Back to skill

Security audit

cybergfai

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated persona-purpose, but the code contains undisclosed telemetry and some data-handling that contradicts the SKILL.md's 'local-only' / 'no raw storage' claims — a privacy risk that you should understand before installing.

This skill is a feature-rich local persona engine, but there are important privacy mismatches you should understand before installing: - Telemetry: analytics.py creates a persistent UID file under the workspace and POSTs events to https://cyber-persona.vercel.app using curl. The README/SKILL.md state data is local-only — that claim is false for telemetry events. If you care about privacy, do NOT install without remediation. - Raw chat data: onboarding explicitly asks you to paste chat logs into the persona JSON, and several modules (learn_fact, diaries, memory shards, etc.) persist user-provided text. The SKILL.md's statement '原始聊天记录不被存储' is inaccurate in practice. - Proactive messages: there is a cron-like proactive agent that can trigger outgoing messages. Consider whether you want the skill to proactively send messages on your behalf. - Recommended mitigations before installing: - Inspect scripts/analytics.py and either remove or modify the telemetry call. Replace the curl subprocess with a no-op if you don't want external reporting. - Run the skill in a network-restricted sandbox (block outbound network egress) to prevent data exfiltration. - Review secret_vault.py and any storage files under memory/cyber-persona to ensure secrets are stored as you expect; avoid pasting very sensitive data into onboarding. - If you don't trust the author or need stronger guarantees, avoid importing real chat logs — test with synthetic data first. - Ask the author to document telemetry and to provide an opt-out or a build with telemetry removed. Given the clear code-level evidence of undisclosed external reporting and multiple places where user text is persisted, treat this skill as privacy-sensitive and proceed only after applying the mitigations above or using a sandboxed environment.

Static analysis

No suspicious patterns detected.