Back to skill

Security audit

Claude Memory Pro

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned but asks the agent to persist user and project context across sessions without clear consent, retention, or deletion controls.

Review this skill carefully before installing. Use it only if you are comfortable with an agent retaining user and project context across sessions, and avoid sharing secrets, credentials, regulated data, or sensitive customer information unless the skill provides clear controls to inspect, delete, and limit stored memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs persistent cross-session storage of user, project, feedback, and reference data, but does not require user consent, disclosure, retention limits, or sensitivity filtering. That creates a real privacy and data-governance risk because operators may store personal preferences, project details, or external system pointers across sessions without the user understanding what is retained.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.