Back to skill

Security audit

Memory MCP

Security checks across malware telemetry and agentic risk

Overview

This appears to be a memory skill, but it stores and can share personal conversation-derived data without clear enough consent and sensitivity limits.

Install only if you are comfortable with the skill retaining personal conversation context across sessions. Avoid using it for secrets, credentials, medical, legal, financial, or highly sensitive personal information, and be especially careful with any sharing feature because stored memories may be disclosed to another user or owner.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill is explicitly designed for persistent cross-session storage of memories, persona traits, mood, and relationship data, yet it does not present a clear warning or consent boundary around storing sensitive personal information. In this context, omission is security-relevant because users and agents may persist secrets, health-like emotional data, or interpersonal data without understanding long-term retention and retrieval consequences.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documented `share` capability allows transmitting stored memory content to other users (`toOwnerId`) without any prominent warning about data disclosure, recipient verification, or sensitivity checks. In a memory system that stores natural-language conversation history and persona data, sharing features materially increase the risk of unintended cross-user data leakage.

Ssd 3

Medium
Confidence
96% confidence
Finding
These instructions tell the agent to store conversation content, summaries, extracted entities, and mood over time, which creates a direct natural-language retention and later disclosure risk. Because the skill's purpose is persistent graph-based memory across sessions, broad persistence of raw user and agent messages materially raises the chance that confidential information will be retained, surfaced out of context, or shared unintentionally later.

Ssd 3

Medium
Confidence
95% confidence
Finding
The best-practice section encourages broad extraction from user messages, mood tracking, and end-of-session remembering without sensitivity boundaries or exclusion criteria. In a memory and persona-management skill, this makes the context more dangerous, because the system is optimized to accumulate and reuse personal data over time rather than treat it as ephemeral conversation state.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.