Back to skill

Security audit

mnemo-memory

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed cloud-backed agent memory integration, with no hidden or destructive behavior found in the reviewed artifact.

Install only if you are comfortable with agent memories, searches, and related metadata being stored outside the local session in TiDB Cloud or a self-hosted server. Do not store secrets or regulated personal data unless you have reviewed retention, sharing, and access controls; use a dedicated least-privilege database account and prefer pinned or verified package versions where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:125
Finding

Unpinned Third-Party Plugin Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 125 and 158–159
Vulnerability Type: Unpinned and externally hosted third-party dependencies
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md, line 125:

bash
npm install mnemo-openclaw

SKILL.md, lines 158–159:

text
| **Claude Code** | `/plugin marketplace add qiffang/mnemos` → `/plugin install mnemo-memory@mnemos` |
| **OpenCode** | `"plugin": ["mnemo-opencode"]` in `opencode.json` |

Technical Analysis

The installation instructions reference mutable npm packages and a remote plugin marketplace without pinning an exact package version, immutable commit hash, or integrity digest. Consequently, the code installed by a user may differ from the code that was available when this skill documentation was reviewed.

The project contains only SKILL.md; it does not include the source code, lockfiles, checksums, signatures, or software bill of materials for the referenced plugins. The actual runtime behavior of mnemo-openclaw, mnemo-opencode, and mnemo-memory@mnemos therefore cannot be verified from this artifact.

This creates a supply-chain trust boundary. If a package publisher account, npm package, marketplace repository, release process, or dependency is compromised, a subsequent installation could retrieve attacker-controlled plugin code. Because the advertised plugins handle cloud-persistent agent memory and TiDB credentials, compromise could expose particularly sensitive data.

The documented network communication with TiDB Cloud is declared and necessary for the skill's cloud-persistence functionality. No hidden network destination or confirmed credential-exfiltration logic was found in SKILL.md; the risk arises from installing unaudited, mutable external implementations.

Attack Path

  1. An attacker compromises a referenced package, publisher account, marketplace repository, or an upstream dependency.

...[truncated 1348 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every npm plugin to an exact reviewed version, for example:
    bash
    npm install --save-exact mnemo-openclaw@<reviewed-version>
    
  2. Pin marketplace installations to an immutable release tag or commit hash rather than a mutable repository or channel.
  3. Publish and verify cryptographic integrity hashes or signed release attestations before installation.
  4. Include lockfiles and a software bill of materials so direct and transitive dependencies can be reproduced and audited.
  5. Make the referenced plugin source available alongside the skill or link each documented release to the exact audited source revision.
  6. Use automated dependency scanning, provenance verification, and publisher-account protections such as phishing-resistant multi-factor authentication.
  7. Run plugins in a restricted sandbox with only the filesystem, network destinations, and tools required for memory operations.
  8. Use a dedicated least-privilege database account limited to the required memory schema and operations. Do not use administrative TiDB credentials.
  9. Restrict outbound traffic to explicitly approved TiDB or self-hosted server endpoints.
  10. Warn users not to store secrets in agent memory and document credential rotation and revocation procedures for suspected package compromise.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill prominently markets cloud-persistent, shared memory but does not provide a clear user-facing warning that stored memories and search queries/content may leave the local environment, persist across sessions, and be accessible across agents or team contexts depending on configuration. This can cause users or downstream agents to submit sensitive prompts, credentials, internal code, or personal data under the mistaken assumption that the plugin behaves like local ephemeral memory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.