Back to skill

Security audit

Longmemo Elite

Security checks across malware telemetry and agentic risk

Overview

This long-term memory skill is purpose-aligned, but it asks the agent to persist and reuse broad conversation-derived data across files, Git notes, local indexes, and optional external services without clear consent and scoping controls.

Review this carefully before installing. Use it only for workspaces where persistent memory is acceptable, avoid storing secrets or sensitive personal data, keep cloud sync and automatic extraction disabled unless you explicitly want third-party processing, and periodically inspect and delete the generated memory files, Git notes, vector stores, and logs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Context-Inappropriate Capability

Low
Confidence
73% confidence
Finding
The skill recommends optional cloud sync and automatic fact extraction through external services, which expands data flow beyond local memory management into third-party systems. In a long-memory skill, this is contextually related, but it still creates a real security and privacy risk because user conversation data may be transmitted and retained externally without strong minimization or consent requirements.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation scope is overly broad and encourages the skill to apply across many vague scenarios without clear boundaries on when persistence should occur. For a memory system, broad triggering is dangerous because it can normalize indiscriminate capture and recall of user data, including sensitive content that should not be retained.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The workflow directs file creation, file mutation, and command execution such as git initialization and sync commands, but it does not provide a clear user-facing warning or consent checkpoint about filesystem and repository side effects. This is dangerous because an agent could modify the workspace, create logs, or alter Git state in ways the user did not expect.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The cloud sync and external extraction features are presented as recommended/optional enhancements without an explicit privacy warning about sending conversation-derived data to third-party services. This is dangerous because users may not realize that preferences, decisions, deadlines, and other natural-language content could leave the local environment and be retained externally.

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs persistent storage and later recall of user preferences, decisions, deadlines, corrections, and other conversation-derived facts across sessions. In context, this is the core function of the skill, which makes the risk more—not less—serious: it systematically retains potentially sensitive natural-language data and optionally extends that retention to cloud sync and automated extraction pipelines.

Ssd 3

Medium
Confidence
95% confidence
Finding
The workflow tells the agent to create persistent session-state and memory files containing current task context, user preferences, decisions, and daily activity. This broad logging behavior can expose private information to anyone with workspace access and can unintentionally preserve sensitive material far beyond the original conversational need.

Ssd 3

Medium
Confidence
97% confidence
Finding
The WAL and session-management procedures normalize continuous recording, recall, and migration of conversation content into multiple persistent stores and logs. This increases the attack surface and likelihood of accidental leakage because the same sensitive information may be duplicated across hot memory, archives, lesson logs, and other storage layers.

Ssd 3

Medium
Confidence
96% confidence
Finding
Recommending automatic fact extraction from conversations and cloud synchronization encourages transmission of user-derived data into external systems where control, retention, and secondary use may be unclear. In a memory-management skill this is highly sensitive, because the feature is specifically designed to capture and preserve semantic details from user interactions over time.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.