Skip to content

Security: SilasReinagel/agentmem

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
0.1.x ✅

Reporting a Vulnerability

If you discover a security vulnerability in agentmem, please report it responsibly:

  1. Do NOT open a public GitHub issue
  2. Email security concerns to: silas@silasreinagel.com
  3. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours
  • Initial assessment: Within 1 week
  • Fix timeline: Depends on severity
    • Critical: 24-48 hours
    • High: 1 week
    • Medium: 2 weeks
    • Low: Next release

Security Considerations

Data Storage

  • All data is stored locally in SQLite at ~/.agentmem/memory.db
  • No data is transmitted to external servers
  • Database file permissions follow system defaults

Input Validation

  • Agent IDs are validated to prevent path traversal
  • JSON inputs are parsed safely
  • SQL queries use parameterized statements

Recommendations

  1. File permissions: Ensure ~/.agentmem/ has appropriate permissions (700 recommended)
  2. Sensitive data: Avoid storing secrets, API keys, or PII in agent memory
  3. Multi-user systems: Each user should use their own database path via AGENTMEM_DB_PATH

Threat Model

agentmem is designed as a local-first CLI tool. It assumes:

  • The user trusts the local filesystem
  • The calling agent (AI) has appropriate access controls
  • Network security is handled at the application layer (not agentmem's responsibility)

Out of scope:

  • Encryption at rest (use filesystem encryption if needed)
  • Access control between agents (isolation is by convention via --user)
  • Network-based attacks (agentmem has no network functionality)

There aren't any published security advisories