Back to skill

Security audit

Thought-Retriever

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent memory-building purpose, but it automatically stores conversation-derived data and sends conversation and memory text to an external LLM using a bundled API key without enough user control.

Install only if you are comfortable with conversation content and stored memory snippets being sent to the configured external LLM service and saved locally after conversations. The publisher should replace the bundled API key with user-provided configuration, add explicit opt-in, redaction, retention and deletion controls, and review or quarantine new memories before they can influence later behavior.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
thought_retriever.py:31
Finding

Hard-Coded API Credential Exposed in Source Code

Content
View full analysis
`. 4. If the key remains valid, requests are billed to or attributed to the credential owner. 5. The attacker can continue using the credential until it is revoked, expires, or is restricted by the provider. ### Impact Assessment If active, the exposed key grants the attacker the API privileges assigned to that credential. Potential impact includes: - Unauthorized use of the associated LLM API. - Consumption of account quota and generation of charges. - Service disruption through ...[truncated 347 chars]
Remediation
View remediation

other

Warning
Location
thought_retriever.py:46
Finding

Conversation and Persistent Memory Content Sent to an External Service Without Data Minimization

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
thought_retriever.py:46
Finding

Untrusted Conversation Content Can Poison Persistent Agent Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code hardcodes an external API endpoint and secret key, then transmits conversation-derived content to that third-party service. In a memory/retrieval skill, this creates unjustified data exfiltration risk because user queries, generated answers, and stored thought content are sent off-box without clear necessity, consent, minimization, or local-only fallback.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill sends the user's query and generated answer to an external LLM service without any user-facing warning, consent flow, or privacy disclosure. This is dangerous because conversations may contain secrets, personal data, or proprietary information, and users are not informed that their content leaves the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly documents persistent storage of conversation-derived content into local memory files and describes registration as an automatic post-turn hook, but it does not present any user-facing warning, consent flow, retention limit, or opt-out. This creates a privacy and data-governance risk because users may unknowingly have prompts and derived content stored after every conversation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that each Thought stores the original user query in a persistent ontology entity. Retaining natural-language user questions can capture sensitive personal, business, or credential-like information, which may later be exposed through local file access, backups, downstream retrieval, or reuse by other components such as Evolver.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description states the skill runs after every conversation and automatically distills model outputs into reusable memory, but it does not define user consent, scope limits, or trigger constraints. In a memory/evolution skill, this can cause over-collection of sensitive conversational data and unintended persistence of private or unsafe content into long-term storage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file's natural-language comments, CLI description, and embedded prompts are written entirely in Chinese and the LLM prompt instructs output in that language context without any opt-in or language selection mechanism. This can violate a language/locale policy when users are not given a choice of language.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill derives new memory items from conversation content and persists them into long-term storage, while also using an external model to perform that extraction. This creates a natural-language data retention and leak channel: sensitive user content can be transformed into durable memory entries that may later be surfaced, searched, or transmitted again.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function claims a simple local keyword-matching approach, but actually performs external LLM calls for every stored thought to score relevance. This mismatch hides networked processing and expands the data exposure surface, because both current user input and stored memory entries may be transmitted externally under a misleading local-sounding interface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill automatically writes extracted 'thoughts' plus truncated user query content into persistent ontology storage without explicit notice or consent. This creates a long-term retention channel for sensitive or regulated information and may cause later unintended disclosure through retrieval or inspection of memory files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The prominent descriptive text is presented in Chinese, and the document does not state that language is configurable or user-selectable. Under the stated policy, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill behavior in that locale without indicating user choice or a region-specific justification. This can violate language or locale policy when the skill appears to assume a fixed language experience by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.