Back to skill

Security audit

interaction-record-archive

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about archiving conversations, but it installs persistent hooks that send raw prompts and assistant replies to a ByteDance endpoint, so it should be reviewed before use.

Install only in an explicitly approved ByteDance/internal environment where raw prompt and response archiving is expected. Review the endpoint, retention policy, access controls, and whether SYNC_TOKEN is required; set SYNC_ENABLE=0 if archival should be disabled. Avoid installing this in personal, external, customer, or secret-bearing projects unless the organization has approved sending full conversations to that endpoint.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code collects full user prompts and assistant responses and sends them off-host, creating a clear data exfiltration channel for sensitive content. In skill context, this is especially risky because agent conversations commonly contain credentials, source code, internal paths, incident details, or regulated data; the internal-domain allowlist reduces but does not eliminate the danger.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes automatic collection and transmission of user prompts, assistant replies, session metadata, and potentially transcript-derived content, and its installation registers hooks that run on user and stop events. Although the behavior appears intended for internal archival, the manifest does not declare any explicit tool scope or permissions despite requiring environment access, file reads/writes, shell execution, and network-capable behavior, which weakens reviewability and increases the risk of overbroad data access or unintended deployment in less-trusted environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installer silently creates or modifies .trae/hooks.json and enables a hook script that captures user prompts and assistant responses for later transmission, without any explicit user confirmation at install time. Because this skill’s stated purpose is interaction archiving, the behavior is expected in context, but it still creates a meaningful security and privacy risk by establishing persistent monitoring of future conversations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The curl invocation performs external transmission of collected conversation data to a configured endpoint, which is a genuine exfiltration behavior. Although restricted to specific corporate domains, it still moves potentially sensitive content outside the local execution boundary, so compromise or misuse of the receiving service would expose archived conversations.

Content

Scanner excerpt · scripts/sync.sh (reported line 53)May include surrounding context.

sh
local headers=(-H "content-type: application/json" -H "user-agent: conversation-archive/2.0")
  [ -n "$TOKEN" ] && headers+=(-H "authorization: Bearer ${TOKEN}")
  local code
  code="$(curl --max-time "$TIMEOUT" -s -o /dev/null -w '%{http_code}' \
    -X POST "$ENDPOINT" "${headers[@]}" -d @"$body_file" 2>/dev/null || echo 000)"
  audit "$session_id" "$code"
  printf '%s' "$code"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script exfiltrates conversation content to a remote endpoint via curl with no user-facing notice, prompt, or consent flow. Even though the description says this is for an authorized internal archive and the destination is allowlisted to internal domains, the data includes raw prompts and assistant replies, which can contain secrets, proprietary code, or personal data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file contains natural-language content only in Chinese ("团队归档空间地址(内部域)"). Per the policy, forcing a specific language without opt-in or documented justification can be a language/locale policy violation, and no alternative language or rationale is provided here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script reads SYNC_TOKEN from the environment and uses it as a bearer token for outbound requests. There is no visible user-facing notice in this file that the skill accesses credential material from the environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.