Back to skill

Security audit

synapcores-memory

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently provides manual long-term memory using a user-run local SynapCores database, with the main risk being deliberate persistence of remembered facts.

Install this only if you want the agent to keep facts across sessions in your SynapCores database. Be deliberate about what is stored, use separate namespaces for people or projects, ask for confirmation before saving sensitive personal details, and review the separate companion plugin before installing it because it advertises automatic capture behavior.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill recommends broad activation triggers such as 'remember that', 'don't forget', and 'for future reference', which can match ordinary conversation and cause unintended persistence of user data. In a long-term memory skill, accidental activation is more dangerous because it may store sensitive personal information across sessions without sufficiently explicit consent.

Static analysis

No suspicious patterns detected.