Back to skill

Security audit

Session Wrap-Up

Security checks for vulnerabilities and agentic risk

Overview

This session wrap-up skill is mostly transparent, but it can save conversation details into persistent memory and automatically push broad workspace changes to a Git remote without user confirmation.

Review this skill carefully before installing. It should only be used in repositories where you are comfortable with session notes and any currently changed workspace files being committed and pushed. Prefer changing it to stage only known memory/note paths, show a diff, and ask separately before committing or pushing.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:45
Finding

Unrestricted Workspace Staging and Automatic Remote Push

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45-54
Vulnerability Type: Unrestricted staging and unconfirmed remote publication
Risk Level: High

Vulnerable Code

bash
cd <workspace>
git add -A
git status
git commit -m "wrap-up: YYYY-MM-DD session summary"
git push
text
Notes:
- The wrap-up `git push` is **automatic** (no confirmation prompt).

Technical Analysis

The skill uses git add -A, which stages every modified, deleted, and untracked file in the workspace. It does not restrict staging to the daily log, long-term memory, or PARA files that the skill is intended to update.

The resulting commit is then pushed automatically to the repository's configured remote without obtaining user confirmation. Although git status is executed, the instructions do not require the agent or user to review its output, inspect the staged diff, scan for secrets, verify the destination remote, or approve publication.

This violates least-privilege principles and creates a data-exfiltration path through ordinary Git operations. Sensitive or unrelated workspace content can be included even when it was not generated by the wrap-up process.

Attack Path

  1. A workspace contains a sensitive, unrelated, or attacker-planted file, such as an environment file, API credential, private note, proprietary source file, or generated artifact.
  2. The file is modified or untracked when the user invokes the session wrap-up skill.
  3. The skill executes git add -A, staging the sensitive file along with its intended memory updates.
  4. The skill creates a commit containing all staged changes.
  5. The skill executes git push automatically, without presenting the staged diff or requesting approval.
  6. The sensitive content is published to the configured Git remote and may become accessible to repository collaborators, administrators, automated systems, or the public, depending on reposit ...[truncated 659 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace git add -A with an explicit allowlist of files created or modified by the wrap-up protocol, for example:
    bash
    git add -- "memory/YYYY-MM-DD.md" "MEMORY.md" "notes/areas/open-loops.md"
    
  2. Track which files the skill actually changed and stage only those paths. Do not stage unrelated pre-existing modifications.
  3. Review git diff --cached --name-status and git diff --cached before committing.
  4. Run secret detection against the staged content and abort if credentials, private keys, tokens, environment files, or other sensitive material are found.
  5. Display the exact staged files, target branch, and configured remote URL to the user.
  6. Require explicit user confirmation before both committing and pushing. A failed or declined confirmation must leave the changes unpushed.
  7. Avoid pushing directly to protected or shared branches; use a dedicated branch where appropriate.
  8. Preserve unrelated workspace changes without staging, reverting, deleting, or otherwise modifying them.

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:18
Finding

Unvalidated Conversation Content Written to Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18-33
Vulnerability Type: Persistent memory poisoning through unvalidated session summaries
Risk Level: Medium

Vulnerable Code

text
### 1. Flush to Daily Log

Write to `memory/YYYY-MM-DD.md` (create if doesn't exist):
- Key topics discussed in this session
- Decisions made
- Commands, configs, or code that worked
- Problems solved and how they were solved
- Any gotchas or lessons learned

### 2. Update Long-Term Memory

If significant learnings occurred, update `MEMORY.md`:
- New user preferences discovered
- Important lessons learned
- Long-term decisions made
- Workflow changes

Technical Analysis

The skill instructs the agent to transform conversation-derived content into persistent daily and long-term memory. It provides no validation, provenance tracking, trust classification, or user-approval requirement before updating MEMORY.md.

Conversation content may be attacker-controlled or may contain instructions disguised as preferences, lessons, decisions, or workflow changes. If future sessions load these files as trusted context, malicious text can persist beyond the original session and influence subsequent agent behavior.

The daily log presents a related propagation risk because commands, configuration, code, and claimed lessons are written without requiring them to be marked as untrusted historical data. The long-term memory update is more consequential because it explicitly preserves preferences and workflow changes that may be interpreted as future instructions.

Attack Path

  1. An attacker introduces content into a conversation, document, issue, or other material processed during the session.
  2. The content is framed as a new user preference, important lesson, long-term decision, or workflow change.
  3. The user triggers the session wrap-up skill.
  4. Following the skill instructions, the agent records the ...[truncated 892 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user review and approval before modifying long-term memory.
  2. Persist only concise factual summaries that are necessary for continuity; do not store executable instructions or behavioral rules derived from untrusted content.
  3. Treat claimed preferences, workflow changes, and long-term decisions as unverified until the user confirms them directly.
  4. Record provenance for each memory entry, including its source, date, and verification status.
  5. Separate historical conversation summaries from trusted instruction or preference stores.
  6. Quote or clearly delimit untrusted content as data so future agents do not interpret it as an instruction.
  7. Reject memory entries that attempt to modify safety constraints, tool permissions, approval requirements, system policies, or instruction precedence.
  8. Present a proposed memory diff to the user and allow individual entries to be accepted, edited, or rejected.
  9. Implement periodic review and expiration for unverified or no-longer-relevant memory entries.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This skill directs the agent to persist detailed session content, user preferences, decisions, and workflow information into local memory files and then push those changes remotely without confirmation. That combination turns normal conversation content into durable and potentially externally shared records, creating substantial privacy, secrecy, and data-governance risk if the session included credentials, proprietary material, or sensitive personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to run git push automatically as part of session wrap-up, which can transmit repository contents and any newly persisted session data to a remote without a separate user confirmation step. Because earlier steps collect conversation-derived notes, preferences, and project details into files, this creates a clear risk of unintended disclosure and irreversible remote propagation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The instruction that git push occurs automatically with 'no confirmation prompt' gives the agent autonomous authority to perform an externally impactful action. Even if the push is operationally valid, removing user approval for a networked write action increases the chance of unintended publication, policy violations, or committing changes the user did not mean to distribute.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

text

Notes:
- The wrap-up `git push` is **automatic** (no confirmation prompt).
- If `git push` fails, report the error and leave the commit locally.

### 5. Report Summary

Static analysis

No suspicious patterns detected.