Back to skill

Security audit

Memory Vacuum

Security checks across malware telemetry and agentic risk

Overview

This memory-management skill is not malware, but it should be reviewed because it automatically saves and rewrites conversation memory with limited user control.

Install only if you are comfortable with an agent keeping local conversation journals and automatically summarizing or reorganizing memory files. Prefer a version that asks before writing or compressing, limits what gets saved, excludes sensitive content, and provides review, deletion, and restore controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The listing advertises automatic sharding and semantic compression of memory files, but it does not clearly warn users that the skill will modify, reorganize, and compress persisted memory data. That omission is risky because users may install it expecting passive optimization, while the skill can make irreversible or hard-to-audit changes to stored context and potentially affect recall, integrity, or forensic traceability of memory data.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The listing explicitly promises automatic compression, deduplication, and reorganization of memory files, but it does not clearly warn users that the skill will modify local persistent data and may change how historical information is stored or retrieved. For a memory-management skill, silent mutation of user data is risky because users may assume optimization is lossless, while compression or restructuring can affect traceability, recovery, and trust in stored history.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manual trigger phrases are generic natural-language commands such as '整理一下记忆' and '检查记忆有没有重复', which could easily appear in ordinary conversation without a clear, scoped invocation. In a memory-management skill, unintended activation is especially risky because it could cause automatic archival, compression, deduplication, or modification of user memory state when the user may only be discussing memory conceptually rather than requesting the skill to act.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description uses broad triggers like '内存、清理、整理记忆、减轻负担等场景', which can match ordinary conversation rather than an explicit user request to manage stored memory. That increases the chance the skill activates unexpectedly and writes or modifies memory files without clear user intent, creating privacy and consent risks.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill states that every message is appended to a dated memory file, but it does not present a clear user-facing warning or consent mechanism before automatic persistence begins. This is dangerous because routine conversation data may be stored by default, including sensitive personal or confidential information the user did not expect to be written to disk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The automatic compression behavior modifies MEMORY.md before each session, merges duplicates, rewrites long entries, and compresses older material without clearly warning the user that stored content will be transformed. This can silently alter records, reduce fidelity of important information, and create integrity and transparency issues for any workflow relying on accurate memory retention.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.