Back to skill

Security audit

getmem.ai Memory

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate-looking memory skill, but it sends full conversation turns to an external persistent memory service without enough user-facing consent, retention, or deletion guidance.

Review this carefully before installing. Use it only if you trust getmem.ai with conversation memory, have approval to send the relevant data to that service, and can avoid storing secrets, regulated data, or confidential conversations. Confirm how to delete/export memories and consider disabling it for sensitive sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises persistent memory but does not clearly warn users in the description that conversation content is sent to a third-party service and retained indefinitely. In an agent setting, this omission can cause operators to enable the skill without understanding the privacy, data residency, retention, and consent implications of transmitting potentially sensitive prompts and responses off-platform.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The usage example instructs developers to store full user and assistant exchanges indefinitely without any cautionary guardrails. This is dangerous because it normalizes bulk exfiltration of potentially sensitive conversation data to an external memory provider, increasing the risk of privacy violations, over-collection, and long-term exposure if the third-party service or account is compromised.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.