Back to skill

Security audit

Vestige

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate local memory skill, but it may store and resurface personal or project details too automatically for some users.

Install only if you want a local memory layer that can persist preferences, reminders, and project context across sessions. Before using it, verify the ~/bin/vestige binaries, learn how to review and delete stored memories, and avoid storing secrets, credentials, legal, health, financial, or other sensitive information.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match ordinary conversation and can cause the skill to persist data without a clear, explicit user intent to store it. In a cross-session memory skill, accidental ingestion increases privacy risk because incidental preferences, plans, or sensitive details may be retained and later surfaced unexpectedly.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The description emphasizes persistent recall across sessions but does not clearly warn that the skill stores user preferences and conversation-derived information long term. This can undermine informed consent and lead users or operators to disclose sensitive data without realizing it will be retained beyond the current session.

VirusTotal

52/52 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.