Back to skill

Security audit

EngramClaw

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local memory skill, but it needs review because it encourages broad persistent storage of prompts, session details, and user behavior patterns without tight consent or retention boundaries.

Install only if you intentionally want an agent to keep local cross-session memory. Before use, set strict rules: project-scoped technical notes only, no raw prompts, no secrets or personal data, redact before saving, require user approval for behavioral preferences, and regularly review or delete the Engram database.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill presents Engram as a technical memory system, but later instructs storing user behavior patterns to drive future proactive behavior. This broadens collection beyond technical context into behavioral profiling, increasing privacy risk and making operators more likely to persist user data without clear consent or minimization.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The documentation is internally inconsistent about whether Engram should store user preferences and behavior, which can cause agents to persist personal information in the wrong store. Ambiguity in a memory skill is dangerous because it leads to over-collection and weak privacy boundaries across systems.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger condition is overly broad: invoking memory search whenever the user says "recuerda/remember" can be activated during ordinary conversation rather than a deliberate request to access persistent memory. In a persistence skill, ambiguous invocation increases the chance of unnecessary retrieval or storage of prior context, which can surface sensitive project or user information unexpectedly.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README promotes persistent storage of bugfixes, decisions, configurations, and project context without clearly warning about privacy, sensitive data handling, or retention boundaries. Because this skill is specifically designed to preserve information across sessions, missing privacy guidance makes accidental long-term storage of secrets, personal data, or confidential project details more likely.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation explicitly instructs saving user prompts and session summaries to persistent storage, yet provides no warning about privacy, consent, retention, or sensitive-data handling. In a memory system for AI agents, this increases the chance that secrets, personal data, credentials, or regulated information are stored indefinitely and later retrieved or exposed beyond user expectations.

Ssd 3

Medium
Confidence
88% confidence
Finding
The skill directs the agent to save session summaries, instructions, discoveries, and relevant files, which can easily include user preferences and sensitive session details without strict minimization boundaries. Persistent cross-session storage of such data increases privacy exposure and may retain more personal information than necessary for the stated purpose.

Ssd 3

Medium
Confidence
96% confidence
Finding
This section explicitly encourages saving user behavior patterns so another proactive component can anticipate future needs. That creates durable behavioral profiling from conversation history, which is more sensitive than ordinary technical memory and can be misused or retained indefinitely.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.