Back to skill

Security audit

Memory Store

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local memory tool, but private-memory records can be copied into shared summary and index files, so it needs review before installation.

Install only if you are comfortable with a local plaintext memory store. Do not store secrets, credentials, tokens, or sensitive personal data, and treat private visibility as convenience filtering rather than confidentiality. Pin npm package versions for operational installs and review permissions on the memory-store directories.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/memory_cli.js:348
Finding

Private Memory Content Leaks Through Unfiltered Summary and Index Files

Content
View full analysis

Vulnerability Details

File Location: scripts/memory_cli.js, lines 348–353 and 368–418
Vulnerability Type: Private-data exposure through derived artifacts
Risk Level: Medium

Vulnerable Code

js
function saveMemories(storePath, memories) {
  ensureStoreDir(storePath);
  const memFile = path.join(storePath, "memories.json");
  atomicWriteJson(memFile, memories);
  rebuildIndex(storePath, memories);
  updateSummary(storePath, memories);
}
js
/** Maintain SUMMARY.md — a human/agent-readable snapshot of top memories. */
function updateSummary(storePath, memories) {
  if (!memories || memories.length === 0) {
    fs.writeFileSync(path.join(storePath, "SUMMARY.md"),
      "# Memory Store Summary\n\n_No memories yet._\n", "utf8");
    return;
  }

  // Rank: composite score descending, take top 10
  const ranked = memories
    .filter((m) => m.status !== "archived")
    .map((m) => ({ mem: m, score: summaryScore(m) }))
    .sort((a, b) => b.score - a.score)
    .slice(0, 10);

  const lines = [];
  lines.push("# Memory Store Summary\n");
  lines.push(`_Last updated: ${nowISO()}_\n`);
  lines.push(`Total memories: ${memories.length} | Showing top ${ranked.length}\n`);
  lines.push("---\n");

  for (const { mem, score } of ranked) {
    const icon = TYPE_ICON[mem.type] || "📄";
    const p = mem.priority || "P2";
    const imp = mem.importance || "—";
    const scope = mem.scope === "workspace" ? "📁" : "🌐";
    lines.push(`### ${icon} ${mem.type}: ${mem.title}`);
    lines.push(`**Priority:** ${p} · **Importance:** ${imp} · **Scope:** ${scope} ${mem.scope || "global"}`);
    if (mem.summary) lines.push(mem.summary);
    if (mem.tags && mem.tags.length) lines.push(`\`tags: ${mem.tags.join(", ")}\``);
    lines.push("");
  }

  lines.push("---\n");
  lines.push("_Run `memory-store search --query \"...\"` for full-text search._\n");

  fs.writeFileSync(path.join(storePath, "SUMMARY.md"), lines.join("\n"), "utf8");
}

function rebuildIndex(s
...[truncated 2840 chars]
Remediation
View remediation

Remediation Suggestions

  1. Exclude private records from shared derived artifacts:
js
const publicMemories = memories.filter(
  (memory) => memory.visibility !== "private"
);

rebuildIndex(storePath, publicMemories);
updateSummary(storePath, publicMemories);
  1. If private summaries and indexes are required, generate separate per-agent artifacts. Use sanitized Agent identifiers, assign explicit ownership metadata, and ensure that only the matching identity can select them through the CLI.

  2. Do not place private titles, summaries, details, tags, identifiers, or metadata in any shared index. Indexing only identifiers is insufficient if associated tokens reveal the underlying content.

  3. Create global memory directories with mode 0700 and memory, archive, summary, index, configuration, and temporary files with mode 0600. Verify existing objects and safely tighten overly broad permissions where supported.

  4. Preserve restrictive permissions during atomic replacement by creating the temporary file with mode 0600 and validating the final file mode after renameSync().

  5. Add regression tests that store distinctive marker strings in private titles, summaries, details, and tags, then assert that none appear in shared SUMMARY.md or memories.index.json.

  6. Add tests covering mixed public and private records, global and workspace stores, updates, merges, recalls that modify access counters, archive operations, and migration paths because each may trigger derived-artifact regeneration.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (91)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是“记忆管理”运行时能力:依据用户请求和策略访问/持久化跨会话记忆,强调 off/explicit 模式下不得自动访问或保存记忆。但实际代码并不实现记忆读取、保存、回忆或查询逻辑;它是一个安装器,主要作用是检测 Claude、Codex、Gemini 等 agent 的目录,复制技能工件,执行更新/校验,并写入一个本地配置文件来设置 memory profile。虽然写入 memory profile 与声明主题有关,但整体主功能与声明明显不同,属于安装与配置管理而非记忆管理本身。因此描述不能准确代表该代码块的实际行为。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about runtime memory management behavior: accessing, persisting, and recalling structured cross-session memory subject to explicit user intent and memory policy restrictions. The supplied code does not implement memory read/write/query behavior or policy checks. Instead, it implements an update command that syncs existing installations by calling an installer with a --update flag, exposes CLI help text, and handles update failures. This is a materially different primary purpose and introduces undeclared capabilities around package installation maintenance and file synchronization.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向用户记忆管理的技能:根据策略读取、持久化、回忆和查询跨会话记忆。实际代码并未实现这类记忆管理逻辑,而是一个测试脚本,主要验证安装器和更新器的合同:参数解析、目标路径选择、文件复制与校验、更新检测、包发布内容、版本输出,以及配置文件初始化约束。虽然测试中涉及“memory profile”和“.memory-store/config.json”,这只是安装/配置层面的验证,不是执行用户记忆的保存、回忆或查询。因此代码的主要目的与声明严重不符,属于明显的描述—行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is about managing structured user memory with policy-gated access and persistence. The actual code does nothing related to memory storage, recall, policy checking, user-triggered persistence, or cross-session data handling. Instead, it reads local repository files (.github/workflows/publish.yml and package.json) and asserts that the release pipeline is configured correctly for npm publication. This is a materially different primary purpose and accesses unrelated resources, so it is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个“结构化记忆管理”能力,核心应涉及记忆策略读取、记忆持久化、回忆/查询历史内容,以及根据 explicit/off/balanced/proactive 模式决定是否访问记忆。实际代码完全没有任何记忆相关逻辑,也不处理用户输入、会话历史、多 Agent 数据或持久化存储。相反,它只是读取 package.json 和若干脚本文件,执行断言以确保包不包含自动 postinstall 行为、公开 SECURITY.md,并且生产脚本不调用子进程。这属于安全测试/合规检查,其主要目的、访问资源和触发方式都与声明明显不一致。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
node scripts/memory_cli.js mode --json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
node scripts/memory_cli.js mode --json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
node scripts/memory_cli.js mode --json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
node scripts/memory_cli.js mode --json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
node scripts/memory_cli.js mode --json

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/cli.md (reported line 34)May include surrounding context.

md
memory-store-update --dry-run        Preview without changing files

This command copies files from the currently installed npm package. It does not
download or execute remote code, create new Agent installations, or modify memory data.

To update to the latest published package first:
  npm i memory-store-skill@latest

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/update.js (reported line 18)May include surrounding context.

js
memory-store-update --dry-run        Preview without changing files

This command copies files from the currently installed npm package. It does not
download or execute remote code, create new Agent installations, or modify memory data.

To update to the latest published package first:
  npm i memory-store-skill@latest

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The cheatsheet instructs users to run npx memory-store without a pinned version, which can fetch and execute whatever package version is current at execution time. In a security-sensitive agent skill context, this creates a supply-chain risk: a compromised or malicious future release could be executed directly from documentation-driven user behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The documentation states that setup does not modify agent directories, yet nearby examples show setup --agent ... and setup --sync, which strongly imply configuration changes. This mismatch can mislead operators into running commands with side effects they did not expect, undermining informed consent and potentially altering agent configuration or trust settings.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The cheatsheet advertises legacy commands like archive, restore, merge, and migrate, which exceed the stated purpose of a constrained memory-store skill. Broad undocumented or legacy functionality increases attack surface and can enable destructive or out-of-scope data operations, especially if users or agents rely on the cheatsheet as authoritative guidance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation instructs users to run npx memory-store without a pinned package version. npx may resolve and execute whatever version is currently published or otherwise selected at runtime, which creates supply-chain risk and undermines reproducibility. In an agent skill/install context, that can lead to execution of unexpected code during setup or mode changes if the upstream package is compromised or changed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This example uses npx memory-store setup --sync without pinning a version. That allows runtime retrieval/execution of an unpinned package version, exposing users to accidental or malicious upstream changes and making installations non-reproducible. Because this command is presented as an update path, it may be routinely re-run and increase exposure to a compromised release.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The FAQ shows npx memory-store mode with no explicit version. Unpinned npx execution can fetch or select a newer or compromised package than the one the user expects, enabling supply-chain attacks or inconsistent behavior. In an agent ecosystem, even administrative/status commands deserve version pinning because they normalize unsafe execution patterns.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command uses npx memory-store mode balanced --global without a pinned version, so execution depends on mutable upstream package state. If the package namespace or release stream is compromised, users may run attacker-controlled code while changing configuration. The surrounding skill context makes this more relevant because these are copy-pastable operational commands intended for real use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The example npx memory-store mode explicit --workspace executes an unpinned package version. That increases supply-chain exposure because users may unknowingly run altered package contents at command time, especially in fresh environments or CI-like contexts. Documentation examples materially influence operator behavior, so this is a genuine issue rather than a purely theoretical concern.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This unpinned npx memory-store mode --reset --workspace example has the same supply-chain weakness: the package resolved at execution time may not be the reviewed one. An attacker who compromises the package or publishing pipeline could gain code execution on user systems. The file's context does not include overtly malicious behavior, but it does normalize a risky package execution practice in operational docs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx memory-store without a pinned version, which can fetch and execute whatever version is current on the npm registry at invocation time. If the package is compromised, typosquatted, unpublished/replaced in a dependency-confusion style workflow, or a new malicious version is published, users may execute attacker-controlled code from documentation alone.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example uses npx memory-store version without version pinning, causing runtime resolution of the package from npm instead of a fixed reviewed artifact. Documentation-driven execution paths are high leverage because users often copy-paste them verbatim, making supply-chain compromise practical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx memory-store setup --list is unpinned and may execute a different package version than the one reviewed or intended. In a package compromise scenario, setup-related commands are especially sensitive because they can modify agent integration paths and local configuration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This unpinned npx memory-store setup --agent codex invocation can download and execute the latest registry version at the time of use. Because it performs installation/setup actions, exploitation could lead to persistence or tampering with agent skill directories.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/cli_experience_contract.js:21

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/config_contract.js:21

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/install_contract.js:33

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/smoke.js:29