Back to skill

Security audit

记忆管理器

Security checks across malware telemetry and agentic risk

Overview

This local memory skill is mostly purpose-aligned, but its broad activation language and inconsistent network/privacy instructions need review before installation.

Install only if you want a local Markdown-based memory system and are comfortable with the agent creating and updating files under $HOME/memory. Treat the local-only privacy promise cautiously until callback_url and network/API references are removed or clearly scoped, and avoid storing credentials or highly sensitive personal data in this memory directory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The skill repeatedly claims it makes no network requests and stores everything locally, yet its interface and later sections reference callback URLs, HTTPS communication, API authentication failures, rate limiting, and network connectivity errors. This inconsistency can mislead users and host agents into granting trust or exposing data under false assumptions about isolation and exfiltration risk.

Intent-Code Divergence

High
Confidence
94% confidence
Finding
The privacy section states there are no network requests, but other parts of the skill describe network-oriented behavior and failures. Security/privacy contradictions are dangerous because users may store sensitive information based on false local-only assurances, while the runtime behavior or operator expectations may permit network use.

Vague Triggers

High
Confidence
88% confidence
Finding
The activation guidance is so broad that it can cause the skill to trigger in many generic AI, orchestration, or LLM-use contexts unrelated to structured memory management. Over-broad activation increases the chance the agent invokes a write-capable/exec-capable skill unnecessarily, expanding attack surface and risking unintended file operations on user data.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.