Back to skill

Security audit

Lumetra Engram

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent memory integration, but it can automatically persist user context to Lumetra's hosted service without clear consent or sensitive-data limits.

Review this before installing if your conversations may include personal, confidential, customer, health, financial, or credential-like information. Configure it only if you are comfortable sending selected memories to Lumetra's hosted Engram service, protect the ENGRAM_API_KEY, and prefer explicit user approval before storing sensitive or long-lived memories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly directs the agent to store user facts, decisions, and context in a third-party hosted memory service, but it does not warn about data sharing, retention, or the sensitivity of information being sent off-platform. This creates a real privacy and compliance risk because users or operators may unknowingly transmit personal, confidential, or regulated data to an external service.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The setup instructions require passing an API key as a bearer token to register the hosted MCP service, but they do not include any guidance about protecting that credential or avoiding exposure through shell history, logs, screenshots, or shared config files. While the command itself is common, omission of credential-handling precautions increases the chance of accidental key disclosure and unauthorized access to the memory service.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.