T09 · Insecure Skill Coding Practices
- Location
monitor_server.py:19- Finding
Unauthenticated Network Exposure of Memory Records and Workspace Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a plausible local memory/query tool, but it exposes memory data over an unauthenticated web server and installs persistent cron execution with weak controls.
Install only if you are comfortable with a local memory tool that writes persistent state and can set up recurring cron execution. Do not run the monitor server on a shared or network-reachable machine unless it is changed to bind to localhost and require authentication. Review setup_cron.sh before running it, especially the exact crontab entry and removal behavior.
monitor_server.py:19Unauthenticated Network Exposure of Memory Records and Workspace Files
setup_cron.sh:14User-Level Persistence Through Automatic Cron Registration
setup_cron.sh:5Unsafe Construction of Cron Commands from Unquoted Installation Paths
The skill presents itself as a productivity capability bundle, but accompanying artifacts indicate it may modify crontab, establish persistent scheduled execution, and write system-level logs or manage background tasks. Hidden persistence mechanisms are significantly more dangerous than ordinary query tooling because they can survive beyond the immediate session and perform recurring actions without continued user awareness.
The skill presents itself as a productivity capability bundle, but accompanying artifacts indicate it may modify crontab, establish persistent scheduled execution, and write system-level logs or manage background tasks. Hidden persistence mechanisms are significantly more dangerous than ordinary query tooling because they can survive beyond the immediate session and perform recurring actions without continued user awareness.
The reload path calls clear() before reloading, which deletes all stored memories and then attempts to rebuild state from files. If the reload is triggered accidentally, with a bad path, or when parsing fails, it can cause irreversible data loss or partial data destruction inconsistent with a simple query tool's purpose.
os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.
def refresh_status(self):
"""刷新状态"""
try:
os.system(f"cd {WORKSPACE} && python3 cron_monitor.py > /dev/null 2>&1")
except:
pass
The skill advertises executable capabilities and references tools/scripts that imply file read, file write, and shell access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization blind spot: an agent or reviewer cannot easily determine the intended execution boundary, increasing the risk of over-privileged use or accidental invocation of dangerous operations.
The file is presented as a natural-language memory query agent, but it also performs stateful synchronization, status tracking, logging, configuration mutation, and database reindex/reload operations. This scope expansion increases attack surface and allows a caller expecting read-only querying to trigger writes to disk and persistent state changes, which is risky in an agent-tool context.
The reload operation performs a full delete-and-reimport with no confirmation prompt, dry run, or rollback protection. This makes accidental invocation or misuse likely to destroy user data, especially because the tool's primary expected function is querying rather than destructive maintenance.
The CLI accepts arbitrary key/value configuration updates and persists them without restriction. In an agent setting, this lets callers alter runtime behavior such as logging paths, sync cadence, or other nested settings, creating unexpected persistent side effects and potential abuse of file writes or policy bypass.
The description is written entirely in Chinese, which implies a fixed language presentation without any indication that users can opt into another language or that the skill is region-specific. This can conflict with language/locale policy expectations when no user choice or justification is provided.
The /api/refresh endpoint causes server-side execution of cron_monitor.py on a simple GET request without authentication. This lets any reachable party trigger local actions repeatedly, creating an unnecessary remote execution surface and enabling abuse such as forced rescans, side effects in the script, or resource exhaustion.
A GET-accessible endpoint initiates subprocess-like behavior with no confirmation, authentication, or user awareness. In a monitoring context, users would reasonably expect passive observation, not a network-triggerable action that runs local maintenance code.
The monitoring server exposes the contents of the memory database, including content, descriptions, and source_file fields, through an unauthenticated API. Because the server binds to all interfaces and sets Access-Control-Allow-Origin: *, any reachable client or website can retrieve potentially sensitive stored memories, which goes far beyond a simple status page.
The API returns up to 100 memory records with raw content and metadata and does so without authentication or disclosure safeguards. In the context of a personal memory/assistant system, these records are likely to contain sensitive notes, prompts, or user-derived data, making the exposure especially dangerous.
This script checks for and manages a cron entry that repeatedly executes a local Python program every 30 minutes, which is a form of persistence. In the context of an agent skill, establishing scheduled execution can be dangerous because it causes ongoing code execution outside the user's immediate action and may continue syncing or processing data indefinitely.
echo "🔧 配置记忆数据库定时同步任务"
echo "======================================"
if crontab -l 2>/dev/null | grep -q "memory_query_agent.py"; then
echo "✅ 定时任务已存在"
crontab -l | grep "memory_query_agent"
else
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
if crontab -l 2>/dev/null | grep -q "memory_query_agent.py"; then
echo "✅ 定时任务已存在"
crontab -l | grep "memory_query_agent"
else
echo "📝 添加定时任务..."
(crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
if crontab -l 2>/dev/null | grep -q "memory_query_agent.py"; then
echo "✅ 定时任务已存在"
crontab -l | grep "memory_query_agent"
else
echo "📝 添加定时任务..."
(crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
if crontab -l 2>/dev/null | grep -q "memory_query_agent.py"; then
echo "✅ 定时任务已存在"
crontab -l | grep "memory_query_agent"
else
echo "📝 添加定时任务..."
(crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \
This line installs a recurring cron job that runs memory_query_agent.py every 30 minutes and writes to a log, creating durable scheduled execution. Even if intended for legitimate syncing, automatic persistence is security-relevant because it can continue operating on local data, execute code repeatedly, and survive beyond the current session without granular consent.
crontab -l | grep "memory_query_agent"
else
echo "📝 添加定时任务..."
(crontab -l 2>/dev/null | grep -v "memory_query_agent.py" | grep -v "memory_to_sqlite.py"; \
echo "*/30 * * * * cd $SCRIPT_DIR && python3 $PYTHON_SCRIPT --sync-now >> $LOG_FILE 2>&1") | crontab -
echo "✅ 已添加定时任务:"
echo " - 每 30 分钟同步一次"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
echo "💡 管理命令:"
echo " 查看日志:tail -f $LOG_FILE"
echo " 查看任务:crontab -l"
echo " 删除任务:crontab -e"
echo " 手动同步:python3 $PYTHON_SCRIPT --sync-now"
echo " 查看状态:python3 $PYTHON_SCRIPT --sync-status"
echo " 交互查询:python3 $PYTHON_SCRIPT -i"
The README content is written entirely in Chinese, including the title and usage sections, with no indication that users can choose another language. This can be a natural-language policy concern when a skill implicitly requires a specific language without user opt-in or justification.
The markdown explicitly states '中文智能查询', which presents the query capability as Chinese-only. Under the policy criteria, forcing a specific language without offering a language choice or documenting a justified locale constraint is a natural-language policy violation.
The skill's docstrings, prompts, help text, and output messages are written only in Chinese, indicating the skill is designed to operate in a fixed language without offering a user choice. This can violate language/locale policy when no opt-in or documented locale restriction is provided.
The metadata description lists several broad capabilities such as a natural-language query tool, monitoring service, and setup script, but it does not define any specific activation conditions, scope limits, or exclusion cases. In a manifest file, this can make invocation criteria ambiguous and increase the chance of unintended use.
The file-level docstring and user-facing strings are written exclusively in Chinese, with no indication that language selection is configurable or intentionally region-scoped. Per the policy, forcing a specific language without user opt-in can be a locale-policy violation.
This shell script's comments and all visible user-facing status messages are written in Chinese, with no indication that the skill is region-specific or that another language is available. That creates a natural-language policy concern under the locale/language rule because the file effectively enforces a specific language without user opt-in.
No suspicious patterns detected.