Back to skill

Security audit

Grantai Memory

Security checks for vulnerabilities and agentic risk

Overview

This memory skill has a coherent purpose, but it asks users to enable persistent, broad recall of files, project history, and raw conversation text without enough scoping, consent, or retention controls.

Review this before installing. It may be useful if you intentionally want local long-term agent memory, but avoid importing directories, git history, or raw conversations that may contain secrets, credentials, client data, personal data, or proprietary code unless you have verified where the data is stored, how to exclude sensitive files, and how to review and delete retained memory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context Leakage

High
Category
Data Exfiltration
Confidence
94% confidence
Finding

A tool explicitly designed to capture conversation turns verbatim creates a direct context-leakage channel from ephemeral agent interactions into persistent storage. In this skill's context, the danger is elevated because the whole product is optimized for cross-session recall, making accidental persistence and later resurfacing of sensitive prompts, secrets, or internal discussions more likely.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
| `grantai_summarize` | Save session summaries |
| `grantai_project` | Track project state across sessions |
| `grantai_snippet` | Store code snippets with context |
| `grantai_capture` | Capture conversation turns verbatim |
| `grantai_git` | Import git commit history |
| `grantai_health` | Check memory system status |
| `grantai_savings` | View token savings statistics |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill prominently advertises long-term cross-session memory but does not pair that claim with a clear warning that conversation and project data may be persistently stored. This is dangerous because users may disclose secrets, credentials, internal code, or personal data under the assumption that the agent's working context is ephemeral.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Describing the feature as 'automatic activation' without clearly defining when it triggers can cause users to unknowingly enable persistent memory behaviors. In an agent environment, ambiguous invocation semantics increase the risk of unintentional collection, retention, or use of sensitive project and conversation data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation asserts that data is '100% local' and 'never leaves your machine' while also instructing users to run a container image pulled from a remote registry. Even if the runtime behavior is local after download, this wording is materially misleading because it obscures the trust boundary and supply-chain dependency introduced by a third-party image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Encouraging users to 'Learn the src/ directory' without warning about sensitive local data ingestion can lead to bulk import of secrets, API keys, proprietary code, environment files, or regulated data into persistent memory. Because the skill's purpose is long-term retention and recall, accidental ingestion becomes materially more dangerous than a transient file read.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Documenting verbatim capture of conversation turns without a strong privacy warning creates a significant risk of retaining credentials, personal data, client information, or confidential operational details exactly as entered. Verbatim retention is especially sensitive because it preserves raw secrets and context that summaries might otherwise omit.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.