Back to skill

Security audit

sense-memory

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real encrypted Nostr-backed memory skill, but it needs Review because it encourages broad long-term storage of personal and behavioral information on external relays.

Install only if you are comfortable giving the skill a Nostr identity credential and letting it persist encrypted memories to configured relays. Use a dedicated identity, avoid storing sensitive personal, financial, health, authentication, or private-communication data, prefer a relay you control if possible, and do not assume forget requests erase every remote copy.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

other

Warning
Location
SKILL.md:188
Finding

Overbroad Persistent Collection of User and Behavioral Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:208
Finding

Remote Deletion Is Best-Effort but Presented as a Forget Operation

Content
View full analysis
This publishes a NIP-09 deletion event. Well-behaved relays will remove the original event. ### Technical Analysis The `forget()` operation does not directly erase the original record. It publishes a NIP-09 deletion request and relies on remote relay cooperation. A relay may ignore the event, retain the original event in a database or backup, or allow replicated copies to remain elsewhere. The Skill nevertheless describes the feature as the ability to “forget things,” which can lead users to interpret the operation as guaranteed erasure. The documented journal mechanism is append-only, and the artifact does not provide an equivalent deletion procedure for individual journal entries. Encryption protects content while the key remains secure, but it does not provide deletion. If ciphertext remains available, later compromise of the private key or runtime could make retained records readable. ### Attack Path 1. The agent stores a personal fact or journal entry on a Nostr relay. 2. The relay retains the encrypted event and may copy it into logs, caches, backups, or replicas. 3. The user asks the agent to forget the information. 4. The agent invokes `store.forget()`, which publishes a NIP-09 deletion event. 5. A noncompliant relay ignores the request, or an existing backup or replica retains the original event. 6. The user believes the information was erased even though remote copies remain. 7. A later compromise of the identity key, dependency, endpoint, relay, or backup may expose the retained content. ### Impact Assessment No additional local system privilege is obtained. The affected scope is the confidentiality and lifecycle control of records transmitted ...[truncated 373 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
metadata.json:24
Finding

Security-Critical Runtime Dependencies Are Mutable and Not Auditable in the Artifact

Content
View full analysis
=3.10" }, "dependencies": [ "nostrkey>=0.1.1" ] ``` Related installation instructions in `SKILL.md:8-14` and `SKILL.md:32` install `sense-memory` and `nostrkey` from package infrastructure without exact version and hash verification: ```text pip install nostrkey ``` ### Technical Analysis The artifact contains documentation and an example but does not contain the implementation of either `sense_memory` or `nostrkey`. These packages perform the security-critical operations of: - Loading or constructing the Nostr identity. - Accessing `NOSTR_NSEC` or `NOSTRKEY_PASSPHRASE`. - Encrypting memory plaintext. - Signing events. - Sending data to external relays. - Retrieving and decrypting persistent records. The package name `sense-memory` is not pinned to an exact version in the installation metadata. The dependency constraint `nostrkey>=0.1.1` allows any later compatible release. No lockfile, artifact hash, signature, or vendored source is included. This does not prove that the current packages are malicious. However, it creates a supply-chain trust boundary that cannot be verified from the reviewed project. A compromised maintainer account, malicious future release, repository/package mismatch, or dependency-resolution attack could execute code with access to identity secrets and memory plaintext. The artifact also contains a provenance inconsistency: `SKILL.md:4` declares version `0.1.2`, while `metadata.json:4` declares version `0.2.0`. This makes it unclear which reviewed documentation corresponds to the package that will actually be installed. ### Attack Path 1. An attacker compromises a dependency publisher account, package repository, or release pipeline, o ...[truncated 1400 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs use of environment variables containing sensitive secrets like NOSTRKEY_PASSPHRASE and NOSTR_NSEC, but the manifest declares no explicit tool scope or permissions boundary. In an agent ecosystem, missing scope metadata can cause the agent to access secrets and network capabilities without clear operator consent or least-privilege controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill uses ordinary conversational triggers such as requests to 'remember things' or 'set up memory' to activate persistent storage behavior. Broad triggers increase the chance that the agent stores user data without a deliberate, well-scoped consent flow, especially in normal conversation where the operator may not realize persistence to a third-party relay is being enabled.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages broad retention of user preferences, facts, and decisions, and normalizes later disclosure through memory recall. This creates a privacy and data-minimization issue because the agent is guided to accumulate potentially sensitive personal data over time without strong limits on category, necessity, retention period, or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The day-to-day usage section encourages storing preferences, facts, and project details on relays but does not prominently warn users, at the point of use, that this is persistent storage on third-party infrastructure. Even with encryption, metadata, retention, relay availability, and deletion semantics can create privacy risk if users are not clearly informed before routine use.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to present all remembered information about a person on request encourages wholesale disclosure rather than contextual, least-necessary retrieval. This can surface outdated, overly broad, or sensitive data that the user did not expect to be aggregated and restated in one response.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The journaling examples explicitly direct the agent to persist behavioral observations such as frustration patterns and communication preferences. Storing psychological or behavioral profiling in durable memory is more sensitive than ordinary preferences and can expose users to privacy harms, misuse, or unexpected disclosure if recalled later or replicated across relays.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code accesses NOSTR_NSEC from the environment and immediately uses it to construct an identity, but the file provides no warning in comments, docstrings, or user-facing output that a private credential is required and will be used. For a code file, accessing sensitive environment variables should include some form of disclosure unless clearly documented elsewhere in the skill description, which is not evident here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This example performs memory and journal operations against a remote Nostr relay without any explicit user-facing notice that remembered values and journal content will leave the local process and be sent over the network. Because the example stores personal data such as name, timezone, and free-form journal text, users may unintentionally transmit sensitive information to third-party infrastructure under the assumption that 'memory' is local.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.