Beta Agent Memory

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed long-term memory skill, but it asks agents to store and reuse user conversation details without clear privacy, consent, retention, or deletion controls.

Install only if you intentionally want an agent to remember user context across sessions. Before using it with real users or sensitive information, decide what may be stored, prefer local storage unless remote storage is deliberate, and require clear controls to inspect, delete, disable, and limit saved memories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly promotes persistent storage of conversation episodes, user preferences, and past interactions, but provides no notice about retention, consent, deletion, or privacy boundaries. In a long-term memory system, this omission is security-relevant because sensitive personal data can be accumulated across sessions and reused or exposed in ways the user does not expect.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal