Back to skill

Security audit

Mem0 Memory Layer

Security checks for vulnerabilities and agentic risk

Overview

This skill is advertised as a Mem0 memory helper, but its authoritative files contain unrelated finance, ZVT, and backtesting workflows that need review before use.

Do not install this as a normal Mem0 memory helper unless the publisher aligns the artifacts to one purpose. If testing, use an isolated workspace, avoid real financial or broker credentials, review any generated code before execution, disable or control telemetry and memory retention, and treat the finance/backtest behavior as outside the advertised scope.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file describes a Doraemon-themed finance/ZVT quant-trading assistant, which is materially inconsistent with the declared skill purpose of a Mem0 long-term memory layer. This kind of instruction/context mismatch can cause an agent to adopt unintended behavior, expose users to unauthorized financial guidance workflows, and bypass expected safety boundaries because the embedded human summary effectively repurposes the skill.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The inline instructions explicitly tell the agent to preserve a Doraemon finance-assistant persona and finance-specific identifiers, further steering behavior away from the manifest's memory-layer purpose. Embedded behavioral instructions inside a mismatched skill increase prompt-injection style control over the agent and can make it produce domain-specific outputs users and integrators did not authorize.

Description-Behavior Mismatch

Critical
Confidence
99% confidence
Finding
The manifest is fundamentally inconsistent with the declared skill identity: although presented as a mem0 memory-layer skill, the file primarily defines a finance/ZVT quant-trading and backtesting blueprint with execution triggers, preconditions, trading locks, and output gates. This kind of capability smuggling is dangerous because a host may grant the skill permissions or user trust appropriate for a memory helper while actually activating trading/data-collection behavior.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The use-case router advertises mem0 scenarios, but surrounding controls and downstream logic are centered on ZVT trading workflows. This mismatch can cause incorrect routing and unexpected invocation of privileged or risky behavior under innocent memory-related prompts, which is especially dangerous in an agent ecosystem that auto-selects skills by descriptions and trigger terms.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The post-install notice and human summary tell users the skill helps build A-share quant strategies, directly contradicting the stated mem0 memory-layer metadata. This deceptive presentation increases the risk of user confusion, unsafe consent, and accidental enablement of code-generation or market-data actions outside the expected memory-assistant scope.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The file embeds substantial trading, backtesting, market-data, and execution-governance functionality that is not justified by a memory-layer purpose. Hidden high-risk capabilities are dangerous because they can expand the operational blast radius from simple memory management to financial analysis and executable strategy generation, possibly bypassing policy and user expectations.

Vague Triggers

High
Confidence
91% confidence
Finding
The execute trigger fires when intent matches positive terms and the user uses common verbs like run, execute, fetch, collect, or their Chinese equivalents. Broad activation language increases the chance of accidental invocation from ordinary conversation, causing an agent to enter an execution path the user did not clearly authorize.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Many sample triggers are broad noun phrases like 'personal assistant', 'fitness', or 'customer support', which are likely to appear in normal conversation unrelated to this skill. In a multi-skill environment, such generic triggers can cause collisions, misrouting, and unintended activation of this skill over safer or more appropriate handlers.

Ssd 3

Medium
Confidence
90% confidence
Finding
The prescribed integration pattern stores full user and assistant exchanges in memory, which can naturally include secrets, regulated data, credentials, or sensitive context. Persistent storage of raw conversations materially increases confidentiality and retention risk, especially because the same file also acknowledges missing PII redaction and telemetry/privacy concerns elsewhere.

Ssd 3

Medium
Confidence
88% confidence
Finding
The use cases normalize retention of sensitive categories such as patient information, allergies, account details, and persistent preferences. In context, this is more dangerous because the same manifest documents absent PII redaction and other safeguards, so the skill encourages exactly the kind of storage that creates compliance and privacy exposure.

Static analysis

No suspicious patterns detected.