Back to skill

Security audit

Memory Sync CN

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its memory-sync purpose, but it can copy private memories, daily logs, and an explicit API-keys section into CortexGraph without adequate scoping, filtering, or warnings.

Review and sanitize MEMORY.md and daily logs before using this skill. Do not sync secrets, API keys, credentials, regulated data, or client-private notes; prefer dry-run first, pin and verify cortexgraph/mcporter versions, and back up CortexGraph and MEMORY.md before running gc, consolidation, or promotion commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sync-memory.sh:60
Finding

Sensitive memory sections, including API keys, are synchronized without filtering

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sync-daily.sh:7
Finding

Unvalidated date argument permits path traversal outside the daily-memory directory

Content
View full analysis
Remediation
View remediation
&2 exit 2 fi ``` 2. Validate that the value represents a real calendar date, not merely a matching string. 3. Canonicalize both the base directory and target path with `realpath`. 4. Verify that the canonical target begins with the canonical memory-directory path followed by `/`. 5. Reject arguments containing `/`, `\`, null bytes, or traversal components. 6. Consider enumerating existing daily-log files rather than constructing arbitrary paths from user input. 7. Add tests covering absolute paths, `../` traversal, repeated separators, malformed dates, and symlink-based escapes. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned third-party executables are installed and trusted with private memory

Content
View full analysis
Remediation
View remediation
' npm install -g 'mcporter@' ``` 2. Supply lockfiles and integrity hashes where the package managers support them. 3. Document the expected registry, publisher identity, package homepage, and source repository. 4. Verify package signatures or provenance attestations when available. 5. Avoid global installation where possible; use an isolated, project-specific environment. 6. Review and pin transitive dependencies as well as direct dependencies. 7. Run the tools with restricted filesystem and network access appropriate to local memory storage. 8. Establish a controlled update process that reviews changed releases before modifying pinned versions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The Chinese description explicitly advertises forgetting-curve support and intelligent retrieval, yet the visible content only documents saving/importing and external CortexGraph calls, not actual in-skill recall or decay logic. In a memory-management context, this can cause unsafe assumptions about retention, deletion timing, and what conversational data is being processed or surfaced.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The Chinese description explicitly advertises forgetting-curve support and intelligent retrieval, yet the visible content only documents saving/importing and external CortexGraph calls, not actual in-skill recall or decay logic. In a memory-management context, this can cause unsafe assumptions about retention, deletion timing, and what conversational data is being processed or surfaced.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The Chinese description explicitly advertises forgetting-curve support and intelligent retrieval, yet the visible content only documents saving/importing and external CortexGraph calls, not actual in-skill recall or decay logic. In a memory-management context, this can cause unsafe assumptions about retention, deletion timing, and what conversational data is being processed or surfaced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README advertises automatic bidirectional synchronization between MEMORY.md, CortexGraph, and daily logs, but does not warn users that potentially sensitive memory data may be imported, modified, persisted, or propagated across stores. In an agent skill context, unclear data-flow and write behavior can cause accidental disclosure or unintended modification of personal/project memory, especially when users run shell scripts directly from the documentation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents automatic analysis, memory capture, and recall of user conversation content without any privacy warning, consent guidance, retention notice, or data-sensitivity limits. Because the content being processed is conversational memory, the context makes this more dangerous: users may inadvertently store sensitive personal, corporate, or credential-like information in a long-lived local memory system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes garbage-collection and consolidation commands that can delete or alter stored memories, but it does not clearly warn about irreversible effects, backups, or safe preview-first usage. In a memory store, destructive maintenance can cause permanent data loss or silent corruption of important user information if run casually.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script automatically reads the entire daily log file and sends it to cortexgraph.save_memory, which is an external persistence boundary, without any explicit consent prompt, warning, redaction step, or data classification check. Because daily logs commonly contain sensitive personal notes, credentials, project details, or client data, this creates a real risk of unintended disclosure through normal use rather than an exploit in the classic sense.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions in this file are exclusively in Chinese, and the document does not provide an alternative language or indicate that Chinese is an intentional, justified locale constraint. This can violate language/locale policy when users are not given an explicit language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s natural-language description and operational guidance are entirely in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a skill effectively forces one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This manifest includes a Chinese-only natural-language description, which can indicate a fixed language/locale assumption without offering user opt-in or documenting why the locale is required. Under the policy rule for language/locale constraints, this is a natural-language policy concern because no alternative language choice or region-specific justification is provided in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s comments, prompts, and user-facing output are written entirely in Chinese, which imposes a specific language on users without opt-in. This matches the language/locale policy concern because no alternative language option or justification for a Chinese-only workflow is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline comment on L12 says the script retrieves 'high-score memories' with 'score > 1.5', but the actual mcporter call sets min_score=0.5 on L17. This is an active contradiction between documentation and implemented behavior, which changes the effective scope of what gets considered for promotion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script's descriptive comments and runtime messages are written in Chinese, which imposes a specific language on users without any opt-in or explanation of a region-specific requirement. This can violate language/locale policy when the skill does not provide a choice or document why the locale is fixed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.