Back to skill

Security audit

Conversa Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it requests agent memory access that is not explained or needed for transcript analysis.

Review before installing in environments where skills can access agent memory. The transcript-analysis behavior is ordinary, but memory access should be removed or limited to an explicit user-selected memory record. Users should redact secrets, personal identifiers, regulated data, and confidential content before submitting transcripts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:8
Finding

Unnecessary Agent Memory Access Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–12
Vulnerability Type: Excessive tool permissions
Risk Level: Medium

yaml
allowed-tools:
  - read
  - write
  - memory_search
  - memory_get

Technical Analysis

The skill declares access to memory_search and memory_get, although its documented workflow only requires analyzing conversation text supplied in a user message or file. No documented operation requires access to unrelated Agent memory.

This configuration violates the principle of least privilege. In a host that exposes declared tools to the skill, these permissions could allow the Agent to search and retrieve persistent information that is unrelated to the transcript being analyzed. Transcript content may be untrusted and could contain prompt-injection instructions intended to induce use of the available memory tools.

The file does not explicitly instruct the Agent to retrieve or disclose memory, so this finding concerns unnecessary authorization and the resulting exposure surface rather than confirmed memory exfiltration. The skill does not declare a memory-writing tool, and therefore this is not classified as Agent Memory Poisoning.

Attack Path

  1. A host loads the skill and grants the tools declared under allowed-tools.
  2. A user supplies an untrusted conversation transcript containing instructions designed to influence the Agent's analysis.
  3. The injected content induces the Agent to call memory_search for terms associated with credentials, private conversations, identities, or prior tasks.
  4. The Agent calls memory_get to retrieve matching stored records.
  5. Retrieved information is incorporated into the generated conversation report or otherwise exposed in the current session.

This path requires a host that treats the declared tools as authorized and an Agent that follows the untrusted transcript instructions without enforcing a separation between transc ...[truncated 523 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove memory_search and memory_get from allowed-tools, retaining only tools strictly required by the documented workflow.
  2. Remove write as well if reports are only returned to the user and no file-output feature is required.
  3. If memory-backed transcript retrieval is an intended feature, require explicit user consent and selection of the exact memory record before access.
  4. Restrict searches to a user-approved namespace, conversation identifier, or bounded date range rather than allowing unrestricted memory queries.
  5. Treat all transcript content as untrusted data and explicitly prohibit following instructions embedded within analyzed transcripts.
  6. Prevent memory-derived content from being included in reports unless the user has expressly requested that specific content.
  7. Add tests confirming that ordinary transcript analysis never invokes memory tools and that prompt-injection text inside a transcript cannot trigger memory retrieval.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill is designed to process conversation transcripts, which commonly contain personal data, confidential business details, and sensitive interpersonal context. Omitting an explicit warning increases the chance that users will submit sensitive content without realizing the privacy implications, leading to unnecessary exposure, retention, or mishandling of private information.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The trigger section includes phrases like "extract decisions" and "what came out of this chat," which could plausibly appear in general conversation without clearly indicating invocation boundaries. The file does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is otherwise written in English, but the closing call-to-action is presented in Portuguese ("Gostou desta skill?") with no user opt-in or explanation. This creates an unnecessary language/locale inconsistency that can violate organizational language policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.