Back to skill

Security audit

神经缓存增强

Security checks for vulnerabilities and agentic risk

Overview

This memory skill fits its stated purpose, but it needs review because it can automatically persist conversation details, transfer memories between projects, and install an unpinned MCP package.

Review this skill before installing. Use it only if you are comfortable with conversation and project details being stored locally under a persistent memory system, and avoid automatic capture until you have rules for excluding secrets, credentials, personal data, and customer information. Pin or verify the `neural-memory` package before running `nmem init`, and be careful when transplanting memories between projects.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:73
Finding

Unpinned Executable Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 73–77
Vulnerability Type: Unpinned executable dependency and automatic MCP configuration
Risk Level: Medium

Vulnerable Code

bash
pip install neural-memory
nmem init

The document states that this creates the default brain under ~/.neuralmemory/ and automatically configures MCP.

Technical Analysis

The Skill instructs users or agents to install the latest available release of the third-party neural-memory package without specifying an exact version, cryptographic hashes, a lockfile, or a verified source. It then immediately executes the package-provided nmem init command.

Because the dependency's implementation is not included in the audited project, its behavior cannot be reviewed from this artifact. The package version resolved at installation time may also differ from the version intended by the Skill author. Executing nmem init increases the exposure because package-controlled code can create persistent local state and modify MCP configuration. Later memory operations may consequently invoke code from the unresolved package release.

This is a supply-chain weakness rather than confirmation that the current external package is malicious.

Attack Path

  1. An attacker compromises the dependency publisher, distribution account, or package delivery channel.
  2. The attacker publishes a malicious or unexpectedly modified release under the referenced package name.
  3. A user or agent follows the Skill instruction and runs pip install neural-memory.
  4. The package manager resolves and installs the attacker-controlled release because no exact version or hash is required.
  5. The user or agent runs nmem init, executing package-provided code.
  6. The malicious package can alter MCP configuration or arrange for its code to run during subsequent memory operations.

Impact Assessment

Successful exploitation would execute dependency-controlled code with the operating-s ...[truncated 505 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin neural-memory to a specifically reviewed version rather than installing the latest release.
  2. Publish a lockfile or constraints file containing cryptographic hashes, and install with pip's --require-hashes option.
  3. Document the trusted package index and source repository; reject unexpected indexes and dependency-confusion sources.
  4. Include or vendor the relevant implementation so reviewers can audit the code executed by the Skill.
  5. Verify package provenance and release signatures where supported.
  6. Separate installation from initialization and require explicit user confirmation before nmem init modifies MCP configuration.
  7. Run initialization and the MCP service with least privilege in an isolated environment.
  8. Document all files and configuration entries created or changed by initialization and provide a safe removal procedure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The main description presents the skill as having zero LLM dependency, which materially shapes expected behavior and trust assumptions. Elsewhere, the file states an LLM API is required and that automatic extraction may invoke an LLM, so the described implementation scope does not consistently match the documented behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to automatically extract and store memories from conversations at session end, including facts, decisions, errors, TODOs, and user preferences, without a clear consent, notice, minimization, or retention warning. In an agent context, this can lead to silent persistence of sensitive personal, project, or credential-related information, expanding the blast radius of later leakage or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cross-project transplant feature enables migration of stored memories, including decisions and lessons, between separate 'brains' while preserving structure, but the skill does not prominently warn about transferring user, customer, or project-confidential data across trust boundaries. In multi-project or multi-tenant environments, this creates a real risk of data contamination, confidentiality breaches, and inappropriate reuse of sensitive context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The FAQ says the core retrieval is zero-LLM and nmem_auto is only optionally LLM-backed, while the dependency table marks 'LLM API' as '必需'. These statements cannot both be true as written, creating an intent/documentation contradiction about the skill's actual runtime requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.