Back to skill

Security audit

SwarmRecall

Security checks for vulnerabilities and agentic risk

Overview

SwarmRecall is a disclosed remote memory service, but it needs Review because it encourages persistent storage of raw logs and user context that may contain secrets or sensitive information.

Install only if you are comfortable with agent memories, learnings, sessions, and related data being sent to SwarmRecall servers and retained for later search. Avoid storing secrets, credentials, private logs, regulated data, or confidential project output unless you have reviewed retention and deletion controls. Prefer environment-based secret handling, verify the active API URL before authenticated use, and sanitize logs before using the learnings workflow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:26
Finding

Unpinned Third-Party Packages Create a Mutable Supply-Chain Execution Path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:26, SKILL.md:44, SKILL.md:60; also repeated in README.md:18, README.md:32, README.md:110, and examples/quickstart.md:8
Vulnerability Type: Unpinned executable dependency
Risk Level: Medium

Vulnerable Code

bash
npm install -g @swarmrecall/cli
bash
npm install @swarmrecall/sdk

The update instructions explicitly select the latest available release:

bash
npm install -g @swarmrecall/cli@latest

Technical Analysis

The Skill instructs users to retrieve and execute third-party npm packages without pinning an exact reviewed version or providing an integrity hash. The project contains documentation only and does not include the CLI or SDK source, a package lockfile, or another mechanism that binds installation to the code reviewed during this audit.

npm installations may execute package lifecycle scripts. A future compromised or malicious release could therefore run code during installation with the privileges of the user invoking npm. Global installation of the CLI also makes the executable available throughout the user's environment and increases the scope of a compromised package.

There is no evidence in the audited project that the named packages are currently malicious. The vulnerability is that the effective installed code can change independently after this Skill has been reviewed.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or a transitive dependency.
  2. The attacker publishes a malicious version under the existing package name.
  3. A user follows the documented unversioned installation or @latest update command.
  4. npm downloads the compromised package and may execute its lifecycle scripts.
  5. Malicious code runs with the installing user's privileges and can access files, environment variables, agent configuration, and network resources available to tha ...[truncated 389 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI and SDK to exact versions that have been reviewed, rather than using an unqualified package name or @latest.
  2. Publish and verify package integrity hashes or signed release provenance.
  3. For SDK projects, provide a lockfile and require reproducible installation with npm ci.
  4. Prefer a project-local CLI installation over global installation where practical.
  5. Disable npm lifecycle scripts when they are not required, or document and audit every required lifecycle script.
  6. Add an upgrade procedure that reviews source changes and dependencies before changing the pinned version.
  7. Run the CLI under a dedicated, least-privileged account or sandbox without unrelated credentials.

T09 · Insecure Skill Coding Practices

Error
Location
examples/learnings-workflow.md:7
Finding

Raw Diagnostic Logs May Exfiltrate Secrets to Persistent Remote Storage

Content
View full analysis

Vulnerability Details

File Location: examples/learnings-workflow.md:7-12, examples/learnings-workflow.md:57; reinforced by SKILL.md:178
Vulnerability Type: Unredacted transmission and persistence of sensitive diagnostic data
Risk Level: High

Vulnerable Code

bash
swarmrecall learnings log \
  --category error \
  --summary "npm install fails with peer dep conflict" \
  --details "$(cat /tmp/npm-output.log)" \
  --priority high \
  --area build

The workflow further directs the agent to retain complete diagnostic content:

text
Include the raw error output in details — semantic search across that text is how future agents will find the pattern.

The main Skill similarly instructs:

text
On error or correction: learning_log with the full error output / what was wrong vs. correct.

Technical Analysis

learning_log transmits its content to the hosted SwarmRecall service, where the Skill states that data is stored server-side and indexed with vector embeddings. The documented shell command reads the entire contents of /tmp/npm-output.log and places them in the remotely stored details field without inspection, filtering, size limits, or secret redaction.

Build, installation, and runtime logs can contain bearer tokens, authorization headers, environment values, private registry credentials, internal hostnames, source paths, usernames, package URLs containing credentials, and personal information. A general instruction to obtain consent before storing user content does not adequately address secrets emitted incidentally by tools or third-party processes.

The learning API also accepts a poolId. If diagnostic records are written to a shared pool, the exposure can extend to other agents or pool members permitted to read that pool.

Attack Path

  1. A build or package-management operation writes sensitive information to /tmp/npm-output.log, such as a registr ...[truncated 1044 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to upload complete or raw logs by default.
  2. Extract only the minimum error message, error code, affected component, and sanitized stack frames needed for future diagnosis.
  3. Apply deterministic redaction for API keys, bearer tokens, cookies, passwords, private keys, authenticated URLs, email addresses, and environment-variable values before transmission.
  4. Present the sanitized payload and remote destination to the user for explicit approval before storing it.
  5. Enforce input-size limits and reject binary, excessively large, or malformed logs.
  6. Default diagnostic learnings to private storage and require separate confirmation before assigning a poolId.
  7. Provide deletion and credential-rotation guidance for accidental uploads.
  8. Add tests containing representative secrets to verify that the redaction process removes them before any network request.

T09 · Insecure Skill Coding Practices

Warning
Location
references/commands.md:9
Finding

Arbitrary API Base URL Override Can Redirect Bearer Credentials and Stored Content

Content
View full analysis

Vulnerability Details

File Location: references/commands.md:9-18, references/commands.md:70-73
Vulnerability Type: Unrestricted authenticated endpoint override
Risk Level: Medium

Vulnerable Code

text
| `swarmrecall config set-key <key>` | Set API key. |
| `swarmrecall config set-url <url>` | Override API base URL. |
| `swarmrecall config show` | Print current config. |
text
| `swarmrecall mcp` | Run the MCP server over stdio. Point MCP clients at this command. Reads `SWARMRECALL_API_KEY` / config file for auth. |
text
- `SWARMRECALL_API_KEY` — API key; takes precedence over config file.
- `SWARMRECALL_API_URL` — API base URL; defaults to `https://swarmrecall-api.onrender.com`.

Technical Analysis

The documented configuration supports overriding the API base URL while the same CLI and MCP process reads the SwarmRecall bearer credential. The documentation does not impose a production-host allowlist, require a distinct credential for custom servers, warn users before sending credentials to a changed origin, or state that non-HTTPS endpoints are rejected.

The override is legitimate for custom deployments, but combining an arbitrary destination with an existing production credential creates an unsafe trust-boundary transition. If an attacker can influence setup instructions, environment variables, or the saved configuration, authenticated requests and sensitive memory content may be redirected to a server under the attacker's control.

The static documentation does not establish whether the external CLI validates URLs internally. This finding is therefore limited to the insecure configuration and operational guidance exposed by the audited Skill.

Attack Path

  1. An attacker persuades a user or agent to run swarmrecall config set-url with an attacker-controlled URL, or causes SWARMRECALL_API_URL to be set in the process environment.
  2. The existing ...[truncated 1027 chars]
Remediation
View remediation

Remediation Suggestions

  1. Allowlist the official production origin when a production sr_live_ credential is in use.
  2. Require a separate credential for each custom endpoint and clear the currently configured key whenever the origin changes.
  3. Reject plaintext HTTP and malformed or credential-bearing URLs.
  4. Require explicit user confirmation that displays the destination hostname before saving an endpoint override.
  5. Display the active hostname before the first authenticated write in a session.
  6. Protect configuration files against modification by other local users and document restrictive file permissions.
  7. Warn that SWARMRECALL_API_URL is security-sensitive and should not be accepted from untrusted project files, shell snippets, or inherited environments.
  8. Add CLI tests proving that production credentials are never forwarded to unapproved origins or across redirects.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README promotes persistent memory, shared pools, and background consolidation across sessions but does not clearly warn that data may be stored remotely, retained over time, and shared across agents or tenants according to configuration. For a memory/knowledge service, this omission can cause users to send sensitive or regulated data under incorrect assumptions about locality, ephemerality, or visibility, increasing the risk of privacy violations and accidental data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README embeds live-looking API key and bearer token examples directly in MCP configuration snippets without any accompanying warning about secret handling, rotation, or avoiding commits to dotfiles and project configs. In practice, users often copy these examples verbatim into checked-in config files or shared screenshots, which can lead to credential leakage and unauthorized access to the tenant's persistent memory, knowledge, and collaboration data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill explicitly instructs agents to persist conversational content, preferences, facts, sessions, and learnings to a remote third-party service across sessions. Even though it mentions consent and tenant isolation, this creates a real data-retention/privacy risk because agents may store sensitive or personal information by default, and session persistence expands the blast radius of any accidental over-collection or later misuse.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

swarmrecall register --save swarmrecall memory store "" --category fact --importance 0.8 swarmrecall memory search "" swarmrecall knowledge create --type person --name "Alice" --props '{"role":"engineer"}' swarmrecall learnings log --category error --summary "

" swarmrecall dream start

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file instructs users to store SWARMRECALL_API_KEY, paste an existing key, export it into the shell, and pass it via an MCP env block, but it does not warn that the key is a sensitive credential that should be protected and not shared or committed. Because this file is markdown and directly describes handling credentials, the omission of a privacy/security warning fits the missing user warnings category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow explicitly instructs agents to persist user preferences, decisions, and contextual facts across sessions, but it provides no warning, consent step, retention guidance, or filtering for sensitive data. In a memory-focused skill, that omission is meaningful because agents may store personal or confidential information by default, creating privacy, compliance, and over-collection risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown reference lists memory_delete as a permanent delete but provides no accompanying warning, confirmation expectation, or caution about irreversible data removal. Under the markdown-file criteria, descriptions should warn about behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

knowledge_entity_delete notes that deletion cascades to relations, which can affect multiple records, but the reference provides no caution about this broader impact. For markdown documentation, operations that can remove or alter user data should include clear warnings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

dream_update_config changes system behavior and dream_execute runs cleanup operations including decay, prune, and cleanup, yet the reference contains no caution about operational impact or potential data modification. Markdown skill documentation should disclose behaviors that may affect system integrity or stored data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt instructs users to paste the output of swarmrecall config show, explicitly confirming the presence of an API key and base URL, without warning users not to disclose secrets or to redact sensitive values. In an MCP-enabled client, pasted terminal output may be ingested by the model, logged by the client, or exposed to other tools, creating a real risk of credential leakage even if the key is usually masked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents --save writing the API key to ~/.config/swarmrecall/config.json and set-key setting the API key, but it does not include any caution about storing secrets on disk or exposing them in shell history. Under the markdown-specific warning rule, credential-affecting behavior should be disclosed because it can affect user privacy and system security.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The description says the MCP server reads SWARMRECALL_API_KEY or the config file for auth, implying use of stored credentials and likely communication with the remote API. The command reference lacks any user-facing warning about handling authenticated requests or the privacy implications of sending data to the service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.