{"data":{"skill":{"slug":"remembering-conversations","name":"remembering-conversations","icon":"📦","repo":"https://github.com/obra/episodic-memory/tree/main/skills/remembering-conversations/","status":"approved","author":"obra","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"895812e1-0407-41a3-a882-516f77b5c1c2","skill_id":"34d775e3-7a55-4029-8327-7873bb69bce3","version":2,"content_hash":"2a0685453a77ae8b94728b9ab13ade7a","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported many command execution and weak cryptography patterns, but these are Markdown formatting and prose false positives. The confirmed concern is legitimate but sensitive access to past conversation memory through MCP search and read tools, including conversation files addressed by absolute path.","remediation":[],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"MCP-TOOLS.md","line_end":95,"line_start":93},{"file":"MCP-TOOLS.md","line_end":102,"line_start":102},{"file":"MCP-TOOLS.md","line_end":109,"line_start":109}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Conversation History Access Requires Privacy Review","locations":[{"file":"SKILL.md","line_end":29,"line_start":25},{"file":"MCP-TOOLS.md","line_end":95,"line_start":83},{"file":"MCP-TOOLS.md","line_end":112,"line_start":99}],"confidence":0.86,"description":"The skill instructs agents to search past conversations and use MCP tools that can read archived conversation files by path. This is a legitimate memory workflow, but it may expose sensitive prior user messages, tool outputs, or project details if used without clear task relevance.","confidence_reasoning":"The files explicitly describe searching previous conversations and reading full conversation archives. The behavior is intended, so the risk is privacy exposure rather than confirmed malicious activity."}],"low_findings":[{"title":"External Command Findings Are Markdown False Positives","locations":[{"file":"SKILL.md","line_end":23,"line_start":16},{"file":"SKILL.md","line_end":61,"line_start":57},{"file":"MCP-TOOLS.md","line_end":20,"line_start":9},{"file":"MCP-TOOLS.md","line_end":26,"line_start":24},{"file":"MCP-TOOLS.md","line_end":59,"line_start":30},{"file":"MCP-TOOLS.md","line_end":81,"line_start":75}],"confidence":0.94,"description":"Static analysis treated Markdown backticks and fenced examples as Ruby shell execution. The referenced lines document tool names, parameters, and example payloads; no executable script or shell invocation is present.","confidence_reasoning":"The surrounding context is Markdown documentation and typed examples. I found no code file, interpreter directive, or executable command path in these locations."},{"title":"Weak Cryptography Findings Are Prose False Positives","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"MCP-TOOLS.md","line_end":13,"line_start":13},{"file":"MCP-TOOLS.md","line_end":22,"line_start":22},{"file":"MCP-TOOLS.md","line_end":91,"line_start":91}],"confidence":0.91,"description":"Static analysis flagged lines as weak cryptography, but the cited locations contain description text, prompt template fields, headings, and parameter tables. No cryptographic API, hash function call, or security-sensitive algorithm use is present.","confidence_reasoning":"The cited content is documentation, not implementation. There is no evidence of MD5, SHA1, DES, or other weak cryptographic code in these files."},{"title":"System Reconnaissance Findings Are Benign Text","locations":[{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"MCP-TOOLS.md","line_end":125,"line_start":125}],"confidence":0.9,"description":"The scanner flagged lines as reconnaissance, but the cited text is ordinary guidance and error documentation. No command gathers host, network, user, process, or environment information.","confidence_reasoning":"Both locations are plain Markdown bullets. I found no evidence of system inspection commands or instructions to enumerate the host environment."}],"dangerous_patterns":[{"title":"MCP Read Tool Accepts Conversation File Paths","locations":[{"file":"MCP-TOOLS.md","line_end":95,"line_start":83},{"file":"MCP-TOOLS.md","line_end":112,"line_start":99}],"confidence":0.84,"description":"The documented read tool accepts an absolute path to a JSONL conversation archive. This creates a privacy-sensitive filesystem capability that should be scoped to relevant memory searches and user intent.","confidence_reasoning":"The parameter table and examples explicitly show path-based conversation reads. The risk depends on tool enforcement and usage context, so it is medium confidence rather than a confirmed exploit."}],"files_scanned":2,"total_lines":204,"audit_model":"codex","audited_at":"2026-06-30T11:18:24.375+00:00","created_at":"2026-06-30T11:57:10.067495+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":3,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}