Back to skill

Security audit

神经记忆增强系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is a memory tool that persistently stores and reuses conversation information, but it is too broad and lacks clear user controls for sensitive retention and recall.

Review this before installing. Only use it if you are comfortable with conversation-derived facts and preferences being stored across sessions under ~/.neuralmemory and potentially injected into later chats. Prefer a pinned, reviewed package version in an isolated environment, and avoid storing secrets, personal data, or confidential business details unless the tool provides clear inspect/delete controls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:155
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation language is overly broad, framing the skill as suitable for generic efficiency, automation, batch processing, and workflow optimization rather than narrowly memory-related tasks. This can cause over-triggering in many unrelated user requests, leading to unnecessary tool access, persistence, or command execution in contexts where the user did not intend a memory system to run.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
90% confidence
Finding

A local neural-memory persistence/recall skill should not need broad external API integration or generic HTTPS communication claims unless those behaviors are explicitly necessary and bounded. Advertising networked capabilities beyond the stated purpose creates ambiguity about data exfiltration risk and can normalize unnecessary outbound connections from a persistence tool that handles conversational memory.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a neural-memory recall/storage tool, but later expands into generic file processing, API integration, and command execution claims that exceed the declared purpose. This scope inflation can cause an agent or operator to invoke the skill in unrelated contexts, increasing the chance of unnecessary file access, command execution, or external communication under a misleading trust boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description states '支持中文交互' and the document consistently presents the skill as Chinese-only, but it does not offer a user language choice or explain a justified locale restriction. This can violate language or locale policy when users are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill stores conversation-derived facts, decisions, preferences, todos, and errors persistently, but does not clearly warn users about retention duration, write effects, or review/deletion controls at the point of use. This creates a data-retention risk because sensitive or personal content may be written to local storage without informed consent or clear lifecycle guarantees.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to persist conversation content and inject prior memories into future sessions, creating a direct risk of retaining and redisclosing sensitive user data. In this context, the danger is amplified because the skill is designed around cross-session recall, making accidental disclosure a core failure mode rather than an edge case.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage guidance recommends automatic context injection at session start and immediate recall when a topic is mentioned, without requiring clear user intent or consent. This encourages autonomous activation and increases the chance of retrieving and surfacing prior stored data inappropriately.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document claims the core system does not depend on external LLM or embedding services, yet the dependency section says an LLM API is required. Contradictory dependency statements can mislead reviewers and users about where data flows, what services are involved, and whether external exposure occurs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill says no API key is needed, but later discusses API key leakage and environment-variable handling as though secrets are part of normal operation. This inconsistency obscures the real secret-handling model and may cause users to misconfigure credentials or underestimate exposure paths.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.