Back to skill

Security audit

Agent Memory Manager

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local memory skill, but it needs review because it persistently stores sensitive client and business data, broadly reloads it across sessions, and treats removal requests as archiving rather than deletion.

Install only if you are comfortable with long-term local storage of client, project, trade, and knowledge records. Before using it with personal or confidential data, add clear retention and deletion procedures, avoid storing credentials/payment data/raw sensitive messages, treat recalled memory as untrusted reference material, and do not use archive as proof that someone was forgotten.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:379
Finding

Persistent Untrusted Content Can Poison Future Agent Sessions

Content
View full analysis
MAX_FILE_SI ...[truncated 2865 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
memory_manager.py:477
Finding

The Documented Forget Operation Archives Personal Data Instead of Deleting It

Content
View full analysis
90 days closed) → Project completed and archived Command: python3 /workspace/memory/scripts/memory_manager.py archive \ --domain clients \ --id "jean-dupont" ``` It also states: ```text ✅ Follow GDPR principle: if contact asks to be forgotten → archive + flag ``` The implementation only moves the record into an archive: ```python def op_archive(domain: str, record_id: str): """Archive a record (move to archived/).""" record_id = slugify(record_id) src = record_path(domain, record_id) dest = record_path(domain, record_id, archived=True) if not src.exists(): print(f"❌ Not found: {domain}/{record_id}") sys.exit(1) dest.parent.mkdir(parents=True, exist_ok=True) shutil.move(str(src), str(dest)) # Update index idx = load_index() idx["counts"][domain] = len(list(domain_path(domain).glob("*.json"))) for lst_key in ["hot_leads", "active_trades", "active_projects"]: if record_id in idx.get(lst_key, []): idx[lst_key].remove(record_id) save_index(idx) audit(f"Memory archived: {domain}/{record_id}") print(f"✅ Archived: {domain}/{record_id} → {domain}/archived/") ``` Archived records remain retrievable because `op_recall` checks the archive when an active record is absent: ```python if not path.exists(): # Check archived archived = record_path(domain, record_id, archived=True) if archived.exists(): print(f"ℹ️ Record '{record_id}' is archived.") path = archived ``` ### Tech ...[truncated 1657 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
memory_manager.py:362
Finding

User-Controlled Update Values Are Persisted in the Audit Log

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes persistent storage of sensitive categories of information including client records, trades, projects, and accumulated knowledge, but provides no privacy, retention, consent, access control, or data handling warnings. In a memory skill specifically designed to preserve context across sessions, this omission increases the chance that users or downstream agents will store personal, confidential, or regulated data indefinitely without safeguards.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares broad filesystem read/write behavior in metadata but does not define an explicit tool permission scope such as allowed-tools or equivalent runtime constraints. That creates ambiguity between documented intent and enforceable access, increasing the chance the agent can persist or modify memory files without clear sandbox boundaries or operator review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes persistent storage of client profiles, interactions, preferences, and trade history but does not provide a clear user-facing warning about retention, consent, or privacy consequences. This can lead operators to store personal or sensitive business information without understanding the long-term persistence and compliance implications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automatic remember triggers are very broad, covering nearly any interaction, decision, lesson, or insight. In practice this can cause over-collection and persistence of sensitive or low-quality data without validation, minimization, or explicit user approval.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The session-start protocol instructs the agent to always read memory first and inspect multiple categories of stored data on every session. This unconditional access increases unnecessary exposure of persistent data, can violate least-privilege principles, and may retrieve unrelated sensitive records when the current task does not require them.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill says a contact asking to be forgotten should be 'archive + flag', while the forget operation claims removal or archival of outdated memory. Archiving personal data after a deletion request can directly violate privacy expectations and regulatory obligations because the data is retained rather than deleted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill persistently stores client, project, trade, and knowledge records under /workspace/memory and also logs activity to audit files, but it provides no user consent flow, warning, retention controls, or data-classification guardrails. In an agent context, this increases the risk that sensitive or regulated information is silently written to disk and retained across sessions, exposing it to later unauthorized access, over-collection, or accidental reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The archive operation performs a state-changing filesystem move that alters where records are stored and removes them from active indexes, yet the command offers no confirmation, dry-run mode, or warning about the operational impact. In an agent workflow, this can cause accidental loss of visibility or workflow disruption if records are archived unintentionally, especially because archived records are excluded from normal active listings and stats.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The example client schema hard-codes a language preference of "French" in natural-language content. While presented as an example, the file does not indicate that language and locale should be user-selected or optional, which can imply a fixed locale preference without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.