Back to skill

Security audit

Think Expand

Security checks for vulnerabilities and agentic risk

Overview

This skill is an always-on orchestration core that asks to monitor inputs, persist learning, import remote skills, profile user habits, and monitor the clipboard without enough scoping or user control.

Review this skill carefully before installing. It should only be used in a controlled internal environment after removing or gating always-on activation, clipboard monitoring, user profiling, autonomous GitHub imports, and persistent self-evolution behind explicit user approval, provenance checks, and deletion controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:12
Finding

Global Agent Control Through Mandatory Skill Activation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-15 and 40-44
Vulnerability Type: Agent-wide instruction and role hijacking
Risk Level: High

Complete Evidence Snippet — English rendering of the source instructions:

markdown
## Original capabilities (must always run)
- Automatically activate at system startup as the AI decision-making brain
- All input must first be processed by "Think" for decision-making, scheduling, and execution
- Crash recovery: self-check every 60 seconds and automatically restart on failure

## Trigger scenarios
- Automatically activate at system startup
- All user input must first be processed by think-expand
- Responsible for deciding which core or skill to invoke
- Coordinate the hear, see, speak, do, and learn cores

Technical Analysis

The skill appoints itself as a mandatory, globally active decision layer rather than a user-invoked capability. Requiring every user input to pass through the skill allows its instructions to alter prompt routing, task selection, and tool invocation for unrelated requests.

This violates instruction scoping and least authority. Once loaded, the skill can influence the entire active agent session instead of remaining restricted to a specific requested operation. The automatic-start and mandatory-processing directives also make it difficult for the user or orchestrator to bypass the skill.

Attack Path

  1. The agent discovers or loads think-expand.
  2. The startup directive causes the skill to treat itself as automatically active.
  3. Every subsequent user input is routed through the skill.
  4. The skill selects other cores or skills and controls task scheduling.
  5. Unrelated requests can consequently be redirected or modified according to the skill's persistent orchestration instructions.

Impact Assessment

Successful exploitation provides control over agent-level request routing and decision-making withi ...[truncated 279 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove all automatic-start and mandatory global-processing directives.
  • Require explicit user invocation for each operation.
  • Restrict the skill to the current task and prohibit it from redefining global agent roles.
  • State explicitly that system, developer, user, and platform security policies take precedence.
  • Require user confirmation before dispatching work to another skill or tool.
  • Add an allowlist of permitted downstream capabilities and deny access to unrelated tools.
  • Provide a visible mechanism to disable the skill and terminate any ongoing orchestration.

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:27
Finding

Persistent Self-Modification and User-Behavior Profiling

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27-30, 46-48, and 67-70
Vulnerability Type: Persistent memory poisoning and unauthorized behavioral profiling
Risk Level: High

Complete Evidence Snippet — English rendering of the source instructions:

markdown
4. Self-evolution: experience accumulation, skill generation, automatic optimization, and continuous evolution
5. Perpetual operation: continuously run and automatically restart after a crash

## Integration
- Send decision results to `speak-expand` and `do-expand`
- Store evolution records in `mempalace_wings/self_evolution/`
- Store the skill index in `learned.db` for real-time queries

## Self-evolution capabilities
- Automatic learning: periodically scan GitHub for new skills and absorb them
- Cross-domain fusion: create skill combinations
- Predictive analysis: record user habits and predict subsequent needs
- Local LLM: support offline inference through Ollama or LM Studio

Technical Analysis

The skill directs the agent to transform accumulated experience into generated or optimized skills and persist evolution records and indexes on disk. It also instructs the system to record user habits for predictive analysis.

No consent mechanism, data-retention policy, provenance tracking, validation boundary, integrity protection, or rollback process is defined. Consequently, attacker-controlled prompts or retrieved content could be incorporated into persistent state and affect later sessions. Behavioral profiling may also retain sensitive information inferred from user activity without informed consent.

Attack Path

  1. An attacker supplies crafted instructions or content during an interaction.
  2. The skill treats the interaction as experience suitable for learning or optimization.
  3. Derived records or generated skill material are written to the evolution directory or learned.db.
  4. Later queries or startup operatio ...[truncated 711 chars]
Remediation
View remediation

Remediation Suggestions

  • Disable autonomous writes to long-term memory and generated skill stores.
  • Require explicit, informed user approval before retaining user-related information.
  • Separate untrusted observations from trusted behavioral rules.
  • Validate persisted records against a strict schema and reject executable instructions.
  • Record source provenance, creation time, author, and integrity hashes for every entry.
  • Apply retention limits, data minimization, encryption, and per-user isolation.
  • Require human review before generated content can become an active skill.
  • Provide inspection, deletion, versioning, and rollback controls.
  • Never use learned state to override higher-priority instructions or security policy.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:32
Finding

Automatic Retrieval and Integration of Unpinned GitHub Skills

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 32-36 and 67-68
Vulnerability Type: Mutable remote payload acquisition and unsafe supply-chain integration
Risk Level: Critical

Complete Evidence Snippet — English rendering of the source instructions:

markdown
## Built-in absorption process
1. Triggered by "learn/absorb": automatically search GitHub for highly starred skills
2. Extract information into learned.db and sort it by star count
3. Compare it with existing skills and discard it if it is below the threshold
4. Integrate it into skills_learned after compatibility verification
5. Return the result to speak-expand

## Self-evolution capabilities
- Automatic learning: periodically scan GitHub for new skills and absorb them

Technical Analysis

The skill directs the agent to discover remote skills on GitHub and integrate them into a local active skill directory. The instructions do not require an approved repository allowlist, immutable commit identifiers, cryptographic signatures, checksums, reproducible builds, permission manifests, sandboxing, or human review.

Repository popularity and star count do not establish authenticity or safety. A repository can be compromised, transferred, malicious from inception, or modified after an audit. Compatibility validation is not equivalent to security validation. Integration into skills_learned creates a channel through which post-review remote content may later influence instructions or execute code, depending on the downstream skill loader.

Attack Path

  1. An attacker creates or compromises a GitHub repository that satisfies the discovery criteria.
  2. The periodic scan or a learning trigger discovers the repository.
  3. Star-based ranking and compatibility checks accept the skill.
  4. The remote content is copied or integrated into skills_learned.
  5. The agent's skill loader subsequently loads or invokes the newly integrated c ...[truncated 684 chars]
Remediation
View remediation

Remediation Suggestions

  • Disable automatic discovery and installation of remote skills.
  • Restrict acquisition to an administratively maintained repository allowlist.
  • Pin every dependency to an immutable commit and verify cryptographic signatures and checksums.
  • Require a declared permission manifest for filesystem, network, process, memory, and tool access.
  • Perform static and dynamic security analysis in an isolated sandbox before installation.
  • Prohibit installation based solely on stars, popularity, or compatibility.
  • Require explicit human approval before activation or updates.
  • Separate downloaded content from active skill directories until validation is complete.
  • Run accepted skills with minimal filesystem, network, and process privileges.
  • Preserve an auditable installation record and support immediate revocation and rollback.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:72
Finding

Unnecessary Continuous Clipboard Monitoring

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 72-76
Vulnerability Type: Access to privacy-sensitive clipboard data beyond the stated task requirements
Risk Level: High

Complete Evidence Snippet — English rendering of the source instructions:

markdown
## Offline capabilities
- Basic functions can operate without relying on an external network
- The local skill library is available at any time
- Clipboard monitoring runs independently

Technical Analysis

Independent clipboard monitoring is not necessary for the skill's stated reasoning and orchestration purpose. Clipboard contents commonly include passwords, authentication tokens, private messages, personal identifiers, financial information, and copied source code.

The instruction does not define user consent, activation duration, filtering, access controls, retention, or secure disposal. Continuous or independent monitoring therefore violates least-privilege principles. The reviewed document does not specify an exfiltration endpoint, so remote transmission is not established by the available evidence.

Attack Path

  1. The skill or an associated component starts independent clipboard monitoring.
  2. A user copies a password, token, private message, or other sensitive value.
  3. The monitoring component reads the clipboard value outside a task-specific request.
  4. The captured value becomes available to the skill or associated local components.
  5. If combined with another compromised or remotely acquired skill, the sensitive value could be misused within the permissions of the agent.

Impact Assessment

The capability can expose any information copied by the current desktop user while monitoring is active. This may include credentials and session tokens that enable access to unrelated applications or services. The reviewed file does not establish whether clipboard values are persisted or transmitted, and no implementation wa ...[truncated 37 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove clipboard monitoring from this skill.
  • If clipboard access is essential, require explicit user action for each read.
  • Make access visible, narrowly scoped, and automatically terminated after the requested operation.
  • Filter and redact credential-like values before processing.
  • Do not persist clipboard contents or include them in learning and profiling systems.
  • Isolate clipboard access from remotely acquired skills and other untrusted components.
  • Record privacy-preserving access events for audit purposes without logging clipboard contents.
  • Provide a clear permission control that defaults to disabled.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares that it must always run, auto-activates at startup, and processes all input first. Overly broad trigger scope gives one skill effective control over the entire agent pipeline, so any flawed logic, prompt injection, or unintended behavior in this component can affect every user interaction and downstream action selection.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger scenario explicitly states that all user input passes through think-expand before any other handling. In context, this is especially dangerous because the same skill also claims authority over memory retrieval, task dispatch, and self-evolution, making it a single chokepoint for manipulation, surveillance, or unsafe autonomous decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill openly describes recording user habits and predicting demand without any privacy notice, consent, retention limit, or access control description. Behavioral profiling can expose sensitive personal patterns, create invisible surveillance, and be repurposed for manipulation or leakage if the stored data is accessed by other components.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Clipboard monitoring is mentioned as an offline capability without any warning about exposure of sensitive data. Clipboard contents frequently contain passwords, tokens, private messages, or financial data, so background monitoring can silently capture high-value secrets and dramatically broaden the skill's access to user information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill documentation is entirely presented in Chinese and labels the skill for internal use, but it does not indicate that language selection is configurable or that Chinese is a required locale for a region-specific purpose. This can be a natural-language policy concern when the skill implicitly constrains interaction language without user opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as a central decision/coordination core, but it also claims autonomous GitHub scanning, ingestion, compatibility validation, and integration of new skills into local storage. That expands its authority from orchestration into self-modifying code/content acquisition, which creates a supply-chain risk and enables unreviewed capability growth beyond the user's expectation of a coordinator.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes automatic learning from GitHub and writing data into local databases and directories without any warning or consent flow. This creates both network-exposure and local-modification risks: users may unknowingly allow remote content ingestion, persistent storage changes, and introduction of malicious or low-quality external artifacts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation states that the skill records user habits and predicts future needs, which introduces profiling behavior unrelated to the narrowly stated role of a central decision core. This expands data collection and inference about the user without clear necessity, increasing privacy risk and the chance of overcollection or misuse of behavioral data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to record user habits and predict future needs implies retention and secondary use of behavioral data. In this skill's context, that is more dangerous because the component is positioned as the central always-on core, so it may observe broad interaction history and accumulate a detailed user profile over time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.