Memory Hygiene

Security checks across malware telemetry and agentic risk

Overview

This skill is for memory cleanup, but it gives unsafe instructions to erase and repeatedly re-erase the agent's stored memory without clear safeguards.

Review before installing. Use the audit and configuration advice cautiously, but do not run the wipe or cron examples unless you have backed up the memory directory, confirmed exactly what will be reseeded, and know how to disable the scheduled job. Avoid storing secrets or sensitive account details in vector memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill provides destructive deletion instructions for the entire LanceDB memory directory without any explicit confirmation, backup, or recovery warning. In a memory-management skill, deletion is contextually relevant, but presenting it as a simple step increases the chance an agent or user will irreversibly erase stored data by routine use or misunderstanding.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The scheduled cron job automates recurring full memory wipes with no safety guard, approval gate, or backup requirement. Because the task repeats unattended, any mistake in the wipe/reseed process or changes in MEMORY.md can cause silent, repeated data loss and operational degradation over time.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal