Back to skill

Security audit

Memory Setup

Security checks for vulnerabilities and agentic risk

Overview

The skill is a docs-only memory setup guide, but it recommends continuously indexing memory files and past chats with external embedding providers without enough privacy safeguards.

Review this skill carefully before installing. Use a local provider or memory-only indexing for sensitive environments, avoid indexing secrets or regulated data, and make sure you understand how session transcripts and embeddings can be stored, rebuilt, and deleted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Privacy-Unsafe External Indexing of Session Transcripts

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17-25
Vulnerability Type: External processing of potentially sensitive session data through an insecure default configuration
Risk Level: Medium

Vulnerable Code

json
{
  "memorySearch": {
    "enabled": true,
    "provider": "voyage",
    "sources": ["memory", "sessions"],
    "indexMode": "hot",
    "minScore": 0.3,
    "maxResults": 20
  }
}

Technical Analysis

The recommended configuration enables real-time indexing of persistent memory and past conversation transcripts while selecting Voyage AI as the embedding provider. Using a remote embedding provider generally requires relevant source content to be transmitted to that provider for processing.

Session transcripts may contain personal information, confidential project details, authentication material accidentally pasted into conversations, or other sensitive context. The Skill does not require informed user consent before enabling session indexing, recommend data classification or redaction, explain third-party retention considerations, or limit indexing to curated memory files.

Although the Skill mentions a local provider later in the document, the privacy-preserving option is not the recommended default. This is an insecure configuration practice because it combines broad data collection, continuous indexing, and external processing without sufficient safeguards.

Attack Path

  1. A user follows the Quick Setup instructions without recognizing the privacy implications.
  2. The user enables sources: ["memory", "sessions"], including historical conversation transcripts in the indexing scope.
  3. The indexMode: "hot" setting causes new or updated content to be indexed continuously.
  4. The configured remote provider processes transcript-derived content to generate embeddings.
  5. Sensitive information contained in conversations may consequently leave the local envi ...[truncated 928 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use privacy-preserving defaults:

    json
    {
      "memorySearch": {
        "enabled": true,
        "provider": "local",
        "sources": ["memory"],
        "indexMode": "hot",
        "minScore": 0.3,
        "maxResults": 20
      }
    }
    
  2. Make session-transcript indexing an explicit opt-in rather than including it in the Quick Setup configuration.

  3. Before enabling a remote provider, clearly disclose that indexed content may be transmitted to and processed by a third party.

  4. Require users to review the provider's retention, deletion, regional processing, and model-training policies before activation.

  5. Add filtering and redaction guidance for credentials, access tokens, personal data, financial information, and confidential project material.

  6. Apply data minimization by indexing curated memory content only. Exclude raw sessions unless they are required for a documented use case.

  7. Document procedures for deleting embeddings, rebuilding the index after redaction, and disabling external indexing.

  8. Recommend separate consent and configuration controls for each source so users can independently enable memory and sessions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends external embedding providers such as Voyage AI and OpenAI but does not warn that indexed memory content may be sent to third-party services for embedding generation. Because the indexed sources include long-term memory and past conversations, this can expose sensitive internal notes, personal information, credentials accidentally stored in notes, or confidential business context to external processors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to enable persistent indexing of MEMORY.md files and past session transcripts, which can collect sensitive personal, project, or organizational data across sessions without any privacy notice, retention guidance, or scoping cautions. In this context, the feature is the core purpose of the skill, so the danger is not hidden maliciousness but normalizing broad data capture without informing users of the privacy implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.