Back to skill

Security audit

code-memory-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill’s local code-search purpose is coherent, but it asks users to run unpinned external code and an executable remote model while indexing sensitive repository content.

Install only if you are comfortable running this third-party MCP server with access to the repositories you index. For sensitive code, pin the package and model to reviewed versions, run it with repository-scoped filesystem access, keep SSE bound to localhost, add `code_memory.db*` to `.gitignore`, and avoid indexing unignored secrets.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:178
Finding

Remote Model Code Is Executed Without a Pinned, Vetted Revision

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:35
Finding

Unpinned Third-Party Package Installation Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:125
Finding

Sensitive Repository Content May Be Persisted in an Accidentally Shareable Database

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill metadata installs and launches the MCP server via uvx code-memory without pinning an exact package version or immutable artifact. Because uvx resolves the latest available package at runtime, a future upstream compromise, typosquat, or malicious update could cause arbitrary code execution on the host when the skill is installed or started.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The recommended command uvx code-memory fetches and executes an unpinned package version, creating a supply-chain risk window between review time and execution time. In this skill context, the installed tool is a local MCP server with filesystem access to repositories, so a malicious upstream release could run arbitrary code and access sensitive source code or secrets.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The MCP configuration again references uvx code-memory without version pinning, so routine use of the skill may execute whatever package version is current rather than the reviewed one. This is especially risky because the skill is intended for coding workflows in local Git repositories, giving the server access to potentially proprietary codebases and indexed sensitive content.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.md (reported line 14)May include surrounding context.

md
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Static analysis

No suspicious patterns detected.