Back to skill

Security audit

Total Recall Ai Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed encrypted memory integration, but users should understand it stores local credential material during pairing.

Install only if you want a persistent memory system and are comfortable with encrypted memories being stored on a decentralized network and a local credential file being created at ~/.total-recall-ai/credentials.json. Protect that file and your 12-word recovery phrase; do not paste the phrase into chat, and remove or rotate credentials if the machine is shared or compromised.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The pairing flow states that a credential file will be automatically written to ~/.total-recall-ai/credentials.json, but it does not clearly warn the user beforehand that sensitive local key material will be persisted on disk. In a privacy-focused skill, silent creation of local credentials can mislead users about the trust boundary and increase the risk of accidental exposure through backups, malware, or multi-user systems.

Credential Access

High
Category
Privilege Escalation
Content
- 短语在浏览器端加密后上传,**永不进入本对话**

3. **确认配对完成**:
   - 配对完成后,凭据文件自动写入 `~/.total-recall-ai/credentials.json`
   - Agent确认:"全息记忆AI已配对完成。"

**重要**:配对是无条件的——用户主动安装/请求配对本身就是同意,不需要二次确认门。
Confidence
87% confidence
Finding
credentials.json

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.