Back to skill

Security audit

self-improving-agent-python

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly for agent self-improvement, but it can persist and copy lessons across all local agent workspaces without enough scoping or safeguards.

Install only if you are comfortable with local JSON records of evaluations and lessons being retained and potentially copied to other WorkBuddy agent workspaces. Avoid storing secrets, customer data, private prompts, or unreviewed instructions as lessons, and prefer running the sync step only after reviewing the shared knowledge file and confirming the intended target workspaces.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
scripts/learn_lesson.py:25
Finding

Untrusted Lessons Are Persisted and Propagated Across Agent Workspaces

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/config.py:37
Finding

Ambiguous Workspace Selection Can Modify the Wrong Agent's State

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README's substantive instructions and descriptions are written in Chinese, including the introduction, usage guidance, and data descriptions. This imposes a language constraint on users without any opt-in, alternative language option, or explanation that the skill is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README explicitly promotes cross-agent experience sharing and a shared knowledge base, but it provides no warning about privacy boundaries, sensitive data handling, or isolation between agents. In a self-improving agent context, lessons learned and evaluations can easily contain prompts, outputs, identifiers, or business context, so undocumented sharing increases the risk of unintended data exposure across agents or users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

All user-facing instructions, triggers, parameter explanations, and operational guidance are presented only in Chinese. If organizational policy requires not forcing a specific language without user opt-in, this file violates that expectation because it does not offer alternative languages or state that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation conditions are broad enough to trigger on common phrases like performance analysis or improving efficiency, which can cause the skill to activate outside narrowly intended contexts. In an agent environment, unintended activation can lead to unnecessary self-evaluation, workflow changes, or follow-on actions that affect task handling without explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly describes writing evaluation and lesson data to persistent workspace files and synchronizing learning into a shared cross-agent knowledge store, but it does not warn about retention, sensitivity, consent, or access control. This creates a real risk of storing confidential task details or propagating sensitive information across agents and sessions beyond the original task scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation conditions are broad and ambiguous, including phrases like "optimize workflow" and "Any scenario where the Agent needs to learn from mistakes," which can cause the skill to trigger in contexts far beyond explicit user intent. In an agentic system, overly broad activation can lead to unintended evaluation, logging, and downstream file-writing behavior, increasing the chance of unauthorized persistence or modification of workspace state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly documents writing evaluation records, lessons learned, optimization plans, and shared collective knowledge into workspace and shared-context locations, but does not warn that activating the skill will persist data or affect shared state. This is dangerous because an agent may create or alter local and cross-agent files without the user's awareness, potentially causing data leakage, contamination of shared knowledge, or unintended retention of sensitive task details.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains natural-language documentation and CLI help text in Chinese, including the module docstring and argument descriptions, without indicating any user language selection or regional constraint. That can violate a language/locale policy when a skill implicitly forces one language for interaction or understanding.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and function docstring are written in Chinese, and the CLI parser description also uses Chinese, which imposes a language choice on users without opt-in. This matches the language/locale policy concern because the script does not offer an alternative language or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The argparse description and help text are presented only in Chinese for a general-purpose optimization script. Because no language selection or documented locale constraint is provided, this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's natural-language description includes Chinese-only wording ("跨 Agent 同步学习成果") and the function/CLI descriptions are also written in Chinese, with no indication that users may choose another language. Under the stated policy, forcing or assuming a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The line "Record tool usage注意事项" mixes English with Chinese in a file named SKILL_en.md, which implies an English-language skill. This can violate language consistency expectations because the file does not offer a user language choice or explain the multilingual requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code file contains user- or maintainer-facing natural language in Chinese (for example the module docstring at L04), which can impose a language expectation without any opt-in or documented locale constraint. Under the policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code contains user-facing natural-language text in both Chinese and English, including the module docstring, argparse help strings, and console output. Because it imposes mixed locale behavior without any explicit user opt-in or language selection, it can violate the policy against forcing a specific language or locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.