Back to skill

Security audit

Core Capabilities V2

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plausible local memory/query tool, but it exposes memory data over an unauthenticated web server and installs persistent cron execution with weak controls.

Install only if you are comfortable with a local memory tool that writes persistent state and can set up recurring cron execution. Do not run the monitor server on a shared or network-reachable machine unless it is changed to bind to localhost and require authentication. Review setup_cron.sh before running it, especially the exact crontab entry and removal behavior.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
monitor_server.py:19
Finding

Unauthenticated Network Exposure of Memory Records and Workspace Files

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Warning
Location
setup_cron.sh:14
Finding

User-Level Persistence Through Automatic Cron Registration

Content
View full analysis
/dev/null | grep -q "memory_query_agent.py"; then echo "✅ Scheduled task already exists" crontab -l | grep "memory_query_agent" else echo "📝 Adding scheduled task..." (crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \ echo "*/30 * * * * cd $SCRIPT_DIR && python3 $PYTHON_SCRIPT --sync-now >> $LOG_FILE 2>&1") | crontab - echo "✅ Scheduled task added:" echo " - Synchronizes every 30 minutes" echo " - Log file: $LOG_FILE" fi ``` ### Technical Analysis The setup script rewrites the invoking user's crontab and installs a job that runs `memory_query_agent.py --sync-now` every 30 minutes. This scheduled execution survives completion of the setup process, terminal closure, logout, and system restarts where cron is enabled. Recurring synchronization is part of the declared Skill functionality, so the behavior is not evidence of a concealed backdoor. Nevertheless, persistence is not necessary for manual memory querying and constitutes a continuing system modification that should require explicit informed consent. The filtering logic is also overly broad. It removes every existing crontab line containing either `memory_query_agent.py` or `memory_to_sqlite.py`, without verifying that those entries belong to this Skill installation. An unrelated scheduled task with a matching string may therefore be deleted. ### Attack Path 1. The user invokes `setup_cron.sh`. 2. The script reads the user's existing crontab. 3. It removes entries matching broad filename substrings. 4. It writes a new cron entry that invokes code from the current Skill directory every 30 minutes. 5. The scheduled job continues executing until the user manually edits or removes it. 6. If files in the Skill directory ar ...[truncated 582 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup_cron.sh:5
Finding

Unsafe Construction of Cron Commands from Unquoted Installation Paths

Content
View full analysis
/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \ echo "*/30 * * * * cd $SCRIPT_DIR && python3 $PYTHON_SCRIPT --sync-now >> $LOG_FILE 2>&1") | crontab - ``` ### Technical Analysis The script resolves its installation directory and interpolates that value directly into a cron command without shell-safe quoting. The resulting crontab line is later interpreted by a shell. A path containing spaces will split into multiple shell words and cause the scheduled task to fail or operate on unintended paths. Shell metacharacters in the directory name can alter the structure of the generated command. A newline in a path may also create an additional crontab line where the underlying filesystem permits such a name. The initial assignments are quoted correctly, but that protection is lost when their values are embedded unquoted into the generated cron expression. Because execution occurs later through cron, the dangerous parsing is deferred until the scheduled job runs. ### Attack Path 1. An attacker or untrusted deployment process controls or influences the directory in which the Skill is installed. 2. The directory name contains whitespace, shell metacharacters, or a newline designed to alter the generated cron text. 3. The user runs `setup_cron.sh`. 4. The script interpolates the unsafe path into the crontab without escaping. 5. Cron later passes the generated line to a shell. 6. The injected shell syntax executes with the privileges of the user who installed the scheduled task. ### Impact Assessment Successful exploi ...[truncated 467 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill presents itself as a productivity capability bundle, but accompanying artifacts indicate it may modify crontab, establish persistent scheduled execution, and write system-level logs or manage background tasks. Hidden persistence mechanisms are significantly more dangerous than ordinary query tooling because they can survive beyond the immediate session and perform recurring actions without continued user awareness.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill presents itself as a productivity capability bundle, but accompanying artifacts indicate it may modify crontab, establish persistent scheduled execution, and write system-level logs or manage background tasks. Hidden persistence mechanisms are significantly more dangerous than ordinary query tooling because they can survive beyond the immediate session and perform recurring actions without continued user awareness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The reload path calls clear() before reloading, which deletes all stored memories and then attempts to rebuild state from files. If the reload is triggered accidentally, with a bad path, or when parsing fails, it can cause irreversible data loss or partial data destruction inconsistent with a simple query tool's purpose.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · monitor_server.py (reported line 64)May include surrounding context.

python
def refresh_status(self):
        """刷新状态"""
        try:
            os.system(f"cd {WORKSPACE} && python3 cron_monitor.py > /dev/null 2>&1")
        except:
            pass

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises executable capabilities and references tools/scripts that imply file read, file write, and shell access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization blind spot: an agent or reviewer cannot easily determine the intended execution boundary, increasing the risk of over-privileged use or accidental invocation of dangerous operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file is presented as a natural-language memory query agent, but it also performs stateful synchronization, status tracking, logging, configuration mutation, and database reindex/reload operations. This scope expansion increases attack surface and allows a caller expecting read-only querying to trigger writes to disk and persistent state changes, which is risky in an agent-tool context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The reload operation performs a full delete-and-reimport with no confirmation prompt, dry run, or rollback protection. This makes accidental invocation or misuse likely to destroy user data, especially because the tool's primary expected function is querying rather than destructive maintenance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI accepts arbitrary key/value configuration updates and persists them without restriction. In an agent setting, this lets callers alter runtime behavior such as logging paths, sync cadence, or other nested settings, creating unexpected persistent side effects and potential abuse of file writes or policy bypass.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description is written entirely in Chinese, which implies a fixed language presentation without any indication that users can opt into another language or that the skill is region-specific. This can conflict with language/locale policy expectations when no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The /api/refresh endpoint causes server-side execution of cron_monitor.py on a simple GET request without authentication. This lets any reachable party trigger local actions repeatedly, creating an unnecessary remote execution surface and enabling abuse such as forced rescans, side effects in the script, or resource exhaustion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A GET-accessible endpoint initiates subprocess-like behavior with no confirmation, authentication, or user awareness. In a monitoring context, users would reasonably expect passive observation, not a network-triggerable action that runs local maintenance code.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The monitoring server exposes the contents of the memory database, including content, descriptions, and source_file fields, through an unauthenticated API. Because the server binds to all interfaces and sets Access-Control-Allow-Origin: *, any reachable client or website can retrieve potentially sensitive stored memories, which goes far beyond a simple status page.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The API returns up to 100 memory records with raw content and metadata and does so without authentication or disclosure safeguards. In the context of a personal memory/assistant system, these records are likely to contain sensitive notes, prompts, or user-derived data, making the exposure especially dangerous.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

This script checks for and manages a cron entry that repeatedly executes a local Python program every 30 minutes, which is a form of persistence. In the context of an agent skill, establishing scheduled execution can be dangerous because it causes ongoing code execution outside the user's immediate action and may continue syncing or processing data indefinitely.

Content

Scanner excerpt · setup_cron.sh (reported line 14)May include surrounding context.

sh
echo "🔧 配置记忆数据库定时同步任务"
echo "======================================"

if crontab -l 2>/dev/null | grep -q "memory_query_agent.py"; then
    echo "✅ 定时任务已存在"
    crontab -l | grep "memory_query_agent"
else

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · setup_cron.sh (reported line 16)May include surrounding context.

sh
if crontab -l 2>/dev/null | grep -q "memory_query_agent.py"; then
    echo "✅ 定时任务已存在"
    crontab -l | grep "memory_query_agent"
else
    echo "📝 添加定时任务..."
    (crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · setup_cron.sh (reported line 28)May include surrounding context.

sh
if crontab -l 2>/dev/null | grep -q "memory_query_agent.py"; then
    echo "✅ 定时任务已存在"
    crontab -l | grep "memory_query_agent"
else
    echo "📝 添加定时任务..."
    (crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · setup_cron.sh (reported line 33)May include surrounding context.

sh
if crontab -l 2>/dev/null | grep -q "memory_query_agent.py"; then
    echo "✅ 定时任务已存在"
    crontab -l | grep "memory_query_agent"
else
    echo "📝 添加定时任务..."
    (crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \

Session Persistence

Medium
Category
Rogue Agent
Confidence
98% confidence
Finding

This line installs a recurring cron job that runs memory_query_agent.py every 30 minutes and writes to a log, creating durable scheduled execution. Even if intended for legitimate syncing, automatic persistence is security-relevant because it can continue operating on local data, execute code repeatedly, and survive beyond the current session without granular consent.

Content

Scanner excerpt · setup_cron.sh (reported line 19)May include surrounding context.

sh
crontab -l | grep "memory_query_agent"
else
    echo "📝 添加定时任务..."
    (crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \
     echo "*/30 * * * * cd $SCRIPT_DIR && python3 $PYTHON_SCRIPT --sync-now >> $LOG_FILE 2>&1") | crontab -
    echo "✅ 已添加定时任务:"
    echo " - 每 30 分钟同步一次"

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · setup_cron.sh (reported line 34)May include surrounding context.

sh
echo "💡 管理命令:"
echo "  查看日志:tail -f $LOG_FILE"
echo "  查看任务:crontab -l"
echo "  删除任务:crontab -e"
echo "  手动同步:python3 $PYTHON_SCRIPT --sync-now"
echo "  查看状态:python3 $PYTHON_SCRIPT --sync-status"
echo "  交互查询:python3 $PYTHON_SCRIPT -i"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README content is written entirely in Chinese, including the title and usage sections, with no indication that users can choose another language. This can be a natural-language policy concern when a skill implicitly requires a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown explicitly states '中文智能查询', which presents the query capability as Chinese-only. Under the policy criteria, forcing a specific language without offering a language choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill's docstrings, prompts, help text, and output messages are written only in Chinese, indicating the skill is designed to operate in a fixed language without offering a user choice. This can violate language/locale policy when no opt-in or documented locale restriction is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The metadata description lists several broad capabilities such as a natural-language query tool, monitoring service, and setup script, but it does not define any specific activation conditions, scope limits, or exclusion cases. In a manifest file, this can make invocation criteria ambiguous and increase the chance of unintended use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file-level docstring and user-facing strings are written exclusively in Chinese, with no indication that language selection is configurable or intentionally region-scoped. Per the policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script's comments and all visible user-facing status messages are written in Chinese, with no indication that the skill is region-specific or that another language is available. That creates a natural-language policy concern under the locale/language rule because the file effectively enforces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.