Back to skill

Security audit

PARA Memory System

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is purpose-aligned, but it needs review because it installs persistent agent instructions and keeps personal and project context indefinitely without clear consent, limits, or deletion controls.

Install only if you deliberately want workspace-level persistent memory. Before use, add rules requiring explicit approval before storing personal, business, or sensitive facts; exclude secrets and regulated data; keep memory files out of shared sync and source control; review AGENTS.md before installing it; and define a way to edit, redact, and delete stored notes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:38
Finding

Persistent instruction hijacking through automatically loaded mutable memory

Content
View full analysis
/status.md` - Decision made → log in today's `memory/YYYY-MM-DD.md` **Critical rule: never make "mental notes." If it's worth remembering, write it to a file.** ``` `assets/AGENTS-template.md:1-10`: ```markdown # AGENTS.md — Your Workspace This folder is home. Treat it that way. ## Session Startup Before doing anything else: 1. Read `life/tacit.md` — this is what you know about your human 2. Read `memory/YYYY-MM-DD.md` (today + yesterday) for recent context 3. If in main session (direct chat): also read `MEMORY.md` Don't ask permission. Just do it. ``` ### Technical Analysis The Skill directs the agent to copy persistent behavioral instructions into the workspace-level `AGENTS.md`. It then requires mutable files such as `life/tacit.md`, daily notes, and `MEMORY.md` to be l ...[truncated 3124 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:28
Finding

Excessive cleartext collection and indefinite retention of user and conversation data

Content
View full analysis
/status.md` - Decision made → log in today's `memory/YYYY-MM-DD.md` **Critical rule: never make "mental notes." If it's worth remembering, write it to a file.** ### Nightly consolidation Run during heartbeats or end-of-session: 1. Review today's `memory/YYYY-MM-DD.md` 2. Extract durable facts → update relevant `life/` files (Layer 1) 3. Extract lessons/preferences → update `life/tacit.md` (Layer 3) 4. Keep daily notes as raw archive (never delete them) ``` `assets/daily-template.md:3-19`: ```markdown ## What Happened - [Log conversations, decisions, and events as they happen] ## Decisions Made - [Record any decisions and the reasoning behind them] ## What Was Built/Shipped - [Track tangible outputs] ## New Information Learned - [About the user, the project, tools, etc.] ## Open Questions - [Things to follow up on] ## Next Steps - [What needs to happen tomorrow/next session] ``` `assets/tacit-template.md:6-32`: ```markdown ## About My Human - **Name:** [fill in] - **Timezone:** [fill in] - **Communication style:** [e.g., direct, detailed, casual] - **Tech stack:** [fill in if relevant] ## Working Style - [How do they prefer to receive information?] ...[truncated 3360 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to record user information, preferences, and session details into durable files without any explicit notice, consent flow, retention policy, or data-minimization guidance. This creates a clear privacy risk because sensitive personal or business information may be silently retained and reused across sessions beyond user expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is broad enough to trigger on many generic memory, recall, or organization requests, which increases the chance the skill activates in contexts where the user did not explicitly ask for durable storage. In this particular skill, overbroad activation is more dangerous because the skill's core behavior is to persist user and project information across sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These instructions operationalize long-term storage of user-specific facts, project context, and preferences in multiple files, turning transient conversation data into durable records. Even if intended to improve continuity, this materially increases exposure in the event of unauthorized access, misuse, or storage of information the user did not intend to preserve.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The directive to write down anything 'worth remembering' immediately encourages indiscriminate persistence rather than contextual judgment about privacy, necessity, or sensitivity. That raises the likelihood that secrets, personal details, or confidential business information are stored reflexively and permanently.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Nightly consolidation transforms raw daily logs into structured long-term knowledge and preference records, which amplifies privacy and security risk by increasing discoverability, reuse, and retention of user-specific data. The context makes this more dangerous because the workflow explicitly extracts durable facts and lessons from conversations without requiring renewed user approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template instructs the agent to automatically read life/tacit.md, recent daily memory files, and possibly MEMORY.md at session start, including personal and privacy-sensitive data, without requiring a user-triggered action or clear consent mechanism. This creates unnecessary default access to sensitive material and broadens data exposure in every session, increasing the chance of over-collection, accidental disclosure, or use of personal context beyond the user's immediate request.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · assets/AGENTS-template.md (reported line 65)May include surrounding context.

md
## Red Lines

- Don't exfiltrate private data. Ever.
- Don't run destructive commands without asking.
- `trash` > `rm` (recoverable beats gone forever)
- When in doubt, ask.

Static analysis

No suspicious patterns detected.