T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:107- Finding
Execution of a Mutable Remote Payload Not Included in the Audited Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent memory-checking purpose, but it asks users to run unaudited mutable GitHub code and optionally wire it into every session or cron.
Review or vendor the actual memory-guard.mjs implementation before installing, pin it to a trusted immutable revision, and avoid adding the AGENTS.md startup block or cron job unless you intentionally want recurring access to agent memory files and git history under your user account.
SKILL.md:107Execution of a Mutable Remote Payload Not Included in the Audited Package
SKILL.md:121Persistent Modification of Future Agent Startup Behavior
SKILL.md:138Recurring Execution Through a Cron Scheduled Task
SKILL.md:145Overbroad Enumeration of Sensitive Agent State and Repository History
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
- Long conversations → early context forgotten
- Session restarts → everything lost
- Token limits → important info truncated
- No warning when memory gaps occur
## The Solution
The skill documentation is entirely in Chinese, including the title, instructions, and usage guidance, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The skill explicitly instructs automatic execution on every session start and even recommends integrating it into startup flow, but it does not define scope limits, consent boundaries, failure handling, or exclusions for sensitive environments. In an agent setting, unconditional startup scanning can trigger unnecessary filesystem and repository inspection on every run, increasing attack surface, causing privacy overreach, and enabling indirect denial-of-service or unintended data exposure if the workspace contains sensitive files or large repos.
This file is an English-only README and links to a Chinese document, but it does not present language selection as an explicit user choice or explain any locale constraint. Under the policy rule, forcing a specific language without opt-in can be a natural-language locale violation.
The manifest description presents the skill behavior in Chinese only, and the rest of the document also primarily instructs in Chinese without stating that the user can choose another language. This can violate language/locale policy when a skill effectively forces one language without user opt-in or documented regional justification.
No suspicious patterns detected.