Back to skill

Security audit

MyMemory.bot

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward cloud memory connector, but users should understand that saved memories go to ctxly.app and persist there.

Install this only if you want an external service to retain selected agent context across sessions. Do not store secrets, regulated data, or sensitive personal information; protect the CTXLY_API_KEY; periodically review stored memories; and require human approval before any public tweet-based verification.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill prominently advertises persistent cloud memory and provides direct API examples, but it does not clearly warn users that context and memory contents are transmitted to a third-party remote service. In an agent setting, this can lead to unintentional exfiltration of user data, conversation context, or sensitive operational details if the skill is used without explicit user awareness and consent.

Missing User Warnings

Low
Confidence
87% confidence
Finding
The documentation exposes a DELETE endpoint for removing memories but does not warn that deletion may be irreversible. In a memory skill, operators may trigger deletion without understanding that important context could be permanently lost, causing integrity and availability issues for agent memory.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.