Back to skill

Security audit

Memory Fortress Free

Security checks across malware telemetry and agentic risk

Overview

This memory skill fits its general purpose, but it asks the agent to silently retain conversation details and mixes local memory with optional external services without clear consent or privacy boundaries.

Install only if you intentionally want an agent to maintain persistent memory. Before use, set clear rules that it must ask before storing personal, business, or sensitive details; keep cloud backup, Mem0, and vector/provider features disabled unless you explicitly configure them; inspect the created memory files regularly; and avoid the recursive deletion command unless you have a backup and understand it will erase stored memory data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill markets the free edition as local/persistent memory, yet also embeds concrete instructions for optional cloud backup and Mem0 external API usage in the main workflow. This mismatch can cause an operator or downstream agent to enable external transmission of conversation data under the false assumption that the skill is local-only, creating an unexpected data exposure path.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The document states the free version needs no extra API keys and uses local storage, but elsewhere instructs configuring external-service API keys and provider-backed search. Contradictory security and deployment claims undermine informed consent and can lead users to expose sensitive memory contents to third-party services without realizing the skill supports such flows.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The free edition is described elsewhere as supporting only three memory layers, but the skill repeatedly presents a six-layer architecture including cloud backup and automatic extraction as part of the system. This creates scope confusion that can cause users or agents to invoke higher-risk components they did not intend to deploy, especially components that persist or export conversational data.

Vague Triggers

High
Confidence
90% confidence
Finding
The skill declares a very broad activation scope using generic scene keywords and vague applicability language, without precise trigger boundaries. In an agent environment, this increases the chance the skill activates in unrelated contexts and begins reading or persisting user data when memory tooling was neither requested nor appropriate.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs the agent to silently persist user details, preferences, decisions, and corrections without warning the user or obtaining consent. In a memory-management skill, this is especially dangerous because normal conversational content may include sensitive personal, business, or security information that becomes durably stored and later retrievable.

Missing User Warnings

High
Confidence
98% confidence
Finding
The maintenance section includes a destructive command that recursively deletes the vector database directory, but it is presented without a prominent data-loss warning or confirmation requirement. An agent or user following the documentation could irreversibly erase stored memory contents, harming availability and potentially destroying audit or decision history.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The document explicitly describes cloud synchronization and storing contact information, but it does not warn users about privacy, retention, cross-device exposure, or the sensitivity of personal data. In a memory/persistence skill, this omission is materially risky because users may store secrets or PII in long-lived files and optional cloud backups without understanding the exposure surface.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill normalizes default long-term retention of user-provided details, preferences, corrections, and decisions across files and logs. This broad persistence can accumulate sensitive information over time and make later disclosure more likely through routine recall, summarization, or file access by the agent.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill recommends automatic fact extraction from conversations and storage of user-linked memories via an external memory system. Automatic capture of conversational content, especially when tied to a user identifier, risks indiscriminate collection of personal or confidential information and expands the blast radius if the external system is compromised or misconfigured.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.