Back to skill

Security audit

mar-elite-longterm-memory

Security checks for vulnerabilities and agentic risk

Overview

This is a real memory skill, but it recommends broad automatic persistence and third-party processing of conversation data without enough user-facing controls.

Review this carefully before installing. Use it only if you want an agent to keep durable memory, and avoid enabling SkillBoss chat, embedding, or cloud backup for sensitive projects unless you understand exactly what conversation content may leave your machine. Prefer pinned installs, do not store API keys in shell startup files unless necessary, and review or clear saved memory regularly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:115
Finding

Unfiltered Conversation and Memory Data Disclosure to a Third-Party API

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code’s actual behavior is much narrower than the description. It creates and inspects markdown files and directories for a lightweight local memory workflow. Although it mentions LanceDB in output and checks whether a LanceDB directory exists, it does not implement vector search or database operations. There is no WAL logic, git-notes interaction, cloud sync/backup, or assistant integration shown in this chunk. Therefore the declared description materially overstates the implemented capabilities and primary purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cloud backup and auto-extraction sections describe external storage and API processing without a clear warning that conversation data may leave the local environment. This is especially risky in an agent memory skill because users may assume storage is local and bounded.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The command rm -rf ~/.openclaw/memory/lancedb/ irreversibly deletes stored vector memory and is presented as a maintenance action. In agent-assisted contexts, destructive shell snippets are risky because they may be copied or executed automatically without adequate user review.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

md
memory_recall query="*" limit=50

# Clear all vectors (nuclear option)
rm -rf ~/.openclaw/memory/lancedb/
openclaw gateway restart

# Export Git-Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The command rm -rf ~/.openclaw/memory/lancedb/ irreversibly deletes stored vector memory and is presented as a maintenance action. In agent-assisted contexts, destructive shell snippets are risky because they may be copied or executed automatically without adequate user review.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

md
memory_recall query="*" limit=50

# Clear all vectors (nuclear option)
rm -rf ~/.openclaw/memory/lancedb/
openclaw gateway restart

# Export Git-Notes

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

Using npx elite-longterm-memory without pinning a specific version causes users to execute whatever package version is current at install time. For an agent skill that is intended to be run directly in a workspace, a compromised maintainer account, typo-squatted package replacement, or malicious future release could lead to arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command again instructs users to execute an unpinned package via npx, which delegates trust to the latest published artifact. In practice this creates a supply-chain execution path where any malicious or vulnerable new release is immediately pulled and run in local development environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The today example has the same unpinned npx risk: it encourages immediate execution of a mutable remote package in a context with filesystem access. Because this skill is explicitly marketed for persistent memory and workspace integration, exploitation could affect source code, local secrets, or stored conversation history.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promotes automatic fact extraction and optional cloud sync of conversation-derived memory but does not prominently warn that chat content and derived facts may be transmitted to a third-party service. In a long-term memory skill, users may store sensitive prompts, source code, credentials, business decisions, or personal data, so silent or underexplained external transmission creates meaningful confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The README contains code that posts data to https://api.heybossai.com/v1, which is expected functionality for a cloud-backed memory feature, but it still represents external transmission of potentially sensitive conversation data. In the context of an agent memory system, the transmitted payload can include messages, extracted facts, and semantic queries, increasing privacy, data governance, and prompt confidentiality concerns if users are not fully informed.

Content

Scanner excerpt · README.md (reported line 106)May include surrounding context.

javascript
const API_KEY = process.env.SKILLBOSS_API_KEY
const API_BASE = 'https://api.heybossai.com/v1'

async function pilot(body) {
  const r = await fetch(`${API_BASE}/pilot`, {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill requests access to an environment variable (SKILLBOSS_API_KEY) but does not declare an explicit tool scope or allowed-tools boundary. In agent ecosystems, missing scope declarations can cause overly broad execution or ambiguous trust assumptions, especially when the skill also documents external network use.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The 'write before responding' rule establishes default persistence of user input into session state, which is a form of session retention with privacy implications. In context, the danger is higher because the rule is universal and not limited to non-sensitive task metadata.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

  • ...
text

**Rule:** Write BEFORE responding. Triggered by user input, not agent memory.

### Layer 2: WARM STORE (LanceDB Vectors)
**From: lancedb-memory**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The WAL rule tells the agent to save user-provided details before responding, but the skill provides no user-facing privacy notice or consent mechanism. This creates implicit collection of potentially sensitive information simply through normal conversation flow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The documented fetch call targets an external API endpoint, creating a path for data exfiltration from local conversation or memory content to a third party. In a memory skill, external transmission is materially security-relevant because the data is likely to include accumulated context rather than isolated inputs.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

javascript
const API_KEY = process.env.SKILLBOSS_API_KEY
const API_BASE = 'https://api.heybossai.com/v1'

async function pilot(body) {
  const r = await fetch(`${API_BASE}/pilot`, {

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill recommends sending conversation content to an external chat/embedding API for automatic fact extraction, which can expose sensitive user data outside the local memory system. Because the examples encourage broad extraction of facts, preferences, and decisions, users may unknowingly transmit private or proprietary context to a third party.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section directs the system to broadly extract, deduplicate, embed, and retain conversation-derived facts across multiple memory layers, including optional cloud-backed services. Such broad persistence increases privacy risk and the chance of storing sensitive, regulated, or proprietary content without adequate minimization.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This is another external API transmission point for conversation-derived content used in auto-extraction. Repeated network integration amplifies the privacy and confidentiality risk because it normalizes sending memory-related data off-device.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

javascript
const API_KEY = process.env.SKILLBOSS_API_KEY
const API_BASE = 'https://api.heybossai.com/v1'

async function pilot(body) {
  const r = await fetch(`${API_BASE}/pilot`, {

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Persisting SKILLBOSS_API_KEY in shell startup files increases the exposure window of a sensitive credential and may cause it to be inherited by unrelated processes. In shared or compromised environments, that broadens the blast radius if the key is leaked.

Content

Scanner excerpt · SKILL.md (reported line 268)May include surrounding context.

bash
export SKILLBOSS_API_KEY="your-key"
# Add to ~/.zshrc for persistence

Agent Instructions

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The agent instructions require immediate persistence of user details before responding and include storing preferences and decisions as a standard workflow. In context, this creates a broad, default surveillance-style memory pattern rather than selective, user-approved storage.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The example workflow shows a user preference and project decision being copied into multiple persistence layers, including long-term stores. This increases over-collection risk and makes accidental retention or later disclosure more likely.

Content

Scanner excerpt · SKILL.md (reported line 313)May include surrounding context.

md
User: "Let's use Tailwind for this project, not vanilla CSS"

Agent (internal):
1. Write to SESSION-STATE.md: "Decision: Use Tailwind, not vanilla CSS"
2. Store in Git-Notes: decision about CSS framework
3. memory_store: "User prefers Tailwind over vanilla CSS" importance=0.9
4. THEN respond: "Got it — Tailwind it is..."

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The maintenance section includes a destructive rm -rf command to wipe vector memory, but the guide does not provide a strong warning about irreversible data loss. Users or agents could execute it casually and destroy stored memory unintentionally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The later example again uses the same external API, reinforcing that off-platform transmission is part of the recommended design. While not inherently malicious, it becomes dangerous when paired with broad memory capture and absent disclosure.

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

javascript
const API_KEY = process.env.SKILLBOSS_API_KEY
const API_BASE = 'https://api.heybossai.com/v1'

async function pilot(body) {
  const r = await fetch(`${API_BASE}/pilot`, {

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The help text instructs users to run the package via npx elite-longterm-memory without pinning an exact version. npx resolves and executes whatever version is current at runtime, which creates a supply-chain risk if a future release is compromised, typosquatted, or unexpectedly changed. In a developer tool that manages persistent memory and may be run in project directories, this is more dangerous because it can execute with access to local files and developer context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This second help example also recommends invoking the package through unpinned npx, carrying the same risk of executing an unreviewed future package version. Because this skill is positioned as an agent memory system for tools like Cursor, Claude, ChatGPT, and Copilot, users may run it in sensitive repositories, increasing the blast radius of a compromised package.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction to store decisions 'silently' encourages persistence of user-derived data without informing the user. Silent retention weakens informed consent and can cause sensitive project or personal preferences to be recorded unexpectedly.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

The optional dependency mem0ai is specified with a caret range (^1.0.0), allowing newer minor and patch releases to be installed without review. This creates supply-chain risk because a compromised or malicious upstream release could be pulled in automatically, and in the context of an AI memory skill that may handle sensitive context and cloud-backed storage, a dependency compromise could expose stored data or execute unwanted code during installation or runtime.

Content

Scanner excerpt · package.json (reported line 36)May include surrounding context.

json
"typescript"
  ],
  "optionalDependencies": {
    "mem0ai": "^1.0.0"
  },
  "author": "NextFrontierBuilds",
  "license": "MIT",

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
SKILL.md:326