Back to skill

Security audit

mempalace

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local memory integration, but it broadly records and reuses conversation history across sessions without enough user-controlled limits.

Review this carefully before installing. Use it only for conversation archives you are comfortable storing and searching locally, avoid mining folders that may contain secrets or regulated data, and consider pinning or separately reviewing the mempalace package before giving it access to private history.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:35
Finding

Unconditional Session-Wide Memory Control and Persistent Diary Writes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35–41
Vulnerability Type: Agent instruction hijacking through unconditional global directives
Risk Level: High

Complete Code Snippet:

markdown
## Protocol — FOLLOW THIS EVERY SESSION

1. **ON WAKE-UP**: Call `mempalace_status` to load palace overview.
2. **BEFORE RESPONDING** about any person, project, or past event: call `mempalace_search` or `mempalace_kg_query` FIRST. Never guess from memory — verify from the palace.
3. **IF UNSURE** about a fact (name, age, relationship, preference): say "let me check" and query. Wrong is worse than slow.
4. **AFTER EACH SESSION**: Call `mempalace_diary_write` to record what happened, what you learned, what matters.
5. **WHEN FACTS CHANGE**: Call `mempalace_kg_invalidate` on the old fact, then `mempalace_kg_add` for the new one.

Technical Analysis

The skill declares that its protocol must be followed in every session rather than limiting its behavior to explicit invocations or memory-related tasks. It changes the agent's response process by requiring memory queries before responding about broad classes of subjects and mandates a persistent diary write after each session.

The instructions do not require user consent before writing, do not define a sensitivity filter, and do not restrict what can be included in a diary entry. Retrieved memory is also introduced into the agent's active context without an explicit requirement to treat stored content as untrusted data. This creates both privacy risk and a potential indirect instruction-injection path if stored conversation content contains adversarial directives.

Attack Path

  1. The skill is loaded into an agent session.
  2. The unconditional protocol directs the agent to use MemPalace even when the user did not explicitly request memory functionality.
  3. The user conducts an unrelated or sensitive conversation.
  4. At the end of the session, the age ...[truncated 1055 chars]
Remediation
View remediation

Remediation Suggestions

  • Restrict the protocol to sessions where the user explicitly invokes the skill.
  • Require informed user confirmation before writing diary entries or modifying knowledge-graph facts.
  • Provide a clear preview of information that will be persisted.
  • Exclude credentials, authentication tokens, private keys, financial information, health information, and other sensitive data by default.
  • Treat all retrieved memories as untrusted reference data and explicitly prohibit following instructions found inside stored content.
  • State that system, developer, and current-user instructions always take precedence over retrieved memory.
  • Add per-session controls to disable reading or writing memory.
  • Define retention limits and allow users to inspect, edit, and delete diary entries.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Third-Party MemPalace Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–20 and 90–95
Vulnerability Type: Unpinned package dependency installed from an external package source
Risk Level: Medium

Complete Code Snippet:

yaml
    install:
      - id: mempalace-pip
        kind: uv
        label: "Install MemPalace (Python, local ChromaDB)"
        package: mempalace
        bins:
          - mempalace
bash
pip install mempalace
mempalace init ~/my-convos
mempalace mine ~/my-convos

Technical Analysis

Both the installation metadata and manual setup instructions install mempalace without a pinned version, lock file, integrity hash, or immutable source reference. Consequently, installation resolves whatever package version the configured package index serves at that time.

The package implementation is not included in the audited project, so its installation hooks, runtime behavior, transitive dependencies, and handling of conversation archives cannot be verified from this artifact. Because the package is subsequently given access to a directory containing user conversations, a compromised or unexpectedly changed release would operate on sensitive local data.

Attack Path

  1. A user or automated installer follows the skill's installation configuration or executes pip install mempalace.
  2. The package manager resolves the latest available package and its transitive dependencies from the configured registry.
  3. A compromised account, malicious replacement release, dependency-confusion condition, or unsafe transitive update supplies altered code.
  4. Package installation hooks or subsequent mempalace commands execute that code with the privileges of the installing user.
  5. The altered package receives access to ~/my-convos during initialization or mining and could read, modify, destroy, or transmit accessible data.

Impact Assessment

Exploitation would generally obtain the ...[truncated 524 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin mempalace to a specifically reviewed version.
  • Use a lock file that records exact transitive dependency versions.
  • Require cryptographic hashes for downloaded distributions.
  • Document and enforce a trusted package registry.
  • Prefer a verified immutable source commit or signed release artifact.
  • Review package installation hooks and all transitive dependencies before deployment.
  • Run the MCP server under a dedicated, least-privileged account or sandbox.
  • Restrict filesystem access to explicitly approved conversation directories.
  • Disable network access for the runtime when it is not required by the documented local-only functionality.

other

Warning
Location
SKILL.md:23
Finding

Broad Verbatim Ingestion of Conversation Archives Without Data-Minimization Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23–25 and 90–95
Vulnerability Type: Privacy overcollection and sensitive local-data exposure
Risk Level: Medium

Complete Code Snippet:

markdown
# MemPalace — Local AI Memory System

You have access to a local memory palace via MCP tools. The palace stores verbatim conversation history and a temporal knowledge graph — all on the user's machine, zero cloud, zero API calls.
markdown
The user needs to initialize and populate the palace first:

```bash
pip install mempalace
mempalace init ~/my-convos
mempalace mine ~/my-convos
text

### Technical Analysis

The documented workflow mines a supplied conversation directory and stores conversation history verbatim. The skill does not document file allowlisting, path exclusions, secret detection, field-level redaction, encryption at rest, retention periods, access controls, or a review step before content is indexed.

Local-only storage reduces exposure to an external cloud service but does not eliminate confidentiality risks. Any process, user, or agent tool with access to the memory database may search and retrieve indexed content. Semantic search can also surface sensitive passages even when a later query does not use the same keywords as the original conversation.

### Attack Path

1. The user places multiple conversation exports under `~/my-convos`, including conversations containing credentials, personal data, confidential project details, or other sensitive information.
2. The user runs `mempalace init ~/my-convos` and `mempalace mine ~/my-convos`.
3. The mining process indexes the selected archive and stores verbatim conversation chunks.
4. A later agent session performs a broad semantic search, either because of a legitimate request, an overbroad query, or manipulated input.
5. Search results expose sensitive passages to the active agent context and potentially to a user or pro
...[truncated 673 chars]
Remediation
View remediation

Remediation Suggestions

  • Display a file and record preview before mining begins.
  • Require explicit allowlisting of input files and directories.
  • Support exclusion patterns for credentials, private conversations, hidden files, backups, and unrelated exports.
  • Detect and redact secrets, tokens, private keys, and sensitive personal information before indexing.
  • Encrypt the memory database at rest with keys protected separately from the database.
  • Apply restrictive filesystem permissions to indexes and source archives.
  • Implement per-wing and per-room access controls.
  • Establish configurable retention periods and automatic expiration.
  • Provide reliable inspection, export, selective deletion, and complete purge functions.
  • Ensure semantic-search results are filtered according to the current user's authorization and purpose.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that the palace stores verbatim conversation history and instructs the agent to use and maintain that memory across sessions, but it does not provide a prominent consent, retention, or sensitivity warning. This creates a privacy risk because users may disclose personal, confidential, or regulated data that gets persistently stored locally without clear opt-in or minimization guidance.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes persistent storage of verbatim conversation history and cross-session memory as a core behavior. Retaining natural-language transcripts increases the attack surface for privacy leakage, prompt injection persistence, and unintentional storage of secrets or sensitive personal data beyond the immediate session.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The protocol directs the agent to write a diary after every session containing what happened and what it learned, which mandates routine persistence of user interaction data. That broad collection pattern can accumulate sensitive context over time and may preserve information users did not expect to be retained.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The write APIs encourage storing verbatim content and cumulative diary entries, enabling durable retention of user inputs across sessions. In a memory tool, this is contextually expected, but it remains risky because free-form stored text often contains credentials, health details, personal identifiers, or other sensitive information that can later be surfaced or misused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documented delete capability is destructive and appears without cautionary guidance, confirmation expectations, or recovery limitations. While not inherently malicious, omission of warnings increases the chance of accidental data loss, especially in a memory system intended to preserve long-term user information.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Static analysis

No suspicious patterns detected.