Back to skill

Security audit

Project Memory Workflow

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for repository memory maintenance, but it can be implicitly invoked by an ambiguous “init” request and then create persistent project instruction and documentation files without a separate confirmation.

Review this skill before installing if you often use short commands like “init” for other setup tasks. It is designed to read repository context and create or update persistent memory files, including agent instruction files, so use it only where repository-level AI documentation is desired and check the generated files before committing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes the standalone phrase init, which is highly ambiguous and commonly appears in normal software requests unrelated to repository-memory initialization. This can cause the skill to activate unexpectedly and create or modify documentation files when the user intended a different action, expanding scope and risking unintended repository changes.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
82% confidence
Finding

The skill authorizes autonomous file creation and repository modification 'without asking again' when it infers explicit intent from broad trigger phrases, including ambiguous ones like init. In a codebase context, autonomous writes are more dangerous because they can alter trusted instruction and documentation files, create noise, and potentially interfere with ongoing user changes even though the skill includes some preservation safeguards.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
Use user intent, not missing files alone, to decide whether to write.

- During an ordinary development task, if canonical files are missing, report the missing files and ask whether the user wants project memory initialized. Continue only with read-only analysis until the user agrees; do not expand the requested task implicitly.
- When the user explicitly asks with `初始化项目`, `初始化项目记忆`, `init`, `init project`, `set up project memory`, `建立项目记忆`, or equivalent language, execute initialization without asking again.
- If only some files are missing, create only those files unless the user asks to restructure documentation.
- If another established documentation layout exists, adapt to it and record the mapping; do not create competing sources of truth.
- Never overwrite an existing instruction or project document merely to make it conform to this skill.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill can be implicitly invoked and its description/default prompt are broad enough to match generic repository-setup or memory-maintenance requests, which increases the chance of unintentional activation. That can cause the agent to read, summarize, or persist project context when the user did not explicitly intend to run this workflow, creating confidentiality and integrity risks around repository memory files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L03 is written in Chinese while the rest of the document is in English, implicitly imposing a specific language in the skill documentation without offering a language choice or explaining a locale-specific requirement. This matches the policy category for language or locale constraints expressed in natural language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file presents core behavior and examples partly in Chinese, which can implicitly constrain usage or responses to a specific language context without stating that the user may choose their preferred language. Under the language/locale policy, this is a natural-language policy concern unless the skill offers opt-in or clearly justifies the locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.