T08 · Insecure Dependencies
- Location
SKILL.md:155- Finding
Unpinned Third-Party Package Installation and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a memory tool that persistently stores and reuses conversation information, but it is too broad and lacks clear user controls for sensitive retention and recall.
Review this before installing. Only use it if you are comfortable with conversation-derived facts and preferences being stored across sessions under ~/.neuralmemory and potentially injected into later chats. Prefer a pinned, reviewed package version in an isolated environment, and avoid storing secrets, personal data, or confidential business details unless the tool provides clear inspect/delete controls.
SKILL.md:155Unpinned Third-Party Package Installation and Execution
The activation language is overly broad, framing the skill as suitable for generic efficiency, automation, batch processing, and workflow optimization rather than narrowly memory-related tasks. This can cause over-triggering in many unrelated user requests, leading to unnecessary tool access, persistence, or command execution in contexts where the user did not intend a memory system to run.
A local neural-memory persistence/recall skill should not need broad external API integration or generic HTTPS communication claims unless those behaviors are explicitly necessary and bounded. Advertising networked capabilities beyond the stated purpose creates ambiguity about data exfiltration risk and can normalize unnecessary outbound connections from a persistence tool that handles conversational memory.
The skill is presented as a neural-memory recall/storage tool, but later expands into generic file processing, API integration, and command execution claims that exceed the declared purpose. This scope inflation can cause an agent or operator to invoke the skill in unrelated contexts, increasing the chance of unnecessary file access, command execution, or external communication under a misleading trust boundary.
The description states '支持中文交互' and the document consistently presents the skill as Chinese-only, but it does not offer a user language choice or explain a justified locale restriction. This can violate language or locale policy when users are not given an opt-in or alternative.
The skill stores conversation-derived facts, decisions, preferences, todos, and errors persistently, but does not clearly warn users about retention duration, write effects, or review/deletion controls at the point of use. This creates a data-retention risk because sensitive or personal content may be written to local storage without informed consent or clear lifecycle guarantees.
The skill explicitly instructs the agent to persist conversation content and inject prior memories into future sessions, creating a direct risk of retaining and redisclosing sensitive user data. In this context, the danger is amplified because the skill is designed around cross-session recall, making accidental disclosure a core failure mode rather than an edge case.
The usage guidance recommends automatic context injection at session start and immediate recall when a topic is mentioned, without requiring clear user intent or consent. This encourages autonomous activation and increases the chance of retrieving and surfacing prior stored data inappropriately.
The document claims the core system does not depend on external LLM or embedding services, yet the dependency section says an LLM API is required. Contradictory dependency statements can mislead reviewers and users about where data flows, what services are involved, and whether external exposure occurs.
The skill says no API key is needed, but later discusses API key leakage and environment-variable handling as though secrets are part of normal operation. This inconsistency obscures the real secret-handling model and may cause users to misconfigure credentials or underestimate exposure paths.
No suspicious patterns detected.