Back to skill

Security audit

Neural Memory Enhanc

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed persistent memory tool, but it asks agents to automatically store and re-inject conversation content without enough consent, sensitivity, or trust-boundary controls.

Install only if you are comfortable with a local persistent memory database that may store and later reuse conversation details. Use a dedicated environment, verify the `neural-memory` package source/version before install, avoid storing secrets or sensitive personal data, and periodically inspect or delete the local brain database.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:25
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25-27
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install neural-memory
nmem init

Technical Analysis

The setup instructions install neural-memory from the active Python package index without specifying an exact version, package hash, verified repository, or trusted index. The installed package is then immediately executed through nmem init.

Because the dependency is unpinned, the code installed by the same reviewed Skill can change over time. A compromised publisher account, compromised package release, dependency-confusion condition, or malicious package served by a configured package index could result in arbitrary Python package installation or initialization code running locally.

The project contains only SKILL.md, so the implementation and provenance of the referenced package could not be verified within the audited artifact.

Attack Path

  1. An attacker compromises the package, its publishing account, a transitive dependency, or a package index used by the victim.
  2. The attacker publishes a malicious release under the dependency name or causes package resolution to select an attacker-controlled distribution.
  3. A user follows the Skill instructions and runs pip install neural-memory.
  4. Package installation behavior executes, after which the user runs the installed nmem init command.
  5. Malicious package code executes with the privileges of the user who performed the installation.

Impact Assessment

Successful exploitation can provide arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, malicious code could read or alter accessible files, environment variables, credentials, project data, and local application state. It could also establish additional persistence or communicate with external servic ...[truncated 76 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specifically reviewed version, such as neural-memory==X.Y.Z.
  • Require hash verification with a locked requirements file and pip install --require-hashes.
  • Document the official package repository, publisher identity, and trusted package index.
  • Audit direct and transitive dependencies before approving upgrades.
  • Install the package in a dedicated virtual environment or other least-privilege sandbox.
  • Separate installation from execution and ask the user to verify the resolved package source and version before running nmem init.
  • Consider distributing a reproducible, signed lock file or verified package artifact.

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:87
Finding

Persistent Capture and Reinjection of Untrusted Conversation Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 87-102
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: High

Vulnerable Code

markdown
### At Session Start

1. Call `nmem_context` to inject recent memories into your awareness
2. If user mentions a specific topic, call `nmem_recall` with that topic

### During Conversation

3. When a decision is made: `nmem_remember` with type="decision"
4. When an error occurs: `nmem_remember` with type="error"
5. When user states a preference: `nmem_remember` with type="preference"
6. When asked about past events: `nmem_recall` with appropriate depth

### At Session End

7. Call `nmem_auto` with action="process" on important conversation segments
8. This auto-extracts facts, decisions, errors, and s

Technical Analysis

The Skill directs the agent to persist decisions, errors, preferences, and automatically extracted conversation content. It then directs the agent to inject stored memories into its awareness at the beginning of later sessions.

These instructions do not define a trust boundary between user-provided data and authoritative agent instructions. They also do not require per-item user consent, provenance labeling, sanitization of instruction-like content, or validation before recalled content influences a later session. Consequently, attacker-controlled conversation text may be stored as a fact, preference, decision, instruction, or related memory and later reintroduced into the agent's working context.

This creates a persistent memory-poisoning channel. The risk is broader than ordinary same-session prompt injection because poisoned content can survive the original interaction and affect later sessions. The documented memory types include instruction, further increasing the importance of distinguishing stored data from trusted operational directives.

Attack Path

  1. An attacker supplies crafted conversation content ...[truncated 1329 chars]
Remediation
View remediation

Remediation Suggestions

  • Require explicit user consent before persisting conversation content, especially preferences, instructions, credentials, personal information, and security-sensitive decisions.
  • Treat all recalled memories as untrusted historical data rather than executable or authoritative instructions.
  • Prevent nmem_auto from storing imperative, tool-invoking, credential-related, or policy-changing text without review.
  • Record provenance, author, creation time, originating session, confidence, and trust level for every memory.
  • Clearly delimit recalled content and instruct the agent not to follow commands embedded in it.
  • Require confirmation before recalled data affects sensitive actions, tool calls, access-control decisions, or external communications.
  • Add allowlists for memory types and deny storage of secrets, authentication data, private keys, tokens, and unnecessary personal information.
  • Provide inspection, correction, expiration, deletion, and full-memory-reset controls.
  • Scope memory by user, project, and tenant, and ensure that one context cannot retrieve another context's stored records.
  • Test the recall pipeline against persistent prompt-injection and memory-poisoning payloads.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description explicitly states 'Zero LLM dependency' and describes the skill as 'Pure algorithmic.' Later documentation says an LLM API is required and that the skill cannot be used without LLM support, which directly contradicts the stated intent of the skill's operating model.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The nmem_auto instruction promotes automatic extraction from conversation text into persistent memory without defining what categories must be excluded. Automatic semantic capture increases the chance that sensitive disclosures, internal instructions, or private user details are retained and later exposed through recall.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to persist memories, including decisions, errors, and user preferences, but does not prominently warn that conversation-derived data will be written to local storage. This creates a privacy and consent risk because users and operators may unknowingly retain sensitive content beyond the current session.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly encourages ongoing capture and later recall of user conversation content and preferences across sessions. Without sensitivity boundaries, minimization rules, or consent checks, this can lead to unintended retention and resurfacing of confidential or personal information to future tasks or users sharing the environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states "Vietnamese + English — Full bilingual support," which presents a fixed language scope without any opt-in choice or explanation that the skill is intentionally region- or language-specific. Under the policy, language constraints should either offer user choice or be clearly justified.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The notes normalize storing broad classes of conversational data such as facts, preferences, instructions, and context for future recall. Broad retention categories materially increase the risk of over-collection, long-lived sensitive data, and inappropriate reuse in later contexts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The notes section states that no data is sent to external services unless an optional embedding provider is configured. Elsewhere, the file says an LLM API is required and even includes 'network errors' as an expected runtime condition, which contradicts the claim of fully local operation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L190 says an 'LLM API' is mandatory, implying a dependency on external or platform-provided model access. Immediately after, L193 states that no additional API key is needed, which conflicts with the earlier dependency claim unless carefully qualified as agent-provided credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.