Back to skill

Security audit

Elite Human Memory Hermes

Security checks across malware telemetry and agentic risk

Overview

This memory skill is not clearly malicious, but it appears to automatically store and recall user context in broad ways that need review before installation.

Install only if you intentionally want an agent memory layer. Before enabling it, confirm where memories are stored, whether automatic writes can be disabled, how to review and delete saved memories, and whether sensitive data such as secrets, credentials, health, financial, or private customer details are excluded by default.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger 'the current context feels incomplete or contradictory' is highly subjective and can cause the agent to read memory without a clear user request. In a memory-integrated agent, this increases the chance of unnecessary access to stored personal or sensitive context, creating privacy and data-minimization risks even if the feature is intended to be helpful.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document states that the skill will create the memory structure as needed and describes automatic logging behaviors, but it does not require clear user notice or consent before files are created or written. This can lead to silent persistence of user data, conflict logs, or inferred preferences, which is risky in a memory skill because users may not realize durable records are being generated.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The README states the agent will 'automatically begin using semantic search + metadata filtering when the user references past decisions, preferences, or context,' which is a broad trigger that can activate memory behavior during ordinary conversation without clear user consent. In a memory-oriented skill, this can cause over-collection or retrieval of sensitive context and increase the chance of storing or surfacing unintended personal information.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger "the current context feels incomplete or contradictory" is highly subjective and can cause the agent to read persisted memory without a clear user request or narrowly defined condition. In a memory skill, that broad discretion increases the chance of unnecessary retrieval of sensitive historical user data and weakens privacy boundaries between current-task context and stored context.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The phrase "new long-running context is established" does not define what qualifies for persistence, so the agent may over-collect and store user information based on vague heuristics rather than informed intent. This creates a privacy and data-minimization risk because sensitive or unnecessary details could be written to long-term memory without clear authorization.

Missing User Warnings

High
Confidence
95% confidence
Finding
The skill explicitly supports automatic memory writes and long-term storage of user context, but it does not provide a clear privacy warning, consent model, or disclosure of persistence behavior. In a system designed to accumulate conversational context across sessions, that omission is dangerous because users may unknowingly disclose sensitive information that is then retained, indexed, and later surfaced through retrieval.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.