Back to skill

Security audit

Memphis Cli

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly instruction-only, but it asks agents to enable cloud syncing and recurring background messaging with weak scoping and an exposed shared encryption key.

Install only if you already trust this Memphis environment and intend to use its advanced sync and messaging features. Before enabling share-sync, Pinata/IPFS, watchers, recursive ingestion, or daemons, inspect the missing referenced scripts, rotate the published shared key, use scoped credentials, limit watched and ingested paths, and confirm how to stop background processes and remove stored messages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill documents installation of a recurring background daemon and auxiliary messaging scripts that operate outside the core Memphis CLI commands. This expands the attack surface by introducing persistent automation, periodic network activity, and opaque side effects that a user may not expect from a CLI skill description.

Missing User Warnings

High
Confidence
99% confidence
Finding
The documentation exposes a shared static encryption key directly in the skill content, which effectively compromises confidentiality for all users who rely on it. Any party reading the skill can decrypt captured traffic, impersonate peers, or send forged encrypted messages, and the key cannot be considered secret once published.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to upload/download messages through Pinata without clearly warning that message content and metadata leave the host and transit third-party infrastructure. Even if encrypted, metadata exposure, retention, access policies, and operational mistakes can leak sensitive information or violate user expectations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal