other
- Location
SKILL.md:188- Finding
Overbroad Persistent Collection of User and Behavioral Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real encrypted Nostr-backed memory skill, but it needs Review because it encourages broad long-term storage of personal and behavioral information on external relays.
Install only if you are comfortable giving the skill a Nostr identity credential and letting it persist encrypted memories to configured relays. Use a dedicated identity, avoid storing sensitive personal, financial, health, authentication, or private-communication data, prefer a relay you control if possible, and do not assume forget requests erase every remote copy.
SKILL.md:188Overbroad Persistent Collection of User and Behavioral Data
SKILL.md:208Remote Deletion Is Best-Effort but Presented as a Forget Operation
metadata.json:24Security-Critical Runtime Dependencies Are Mutable and Not Auditable in the Artifact
The skill instructs use of environment variables containing sensitive secrets like NOSTRKEY_PASSPHRASE and NOSTR_NSEC, but the manifest declares no explicit tool scope or permissions boundary. In an agent ecosystem, missing scope metadata can cause the agent to access secrets and network capabilities without clear operator consent or least-privilege controls.
The skill uses ordinary conversational triggers such as requests to 'remember things' or 'set up memory' to activate persistent storage behavior. Broad triggers increase the chance that the agent stores user data without a deliberate, well-scoped consent flow, especially in normal conversation where the operator may not realize persistence to a third-party relay is being enabled.
The skill encourages broad retention of user preferences, facts, and decisions, and normalizes later disclosure through memory recall. This creates a privacy and data-minimization issue because the agent is guided to accumulate potentially sensitive personal data over time without strong limits on category, necessity, retention period, or consent.
The day-to-day usage section encourages storing preferences, facts, and project details on relays but does not prominently warn users, at the point of use, that this is persistent storage on third-party infrastructure. Even with encryption, metadata, retention, relay availability, and deletion semantics can create privacy risk if users are not clearly informed before routine use.
The instruction to present all remembered information about a person on request encourages wholesale disclosure rather than contextual, least-necessary retrieval. This can surface outdated, overly broad, or sensitive data that the user did not expect to be aggregated and restated in one response.
The journaling examples explicitly direct the agent to persist behavioral observations such as frustration patterns and communication preferences. Storing psychological or behavioral profiling in durable memory is more sensitive than ordinary preferences and can expose users to privacy harms, misuse, or unexpected disclosure if recalled later or replicated across relays.
This code accesses NOSTR_NSEC from the environment and immediately uses it to construct an identity, but the file provides no warning in comments, docstrings, or user-facing output that a private credential is required and will be used. For a code file, accessing sensitive environment variables should include some form of disclosure unless clearly documented elsewhere in the skill description, which is not evident here.
This example performs memory and journal operations against a remote Nostr relay without any explicit user-facing notice that remembered values and journal content will leave the local process and be sent over the network. Because the example stores personal data such as name, timezone, and free-form journal text, users may unintentionally transmit sensitive information to third-party infrastructure under the assumption that 'memory' is local.
No suspicious patterns detected.