Back to skill

Security audit

Agent Reflective Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple local memory tool whose persistence is disclosed and purpose-aligned, though users should treat stored memories as plaintext sensitive data.

Install only if you are comfortable with agent experiences being saved in plaintext locally. Run it in a private project directory, avoid storing secrets, credentials, regulated data, or sensitive user details, and delete memory_store.json when the retained history is no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
tool.py:16
Finding

Unsafe Persistent Memory File Handling

Content
View full analysis

Vulnerability Details

File Location: tool.py, lines 16 and 22–29
Vulnerability Type: Plaintext sensitive-data storage, predictable file path, symlink following, and non-atomic writes
Risk Level: Medium

Vulnerable Code

python
MEMORY_STORE_FILE = "memory_store.json"
python
def load_memory(self) -> Dict[str, Any]:
    if os.path.exists(self.persistence_file):
        with open(self.persistence_file, "r") as f:
            return json.load(f)
    return {"experiences": [], "reflections": []}

def save_memory(self):
    with open(self.persistence_file, "w") as f:
        json.dump(self.memory, f, indent=2)

Technical Analysis

The application stores agent contexts, actions, results, metadata, and reflections in plaintext at the predictable relative path memory_store.json. It does not explicitly enforce restrictive file permissions, verify that the destination is a regular file owned by the expected user, reject symbolic links, or use atomic file replacement.

Python's ordinary open() follows symbolic links. Opening the file with mode "w" truncates the resolved destination before writing. Consequently, if the program runs in a directory writable by an attacker, the attacker can pre-create memory_store.json as a symbolic link to another file writable by the victim process. A subsequent store or reflect operation may overwrite that target with JSON content.

The load path also accepts untrusted JSON without schema, ownership, or integrity validation. An attacker able to modify the storage file can inject fabricated experiences and reflections that are later returned by queries or processed by reflection logic. This is a local integrity concern; the audited implementation does not execute stored content as code or send it to a remote service.

Attack Path

  1. A victim runs the tool from a shared or attacker-writable working directory.
  2. The attacker creates memory_store.json as a symbolic link to another file ...[truncated 1260 chars]
Remediation
View remediation

Remediation Suggestions

  1. Store persistent data in a dedicated per-user application-data directory rather than the current working directory.
  2. Create the directory with restrictive permissions such as 0700, and create the memory file with mode 0600.
  3. Reject symbolic links and non-regular files. On supported platforms, open files using os.open() with O_NOFOLLOW, then verify the descriptor with os.fstat().
  4. Validate the file's owner and permissions before reading or replacing it.
  5. Implement atomic persistence by writing to a securely created temporary file in the same directory, flushing and synchronizing it, setting restrictive permissions, and replacing the destination with os.replace().
  6. Apply a strict JSON schema and type validation before accepting stored experiences or reflections.
  7. If memory integrity must be protected from local modification, authenticate the serialized data with a key stored separately from the memory file.
  8. Document that contexts, actions, results, and metadata may contain sensitive information, and provide retention, redaction, and secure-deletion controls.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly markets long-term storage of agent experiences, including user-related context and past actions, but provides no warning about privacy, retention, consent, or handling of sensitive data. This creates a real risk that developers will persist personal, confidential, or regulated information in memory without safeguards, increasing exposure through over-collection, long retention, and later retrieval or reflection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool stores arbitrary context, action, result, and metadata directly to a local JSON file without any notice, consent flow, minimization, or protection. In an agent setting, these fields can easily contain secrets, personal data, tokens, prompts, or sensitive operational history, so silent persistence increases the risk of unintended disclosure through local access, backups, logs, or later exfiltration by other components.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.