| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability in agentmem, please report it responsibly:
- Do NOT open a public GitHub issue
- Email security concerns to: silas@silasreinagel.com
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Initial assessment: Within 1 week
- Fix timeline: Depends on severity
- Critical: 24-48 hours
- High: 1 week
- Medium: 2 weeks
- Low: Next release
- All data is stored locally in SQLite at
~/.agentmem/memory.db - No data is transmitted to external servers
- Database file permissions follow system defaults
- Agent IDs are validated to prevent path traversal
- JSON inputs are parsed safely
- SQL queries use parameterized statements
- File permissions: Ensure
~/.agentmem/has appropriate permissions (700 recommended) - Sensitive data: Avoid storing secrets, API keys, or PII in agent memory
- Multi-user systems: Each user should use their own database path via
AGENTMEM_DB_PATH
agentmem is designed as a local-first CLI tool. It assumes:
- The user trusts the local filesystem
- The calling agent (AI) has appropriate access controls
- Network security is handled at the application layer (not agentmem's responsibility)
Out of scope:
- Encryption at rest (use filesystem encryption if needed)
- Access control between agents (isolation is by convention via
--user) - Network-based attacks (agentmem has no network functionality)