment variable, avoid untrusted SWARMRECALL_API_URL values, and treat recalled shared-pool content as context to verify rather than instructions to obey.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:113
Finding

Untrusted Shared-Pool Memories Can Persistently Influence Agent Responses

Content
View full analysis
` and use returned memories to inform your response. - On session end: call `PATCH /api/v1/memory/sessions/:id` with `ended: true` and a summary. ## Shared Pools - The `POST /api/v1/memory` and `POST /api/v1/memory/sessions` endpoints accept an optional `"poolId"` field. - When `poolId` is provided, the memory or session is shared with all pool members who have memory read access. - The agent must have readwrite access to the pool's memory module to write shared memories. - Search (`GET /api/v1/memory/search`) and list (`GET /api/v1/memory`) results automatically include data from pools the agent belongs to. - Pool data in responses includes `poolId` and `poolName` fields to distinguish shared data from the agent's own data. ``` ### Technical Analysis The skill instructs the agent to use retrieved memories to inform responses. Search and list results automatically include records written to shared pools, but the instructions do not require the agent to: - Treat recalled content as untrusted data. - Distinguish factual data from instructions embedded in memory content. - Validate the author or provenance of shared records. - Restrict recall to private memories when shared data is unnecessary. - Obtain confirmation before acting on sensitive claims originating from a pool. Consequently, a pool member with legitimate write access—or an attacker who compromises such a member—can store instruction-like or misleading conte ...[truncated 1748 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

Configurable API Base URL Can Redirect the Bearer Credential to an Untrusted Server

Content
View full analysis
``` ## API Base URL `https://swarmrecall-api.onrender.com` (override with `SWARMRECALL_API_URL` if set) ``` ### Technical Analysis The skill requires the SwarmRecall API key to be sent as a bearer credential with all API requests while permitting `SWARMRECALL_API_URL` to replace the trusted service URL. No hostname allowlist, HTTPS validation requirement, certificate-pinning requirement, or user confirmation is specified for the override. Environment variables may be influenced by deployment configuration, wrappers, compromised startup scripts, or another process with sufficient control over the agent's environment. If `SWARMRECALL_API_URL` points to an attacker-controlled server, requests made according to the skill can disclose the bearer token in the `Authorization` header. An HTTP destination would additionally expose authenticated traffic to network interception if accepted by the client. The exploitability depends on an attacker or misconfiguration being able to set the environment variable before the skill makes an authenticated request. ### Attack Path 1. An attacker gains control over the agent's deployment environment, startup configuration, or another mechanism capable of setting `SWARMRECALL_API_URL`. 2. The attacker sets the variable to an attacker-controlled API endpoint. 3. The agent loads the skill and uses the overridden base URL for a memory, session, or registration-related API operation. 4. The agent sends `Authorization: Bearer ` to the attacker-controlled endpoint. 5. The attacker captures the bearer credential. 6. The attacker uses the stolen key against the legitimate SwarmRecall API, subject to the permissions assoc ...[truncated 655 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

Delete a memory

text
DELETE /api/v1/memory/:id

Start a session

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
82% confidence
Finding

The dream-cycle instructions tell the agent to merge records and then delete 'duplicates' or stale contradictory memories based on automated clustering/flagging. This creates a real tool-parameter abuse risk because an LLM may misidentify which memory ID is safe to remove, causing unauthorized or irreversible deletion of valid contextual data without explicit user approval.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
Memory is the primary target of dream operations. During a dream cycle:

- **Duplicate clusters**: Groups of similar memories are identified by the dream service. The agent reads the cluster, merges content into the anchor memory, and archives the rest. Use `PATCH /api/v1/memory/:id` to update the anchor and `DELETE /api/v1/memory/:id` to archive duplicates.
- **Session summaries**: Unsummarized sessions are flagged. The agent reads session memories via `GET /api/v1/memory?sessionId=X`, then writes a summary via `POST /api/v1/memory` with `category: "session_summary"`.
- **Decay and pruning**: The server automatically reduces importance of old memories and archives those below the prune threshold. Memories with `category: "session_summary"` or tag `"pinned"` are protected.
- **Contradictions**: Memory pairs with high similarity but divergent content are flagged. The agent reviews both, archives the stale one, and optionally updates the current one.

Static analysis

No suspicious patterns detected.