Back to skill

Security audit

Elite Longterm Memory Local

Security checks for vulnerabilities and agentic risk

Overview

This is a local memory skill with no clear exfiltration, but it asks agents to persist and automatically reuse user conversation details in ways that need careful review.

Install only if you deliberately want persistent local memory. Before use, decide what categories may be stored, avoid secrets or regulated personal data, review memory files regularly, keep backups protected, and require confirmation before recalled memories drive important actions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:56
Finding

Untrusted Conversation Content Can Persistently Influence Future Agent Sessions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56, 81, 139–151, and 163
Vulnerability Type: Persistent memory poisoning through automatic storage and recall
Risk Level: Medium

Complete Vulnerable Segment

The following is an English translation of the relevant instructions from SKILL.md:

text
Line 56:
autoRecall=true (automatically search relevant memories at session start),
autoCapture=false (automatic capture is disabled by default to avoid noise),
captureCategories=["preference","decision","fact"],
minImportance=0.7.
At session start, relevant historical memories are automatically recalled,
and during conversations information is automatically stored according to
category and importance.

Line 81:
Add the memory protocol to AGENTS.md or SOUL.md:
At session start, read SESSION-STATE.md to obtain active context, use
memory_recall to search relevant history, and inspect memory/YYYY-MM-DD.md
for recent activity. When the user provides specific details, write them to
SESSION-STATE.md before replying. Store important decisions using
memory_store. Store preferences with importance 0.9 and category preference.

Lines 139–151:
WAL protocol: first write the information into SESSION-STATE.md.
Store the database migration decision as an important decision.
In a subsequent session, recall the PostgreSQL decision.
The Agent automatically follows that decision and no longer recommends MongoDB.

Line 163:
The recommended configuration is autoRecall=true and autoCapture=false.
If automatic capture is enabled, use minImportance=0.8 and restrict
captureCategories to ["preference","decision"].

Technical Analysis

The Skill establishes a persistent trust path from conversation input to future Agent behavior:

  1. User-provided details can be written to SESSION-STATE.md before the Agent responds.
  2. Decisions, preferences, and facts can be copied into long-term files or the vector database.
  3. Future sessions automatically read or seman ...[truncated 2926 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat recalled memory as untrusted data

    • Explicitly prohibit interpreting recalled content as Agent instructions.
    • Delimit recalled records from system and developer instructions.
    • Require current-session validation before recalled content influences tool calls or security-sensitive decisions.
  2. Require explicit storage approval

    • Replace the unconditional requirement to write specific details before replying with a confirmation workflow.
    • Keep autoCapture disabled by default and require informed opt-in before enabling it.
    • Show the exact proposed record, category, retention period, and scope before storage.
  3. Add content filtering

    • Reject credentials, API keys, authentication tokens, private keys, and other secrets.
    • Reject instruction-like records that attempt to alter Agent policies, tool permissions, or safety constraints.
    • Minimize personal and confidential information before creating embeddings or backups.
  4. Add provenance and lifecycle metadata

    • Record the source, author, creation time, confidence, intended scope, and expiration time for every memory.
    • Distinguish user-confirmed facts from inferred or unverified statements.
    • Expire stale memories automatically and require reconfirmation of consequential decisions.
  5. Introduce trust boundaries

    • Isolate memories by user, project, and workspace.
    • Do not retrieve one user's or project's records in another context.
    • Use allowlisted categories and deny storage of behavioral rules or privileged instructions.
  6. Protect persistent storage

    • Apply restrictive filesystem permissions to session state, long-term memory, vector databases, exports, and backups.
    • Encrypt sensitive records and backups at rest.
    • Validate file ownership and integrity before loading memory files.
  7. Provide review and deletion controls

    • Present recalled records and their provenance to the user.
    • Re ...[truncated 450 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to write user-provided details into persistent local memory files before replying, but it does not require clear user notice, consent, or a sensitivity filter. Even though storage is local, this still creates a privacy and retention risk because sensitive conversation content may be persisted unexpectedly and later recalled or exposed to other local users/processes.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions normalize persisting user conversation details to disk before responding, which creates a built-in data retention pathway for arbitrary user input. In a memory skill, this context makes the behavior expected, but it is still dangerous without consent controls because users may reveal secrets or personal data that become durable artifacts retrievable in later sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented cleanup and backup commands modify retention state and create extra copies of memory data, but the skill does not prominently warn that cleanup can delete records or that backups can duplicate sensitive information. This can lead to unintended data loss or wider exposure of stored private content, especially if backup destinations are less protected than the primary store.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow directs the agent to capture user details, decisions, and session state across multiple persistent artifacts throughout the session lifecycle. This broad, structured retention increases the chance of over-collection, later unintended disclosure, and long-lived storage of sensitive information beyond user expectations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The examples demonstrate storing conversational preferences, technical facts, and project decisions into long-term memory, which reinforces broad persistence of user-supplied content as normal behavior. Example code and workflows shape operator behavior, so omitting privacy cautions here materially increases the likelihood of oversharing and accidental retention of sensitive data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.