T09 · Insecure Skill Coding Practices
- Location
hooks/apm_session_start/handler.js:357- Finding
Fail-Open Group Detection Injects Private DM Memory into Group Sessions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed memory-management system, but its own hook code can automatically expose private DM memory in group sessions when chat mapping or detection fails.
Review carefully before installing in any workspace with private notes or group chats. Use it only if you are comfortable with automatic memory bootstrap and persistence, and avoid group use until the DM fallback and flush-state separation are fixed to fail closed.
hooks/apm_session_start/handler.js:357Fail-Open Group Detection Injects Private DM Memory into Group Sessions
hooks/apm_session_start/handler.js:184Untrusted Persistent Memory Is Promoted into Agent Bootstrap Instructions
hooks/remem-flush/handler.js:119Flush Hooks Mix Group Metadata into the DM-Only State File
ADDENDUM.md:5Memory Templates Encourage Plaintext Storage of Sensitive Infrastructure Information
This document defines behavior that intercepts commands, handles system-style events, and reads/writes memory and flush-state files, but those capabilities are not transparently declared in the skill description. In practice, that means a seemingly benign 'memory protocol' can act like a stateful hook with filesystem side effects, which expands its authority and can surprise users or integrators.
This document defines behavior that intercepts commands, handles system-style events, and reads/writes memory and flush-state files, but those capabilities are not transparently declared in the skill description. In practice, that means a seemingly benign 'memory protocol' can act like a stateful hook with filesystem side effects, which expands its authority and can surprise users or integrators.
The documentation defines a strict privacy boundary for group chats, yet elsewhere allows unresolved group sessions to fall back to DM memory. That creates a direct path for private DM-only memory to be exposed in a group context when configuration is incomplete or detection fails. In a memory bootstrap hook, this is especially dangerous because disclosure happens automatically at session start.
The file documents contradictory safety behavior: one section says missing group state results in no injection, while another says unresolved groups fall back to DM protocol. Contradictions in security-critical routing rules often lead to unsafe implementations, operator misunderstanding, and accidental disclosure of private memory into shared chats. Because this hook governs bootstrap context, any mistake propagates sensitive content before users can intervene.
This fallback semantically authorizes cross-scope data flow from private DM memory into a group-chat session when group mapping is missing. That violates least privilege and session isolation, and could expose personal notes, prior direct-message context, or other sensitive memory to unintended participants. In an agent memory bootstrap mechanism, the leak is automatic and repeatable.
The limitation explicitly accepts a condition where DM-only memory remains injected into group sessions and depends on the agent not to use it. That is not a valid isolation control: the sensitive content is already inside the model context and may influence outputs even if the agent is instructed not to read it. Given this skill's purpose—memory injection by chat type—the mismatch makes the issue more dangerous, not less.
When a group chat is detected but no group-name mapping exists, the handler intentionally falls back to composeApmContext(), which loads DM-only memory from memory/main/* and daily notes. That directly violates the file’s own privacy boundary comments and can disclose private direct-message context into a group session visible to multiple participants.
The fallback exposes sensitive DM memory to a group session while only emitting console warnings to operators; there is no technical safeguard preventing disclosure to end users in the group. Because bootstrapFiles are injected into the active session context, the leak occurs automatically and silently from the participants’ perspective.
The code comments explicitly acknowledge that the fallback is 'NOT RECOMMENDED' and that 'private memory may leak into group chat,' yet the implementation still performs the unsafe action. This is strong evidence of a knowingly unsafe privacy boundary bypass, making accidental disclosure highly plausible in routine misconfiguration scenarios.
A missing group mapping causes the handler to treat a known group session as if it were a DM session, loading private memory that was meant to stay isolated. In this skill context, that is especially dangerous because the entire component is a memory bootstrapper, so misrouting directly changes what confidential context the agent is given in a multi-user environment.
Unknown session keys default to the DM protocol, so any future platform change, parser mismatch, or malformed session identifier can cause a non-DM chat to receive DM-only memory. Because this hook runs at bootstrap, the misclassification happens before any later guardrails can correct it, creating a broad confidentiality risk.
The addendum states that 'MEMORY.md is the authoritative original' and 'stays completely unchanged,' and later says 'MEMORY.md: do not touch.' But the same document instructs users to detect matches in MEMORY.md and move content out of it, and refers to distilling MEMORY.md updates on each flush. That creates an intent-level contradiction in the documentation about whether MEMORY.md is immutable or subject to restructuring.
Lines L51-L53 say non-English references were translated to English 'to keep the skill monolingual.' This is natural-language evidence of an English-only policy, and the file does not mention user opt-in or a documented regional/compliance justification for restricting language.
The skill instructs the agent to automatically flush memory and create missing memory files, but it does not provide a clear user-facing warning that conversations may be persisted or that files may be modified without an immediate explicit prompt. This is dangerous because it can lead to unexpected retention of sensitive chat content, privacy boundary violations, or silent creation of durable records from transient interactions.
The documented fallback permits DM memory in group or unknown sessions and does not make that behavior a hard error or prohibited state. Even if labeled 'not recommended,' it normalizes an unsafe configuration path that can leak sensitive memory across conversation boundaries. The skill context increases risk because the feature is explicitly about privacy-sensitive memory scoping.
The limitation acknowledges that group sessions may still receive MEMORY.md and relies on a DO-NOT-READ instruction plus agent obedience. Security controls based on model compliance are not reliable barriers; once sensitive DM memory is injected into group context, it may be summarized, quoted, or acted upon despite warnings. This is a real privacy weakness because the hook admits known leakage conditions without enforcing technical containment.
The hook explicitly supports cron-triggered /remem via system:event and documents that it writes memory/flush-state.json on every flush, meaning state can be changed without an interactive user action at the time of execution. In a memory/privacy-oriented skill, undisclosed automatic writes increase the risk of unexpected persistence, audit confusion, and cross-context state changes, especially given the noted DM/group flush-state sharing limitation.
The hook persists session metadata including session_id, context usage, flush timing, group counts, and recent file-change deltas to disk without any visible notice, consent, minimization, or retention control. In a memory-management skill, this creates a real privacy and data-governance risk because operational metadata about user sessions and memory activity is silently accumulated and could later be accessed by other local components, operators, or attackers with filesystem access.
The manifest describes a progressive memory protocol for group chat and DM memory, but this addendum embeds a bash-based grep workflow for auditing and extracting MEMORY.md contents. While documentation may include maintenance guidance, prescribing shell command execution is not an obvious requirement of the stated memory-disclosure purpose itself.
The example 06:17 / 18:17 Asia/Shanghai embeds a specific timezone/locale in natural-language documentation. The file does not indicate that this timezone is configurable, user-selected, or required for a region-specific purpose, which can conflict with language/locale neutrality expectations.
No suspicious patterns detected.