T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party Package Is Installed and Executed as an MCP Server
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill is purpose-aligned, but it broadly persists conversation-derived task data and installs an unpinned MCP server package with limited scoping and disclosure.
Review this carefully before installing. Use it only for workspaces where automatic project memory is acceptable, avoid discussing secrets or highly sensitive information while it is active, verify the focalpoint package source and version before installation, and require narrow GitHub permissions if enabling sync.
SKILL.md:12Unpinned Third-Party Package Is Installed and Executed as an MCP Server
SKILL.md:111Unconditional Rules Automatically Persist Conversation-Derived Data Across Sessions
The skill advertises GitHub sync without any warning about repository access, token permissions, or what data may be transmitted between the local memory system and GitHub. Even if the sync is optional, omitting these disclosures can lead users to authorize broader access than intended or expose private repository metadata and task history.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
AI automatically runs heartbeat and finds:
- Deploy task BLOCKED for 4 days
- Docs update STALE — no activity for a week
- Bug fix AT RISK — deadline is tomorrow
The skill explicitly instructs the agent to perform persistent memory actions in every conversation, including bootstrapping at start, creating nodes from user mentions, and appending logs before the conversation ends, but it provides no user-facing notice or consent flow about retention. This creates a real privacy and data-governance risk because users may disclose sensitive project, personal, or business information without understanding it will be stored across sessions.
No suspicious patterns detected.