Back to skill

Security audit

Mem0 Memory Manager

Security checks across malware telemetry and agentic risk

Overview

This skill does what it advertises: it helps users store, review, export, and delete Mem0-backed long-term memory, but users should treat that memory as sensitive.

Install this only if you are comfortable storing personal and work context with Mem0. Do not enter secrets, credentials, regulated data, private customer information, or highly confidential employer details. Use the review and delete workflows regularly to remove anything you do not want retained.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly collects and persistently stores personal profile data such as identity, employer, communication preferences, rules, and project details across sessions, but it does not present a clear privacy warning or informed-consent notice before doing so. This creates a real privacy risk because users may disclose sensitive personal or workplace information without understanding retention scope, sharing boundaries, or how to avoid storing confidential data.

VirusTotal

49/49 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.