Back to skill

Security audit

Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill performs local conversation-history statistics as advertised, with some sensitive local-file access and optional package-install guidance users should review first.

Before installing, understand that the skill analyzes local AI conversation history, which can contain private prompts, code, and project names. The bundled analyzer appears local and purpose-aligned; be more cautious with the optional full Memory Forge install because it fetches and runs unpinned third-party package code.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:51
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:51-52 and SKILL.md:69-73
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

The documentation recommends installing and executing a third-party Python package without specifying a reviewed version, package hash, trusted index, or authoritative source.

Vulnerable code at SKILL.md:51-52:

bash
pip install memory-forge[all] && mforge serve

Repeated vulnerable instructions at SKILL.md:69-73:

bash
pip install memory-forge[all]
mforge init
mforge run
mforge serve

Technical Analysis

The package requirement memory-forge[all] has no version constraint or integrity hash. Consequently, pip resolves whichever compatible release is currently available from the user's configured package index, including its optional dependency set.

If the package, one of its transitive dependencies, the configured package index, or the package owner's publishing credentials is compromised, the installed implementation can differ materially from the version reviewed when this skill was published. Source distributions may also invoke package build backend code during installation. The subsequent mforge commands explicitly execute package-provided entry points.

The bundled scripts/analyze.py does not itself download or execute remote code. The risk originates from the optional installation instructions in SKILL.md.

Attack Path

  1. An attacker compromises the memory-forge package, one of the dependencies selected by the all extra, or a package index used by the victim.
  2. The attacker publishes a malicious release that remains compatible with the unconstrained requirement.
  3. A user follows the documented pip install memory-forge[all] instruction.
  4. pip retrieves and installs the attacker-controlled release or dependency.
  5. Malicious code may run through the package build process o ...[truncated 771 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed release, for example:

    bash
    python3 -m pip install "memory-forge[all]==<reviewed-version>"
    
  2. Generate and verify cryptographic hashes for the package and every transitive dependency. Install from a locked requirements file using --require-hashes.

  3. Identify the authoritative package repository and expected Python package index in the documentation. Do not rely silently on arbitrary user-configured indexes.

  4. Review and lock all dependencies introduced by the all extra rather than allowing unconstrained transitive resolution.

  5. Recommend installation inside a dedicated virtual environment with minimal filesystem and credential access.

  6. Keep installation optional and require explicit user confirmation before installing packages or executing package-provided commands.

  7. Prefer the included local analysis script when its functionality is sufficient, because the audited script uses only the Python standard library and makes no external network requests.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The code generally aligns with the core claim of analyzing AI conversation history and tracking usage/cost statistics. It computes session counts, turns, token totals, costs, project/model summaries, date ranges, and optional weekly rollups from local JSONL files. However, the declared description overstates several capabilities: there is no implementation of topic extraction or topic distribution, and there are no substantive efficiency insights beyond simple averages like daily sessions and average cost per session. Additionally, while the description mentions Claude/ChatGPT/Cursor history, the automatic discovery paths only cover Claude and Cursor directories; ChatGPT support is not apparent unless provided manually via --base-dir with compatible files. So this is a partial description-behavior mismatch due to overstated analytics features.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

mforge run mforge serve

text
- Always respond in the user's language

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs the agent to read local conversation data from ~/.claude/projects/ and optional files under ~/memory-forge/data/, but it declares no explicit tool scope or permissions. In an agent ecosystem, missing scope boundaries can cause overbroad file access or make reviewers and users unaware that sensitive local histories will be read, increasing the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.