Back to skill

Security audit

xiaobai-memory-guard

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent memory-checking purpose, but it asks users to run unaudited mutable GitHub code and optionally wire it into every session or cron.

Review or vendor the actual memory-guard.mjs implementation before installing, pin it to a trusted immutable revision, and avoid adding the AGENTS.md startup block or cron job unless you intentionally want recurring access to agent memory files and git history under your user account.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:107
Finding

Execution of a Mutable Remote Payload Not Included in the Audited Package

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:121
Finding

Persistent Modification of Future Agent Startup Behavior

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
SKILL.md:138
Finding

Recurring Execution Through a Cron Scheduled Task

Content
View full analysis
> /tmp/memory-guard.log 2>&1 ``` ### Technical Analysis The recommended cron entry runs the referenced script every six hours, independently of an interactive Agent session. The script is absent from the audited package and is obtained through a mutable external repository. This creates an unattended execution mechanism that survives the initial skill run. If the script is replaced locally or updated from the upstream repository, the scheduled task will execute the replacement without requiring renewed approval. The command also appends output to the predictable path `/tmp/memory-guard.log`. Depending on host permissions and platform behavior, predictable shared temporary paths can create confidentiality, symlink, or log-tampering risks. The absence of the script prevents verification of the data written to this log. ### Attack Path 1. A user installs the recommended cron entry. 2. The task remains active across Agent sessions and system logins. 3. An attacker compromises the upstream repository, local skill directory, or update process. 4. The attacker replaces `memory-guard.mjs` with a malicious payload. 5. Cron executes the replacement at the next scheduled interval. 6. Execution continues every six hours until the task is discovered and removed. ### Impact Assessment Exploitation provides recurring code execution with the privileges of the user who owns the cron entry. This can enable: - Repeated access to Agent workspace data. - Periodic credential or environment inspection. - Modification of memory and handoff files. - Reinstallation of removed payloads. - Continued execution without an active Agent conversation. ...[truncated 188 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:145
Finding

Overbroad Enumeration of Sensitive Agent State and Repository History

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · README_EN.md (reported line 13)May include surrounding context.

md
- Long conversations → early context forgotten
- Session restarts → everything lost
- Token limits → important info truncated
- No warning when memory gaps occur

## The Solution

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation is entirely in Chinese, including the title, instructions, and usage guidance, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs automatic execution on every session start and even recommends integrating it into startup flow, but it does not define scope limits, consent boundaries, failure handling, or exclusions for sensitive environments. In an agent setting, unconditional startup scanning can trigger unnecessary filesystem and repository inspection on every run, increasing attack surface, causing privacy overreach, and enabling indirect denial-of-service or unintended data exposure if the workspace contains sensitive files or large repos.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file is an English-only README and links to a Chinese document, but it does not present language selection as an explicit user choice or explain any locale constraint. Under the policy rule, forcing a specific language without opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description presents the skill behavior in Chinese only, and the rest of the document also primarily instructs in Chinese without stating that the user can choose another language. This can violate language/locale policy when a skill effectively forces one language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.