Back to skill

Security audit

fulcra-memory

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent memory-sync purpose, but it uploads persistent agent and user context to Fulcra and runs an unpinned external CLI for authentication, uploads, and deletion.

Review this skill before installing if you would not want an agent to persist work summaries, decisions, links, preferences, or task context to Fulcra. Use a pinned and trusted fulcra-api installation, limit Fulcra credentials to the intended agent namespace, require explicit user approval for sensitive memory uploads, and verify archive success before allowing inbox deletion.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/fulcra-memory-cli.md:12
Finding

Unpinned Third-Party CLI Is Dynamically Resolved and Executed

Content
View full analysis
--poll-timeout=5` (after user finishes flow) ``` `references/fulcra-memory-cli.md:21`: ```bash uv tool run fulcra-api data-updates "1 day" ``` `references/fulcra-memory-cli.md:86-88`: ```bash uv tool run fulcra-api file upload memory/progress.md "agent//progress.md" uv tool run fulcra-api file upload memory/log.md "agent//log.md" uv tool run fulcra-api file upload memory/index.md "agent//index.md" ``` `references/fulcra-memory-cli.md:95, 110, 127-128, 140, 147`: ```bash uv tool run fulcra-api file upload memory/role.md "agent//role.md" uv tool run fulcra-api file upload memory/session/20260623-180530_setup-dashboard.md "agent//session/20260623-180530_setup-dashboard.md" uv tool run fulcra-api file upload memory/task/setup-dashboard.md "agent//task/setup-dashboard.md" uv tool run fulcra-api file upload memory/task/index.md "agent//task/index.md" uv tool run fulcra-api file upload memory/archive/20260624-153000_todo.md "agent//archive/20260624-153000_todo.md" uv tool run fulcra-api file delete "agent//inbox/todo.md" ``` ### Technical Analysis The skill repeatedly instructs the agent to execute `fulcra-api` through `uv tool run` without specifying an exact, audite ...[truncated 2520 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill instructs agents to invoke uv tool run fulcra-api without pinning a specific package version or immutable source. That creates a supply-chain risk: a future malicious or compromised release of fulcra-api could be fetched and executed automatically in the agent workflow, especially because this command is presented as a recommended operational step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill directs agents to create and upload persistent session, task, and knowledge files containing summaries, decisions, links, and user preferences, but it does not provide clear user-consent, retention, visibility, or boundary guidance for storing user-related context. Although it includes a privacy warning for progress.md, that safeguard is narrower than the broader storage behavior encouraged in session/, task/, and knowledge/, which can lead to unintended retention or exposure of sensitive user information.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs agents to execute uv tool run fulcra-api without pinning a specific package version or artifact digest. This allows whatever version is current in the package source at execution time to run with the agent's privileges, creating a supply-chain risk where a compromised or incompatible release could exfiltrate data or alter behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The login polling command invokes an unpinned fulcra-api package, so the authentication flow depends on whatever code is resolved at runtime. Because this command handles authentication state, a malicious upstream update could capture device codes, tokens, or redirect users through a hostile flow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The data-updates command references fulcra-api without version pinning, exposing the agent to execution of unreviewed upstream changes. Even though this is a read-oriented operation, it still executes external code that could read local context or leak queried metadata.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill directs the agent to persist summaries of recent work, plans, logs, session context, and task state to an external system, which creates a data-retention and exfiltration surface. Although it says not to include chain-of-thought, the routine persistence of operational context can still capture sensitive user data, secrets, or internal project details if not carefully filtered.

Content

Scanner excerpt · references/fulcra-memory-cli.md (reported line 49)May include surrounding context.

To keep the agent's memory in sync, generate a progress.md summary, ensure OKF files are updated, and upload them to Fulcra.

Step A: Create Progress Report and OKF Files Generate a concise markdown file summarizing the work you have recently completed and what you plan to do next. It must include OKF YAML frontmatter. Do not include internal state or chain-of-thought. Also ensure index.md and log.md are created or updated.

bash

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This upload command runs an unpinned external CLI to handle local file contents and remote transfer. A compromised or changed fulcra-api release could tamper with uploaded memory files, silently exfiltrate additional workspace data, or write to unexpected remote paths.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The log upload uses a non-pinned package invocation, which makes execution non-reproducible and vulnerable to supply-chain compromise. Since logs may contain sensitive operational history, malicious CLI behavior could leak or modify that data during transfer.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The index upload command relies on a latest-resolved external tool rather than a fixed version. That means a package compromise or unexpected update can execute arbitrary code in the agent environment whenever synchronization runs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

Uploading role.md through an unpinned CLI introduces supply-chain risk in a path specifically related to agent identity and procedures. If the tool is compromised, it could alter role definitions, leak policy data, or manipulate instructions that affect future agent behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The session summary upload command invokes unpinned external code to process potentially sensitive context and decisions. This can expose confidential session content to a malicious package update or cause unauthorized remote writes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This task file upload uses an unpinned package invocation, so the behavior of the synchronization path can change without review. Because task files may summarize ongoing work and artifacts, compromise could leak sensitive planning data or modify records.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The task index upload similarly executes an unpinned external CLI, creating a repeatable supply-chain exposure in routine workflow steps. Frequent execution increases the chance that an upstream compromise will be triggered in practice.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Archiving inbox content via an unpinned upload tool is dangerous because the files may originate from users or external triggers and could be sensitive. A compromised CLI could exfiltrate archived content, alter filenames, or mishandle remote storage paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs deletion of inbox content after archiving but provides no warning, verification step, or recovery guidance for this destructive action. In an automated agent context, that increases the risk of accidental data loss, premature deletion before successful archival, or deletion of the wrong item due to path mistakes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The delete command executes an unpinned external package for a destructive action, combining supply-chain risk with the ability to remove data remotely. If the package or dependency resolution is compromised, it could delete arbitrary inbox items or additional remote files under the agent's namespace.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.