Back to skill

Security audit

Mnemo Cortex

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent, but users should review it because it installs mutable remote code and enables persistent/shared agent memory with limited in-skill privacy and pinning safeguards.

Install only if you are comfortable running this third-party local memory service. Pin and review a specific upstream commit or release before installing, avoid saving credentials or confidential data, keep cross-agent sharing off unless intended, and understand how to inspect and delete the local memory store.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:43
Finding

Unpinned Remote Code Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–52
Vulnerability Type: Unpinned external repository installation and execution
Risk Level: Medium

bash
git clone https://github.com/GuyMannDude/mnemo-cortex.git
cd mnemo-cortex
python -m venv .venv
source .venv/bin/activate           # Windows: .venv\Scripts\activate
pip install -e .

mnemo-cortex init                   # interactive wizard: pick model providers
mnemo-cortex start                  # listens on http://localhost:50001
mnemo-cortex health                 # verify

Technical Analysis

The installation procedure clones the mutable default branch of an external GitHub repository and immediately installs it using pip install -e .. It then executes CLI commands supplied by that installation. The instructions do not pin an immutable commit, verify a release signature or checksum, or require dependency lock-file validation.

Consequently, the effective code executed by users can change after this Skill has been reviewed. A compromise of the upstream repository, its maintainer account, its packaging configuration, or its transitive dependencies could introduce arbitrary code into the installation path. Editable installation also leaves execution tied directly to the cloned working tree, increasing the risk that subsequent modifications affect runtime behavior.

No malicious payload is embedded in the audited file, and compromise of the referenced repository was not established. The vulnerability is the unsafe trust and execution model of the documented installation process.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or a dependency consumed during installation.
  2. The attacker adds malicious behavior to the repository source, Python build configuration, package metadata, CLI entry points, or an unpinned dependency.
  3. A user follows the Skill instructions and clones the mutable de ...[truncated 1260 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the clone to an immutable, reviewed commit hash rather than the repository’s default branch:
    bash
    git clone https://github.com/GuyMannDude/mnemo-cortex.git
    cd mnemo-cortex
    git checkout --detach <reviewed-commit-sha>
    
  2. Publish the expected commit identifier in SKILL.md and update it only after reviewing the corresponding source changes.
  3. Prefer a signed, versioned release artifact and verify its cryptographic signature or SHA-256 checksum before installation.
  4. Require locked Python dependency versions and hash verification, such as a generated requirements file installed with pip install --require-hashes.
  5. Avoid editable installation for routine deployments. Build or obtain a reproducible wheel from the reviewed revision and install that fixed artifact.
  6. Run the service under a dedicated, unprivileged account with access limited to the memory database and required configuration.
  7. Isolate the service where practical using a container or operating-system sandbox, and do not expose its listening port beyond localhost unless authentication and transport protections are configured.
  8. Document a verification process covering the repository revision, release signature, dependency lock state, and artifact checksum before any CLI command is executed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill promotes cross-session persistent memory and later instructs users to save information, but it does not present a clear privacy warning about storing potentially sensitive data locally for future retrieval. Users may unintentionally persist secrets, personal data, or regulated information that can later be exposed through recall, backups, or local compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises that multiple agents on the same machine can share or query each other's memories, but it does not warn users about the privacy and access-boundary implications of shared memory. This can lead to unintended disclosure between agents, projects, or users if shared-memory features are enabled without informed consent and clear isolation expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.