Back to skill

Security audit

memo-collect

Security checks for vulnerabilities and agentic risk

Overview

This is a small local memo skill whose behavior matches its purpose, with minor documentation and deletion-confirmation caveats.

Install only if you are comfortable with a local memo tool that stores notes in a JSON file under your home directory and permanently deletes memo entries when delete_memo is invoked. Be careful with completion-style requests, since the skill treats at least one such phrase as deletion rather than marking a note complete.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill provides note-taking features including recording, querying, and deleting notes. However, the supplied code chunk contains only an empty TypeScript declaration file (export {};) and shows no implemented logic, storage, triggers, or permissions. This is a material mismatch because the actual code does not demonstrate the claimed primary purpose or capabilities at all.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
node dist/index.js <action> <content>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
node dist/index.js <action> <content>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
node dist/index.js <action> <content>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
node dist/index.js <action> <content>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
node dist/index.js <action> <content>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
node dist/index.js <action> <content>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
node dist/index.js <action> <content>

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README content is presented in Chinese and does not indicate that other language options are available or that the skill is intentionally restricted to a Chinese-speaking context. The policy requires avoiding forced language or locale constraints unless the user can opt in or the restriction is clearly justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation presents delete_memo as a normal action without warning that it permanently removes data. In an agent setting, lack of disclosure around destructive behavior increases the chance of accidental invocation and irreversible loss of user notes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The delete rule maps a natural-language phrase like '第3条备忘完成了' directly to a destructive deletion command without confirmation. This can cause unintended data loss when a user is merely marking an item as completed rather than explicitly asking to erase it, especially in conversational contexts where intent can be ambiguous.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The delete_memo branch removes data from the in-memory memo list and immediately persists the change to disk, making the deletion effectively destructive. While there is a post-action log message, there is no pre-action warning, confirmation prompt, or explanatory comment/docstring disclosing that the operation permanently modifies the stored memo database.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown usage section includes a delete operation for memo entries, which affects user data, but the description provides no caution or warning about data removal. Under the markdown-file criteria, behaviors that can affect user data should be disclosed clearly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The operational instructions and trigger phrases are presented only in Chinese, implying a fixed language for invocation and use. The file does not offer a language choice or document that the locale restriction is intentional and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file contains multiple user-facing comments and console messages in Chinese, and the skill provides no indication that language is configurable or intentionally limited to a Chinese-speaking audience. This can violate a language/locale policy when users are not given an explicit opt-in or documented locale scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.