Back to skill

Security audit

Memory System

Security checks across malware telemetry and agentic risk

Overview

This memory skill is coherent but asks the agent to persist and summarize broad personal, financial, preference, decision, task, and system-change data with Obsidian archival and limited user-control guidance.

Review this carefully before installing. It is not showing deception or destructive behavior, but it is designed to create long-lived memory and financial summaries across local files and an Obsidian vault. Only use it with workspaces and vaults you intend the agent to read and write, and set explicit rules for what may be recorded, synced, reviewed, redacted, and deleted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases for recording memory are extremely broad and map ordinary conversational statements like preferences, corrections, and decisions into persistent storage. This creates a high risk of collecting sensitive or unintended user data without clear, granular consent, especially because the data is then propagated into multiple files and archives.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill description does not warn users that personal, financial, and behavioral data will be persistently stored and externally synchronized to other locations such as an Obsidian vault. Without prominent disclosure and consent, users may unknowingly expose sensitive information to additional systems, backups, or sync targets.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The Chinese trigger phrases such as '记忆系统', '记忆管理', and '知识提炼' are broad, generic terms that can match ordinary user requests rather than an explicit skill invocation. In an agent environment, this can cause unintended activation of the skill's memory-writing or archival behaviors during normal conversation, which increases the risk of unauthorized persistence or context mixing.

Vague Triggers

Medium
Confidence
88% confidence
Finding
English triggers like 'memory system', 'insight miner', and especially 'wal protocol' are ambiguous and lack clear invocation boundaries. Because these phrases can appear in benign discussion, the skill may activate unexpectedly and apply memory-management workflows to unrelated content, potentially persisting sensitive or irrelevant data.

Ssd 3

Medium
Confidence
93% confidence
Finding
The skill persistently logs broad categories of user-provided data including finances, preferences, decisions, system changes, and to-dos, then promotes that information across WAL, long-term memory, daily logs, and external archival systems. This materially increases the attack surface and privacy risk because sensitive data is duplicated across multiple stores, making over-collection, unauthorized access, and retention errors more likely.

Ssd 3

Medium
Confidence
91% confidence
Finding
The nightly summarization pipeline derives and republishes sensitive financial and activity information into secondary files such as money.md, including net worth, spending trends, asset changes, pending tasks, and inferred signals. Derived summaries can be even more privacy-sensitive than raw logs because they centralize and amplify personal insights, making exposure or misuse more damaging.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.