Back to skill

Security audit

龙虾记忆大师

Security checks across malware telemetry and agentic risk

Overview

This is a local long-term memory helper that openly creates and maintains memory files, with privacy caveats but no hidden exfiltration or destructive behavior found.

Install this only if you want the assistant to keep local long-term notes. Review the MEMORY.md and memory/ files regularly, avoid storing secrets or highly sensitive personal data, and do not enable cron or autonomous learning examples unless you understand how to inspect and disable the scheduled jobs.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill markets itself as a comprehensive long-term memory and autonomous learning system, but the content only provides templates and a simple archive script. This mismatch is dangerous because users may rely on implied safeguards, retention controls, and retrieval logic that do not actually exist, leading to unsafe deployment and overcollection of data without proper controls.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The activation criteria are extremely broad, covering ordinary questions about prior work, people, dates, or preferences. In a memory skill, that broad trigger surface increases the chance of unintended activation and silent persistence or retrieval of personal data in routine conversations.

Missing User Warnings

High
Confidence
94% confidence
Finding
The skill directs automatic recording of project progress, key decisions, and user preferences without clear notice or consent. Because this is persistent storage of potentially sensitive behavioral and personal data, silent collection creates privacy, compliance, and trust risks.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill describes automatic archiving and file modification behavior but does not clearly warn the user that workspace files will be created and changed. Unannounced writes can alter repositories, expose data in version control, and interfere with normal project files.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The guide directs automatic archiving and cleanup of persistent memory files but does not require user notice, consent, or confirmation before retention or deletion actions. In a memory-management skill, this can cause silent storage of sensitive conversation data and unintended deletion or transformation of records, creating privacy, integrity, and auditability risks.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The workflow includes scheduled automatic archiving, cleanup, and autonomous learning/reporting at fixed times without any privacy warning, authorization boundary, or operational safeguard. Because this skill is explicitly designed to create long-term persistent memory for an assistant, unsupervised background processing increases the chance of collecting, retaining, or surfacing sensitive user information without awareness or control.

Ssd 3

Medium
Confidence
93% confidence
Finding
The skill instructs broad long-term retention of user preferences, project activity, and decisions without clear minimization boundaries. Persistent memory systems are especially sensitive because they aggregate context over time, increasing the blast radius of accidental disclosure or misuse.

Ssd 3

Medium
Confidence
90% confidence
Finding
The working buffer protocol explicitly tells the agent to capture key conversation fragments as context pressure rises. This creates an ongoing retention channel for potentially sensitive user content exactly when users may be sharing large amounts of information, increasing privacy risk.

Ssd 3

Medium
Confidence
91% confidence
Finding
The example template encourages persistent storage of user name, style, and current project in a profile-like memory file. Even as an example, this normalizes collecting identifying and preference data without consent gates or sensitivity checks.

Ssd 3

Medium
Confidence
84% confidence
Finding
The search-and-answer workflow instructs the agent to retrieve prior memory records and cite source file paths and lines in responses. In a persistent memory system, that can expose internal storage structure and leak private historical content more broadly than necessary.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.