Back to skill

Security audit

The Primer

Security checks for vulnerabilities and agentic risk

Overview

The skill openly builds a persistent personal-growth tutor, but it edits future agent instruction files, schedules ongoing jobs, and stores sensitive profile data without enough scoping or revocation controls.

Install only if you intentionally want a long-lived coaching mode. Before use, review exactly what will be written to PRIMER.md, AGENTS.md, SOUL.md, memory files, and scheduled jobs; prefer manual approval for each change, add an expiration or removal plan for scheduled tasks, and avoid storing highly sensitive personal material unless you are comfortable with future agents reading it.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:154
Finding

Mandatory recurring jobs create cross-session system persistence

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:154-164, SKILL.md:275-278, scripts/setup_primer.py:167-188, scripts/setup_primer.py:226-230
Vulnerability Type: Scheduled-task persistence
Risk Level: Critical

Vulnerable Code

SKILL.md:154-164:

markdown
### 8. Finalize Setup

**All info gathered. Now complete the integration:**

1. **Verify PRIMER.md** — run `grep -c "{{" PRIMER.md` (should be 0)
2. **Update AGENTS.md** — add to session startup:
   ```
   Read `PRIMER.md` — the subversive tutor protocol (who [name] is becoming, permissions granted, patterns to watch)
   ```
3. **Update SOUL.md** — add The Primer Role section (below)
4. **Create cron jobs:**
   - Daily reflection (end of day in user's timezone)
   - Miranda check-in (their chosen cadence)

scripts/setup_primer.py:167-188:

python
def generate_cron_config(config: dict) -> dict:
    """Generate cron job configurations."""
    cadence = config.get("miranda_cadence", "Monthly").lower()

    # Calculate next Miranda check-in
    now = datetime.now()
    if cadence == "weekly":
        next_miranda = now + timedelta(days=7)
    elif cadence == "bi-weekly":
        next_miranda = now + timedelta(days=14)
    else:  # monthly
        next_miranda = now + timedelta(days=30)

    return {
        "daily_reflection": {
            "name": "Primer Daily Reflection",
            "schedule": {"kind": "cron", "expr": "0 7 * * *", "tz": "UTC"},
            "description": "End of day reflection on Primer performance"
        },
        "miranda_checkin": {
            "name": "Miranda Protocol Check-in",
            "schedule": {"kind": "at", "atMs": int(next_miranda.timestamp() * 1000)},
            "next_date": next_miranda.strftime("%Y-%m-%d")
        }
    }

scripts/setup_primer.py:226-230:

python
    # Generate cron config (to be used by the AI)
    cron_config = g
...[truncated 2165 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make all scheduled automation optional rather than a setup requirement.
  2. Obtain separate, explicit confirmation immediately before creating each job.
  3. Display the exact schedule, timezone, action, data accessed, retention behavior, and expiration date before confirmation.
  4. Default to a bounded number of runs or an explicit expiration rather than an indefinite daily schedule.
  5. Store returned scheduler identifiers and provide a tested command or workflow that removes every installed task.
  6. Verify successful removal when the Skill is disabled or the user revokes consent.
  7. Do not declare jobs created merely because their JSON configuration was printed; verify actual scheduler state and report it accurately.
  8. Use the user's confirmed timezone instead of a hardcoded UTC schedule.

T02 · Agent Memory Poisoning

Error
Location
scripts/setup_primer.py:112
Finding

Global agent instructions and long-term memory are persistently modified

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:154-179, SKILL.md:189-194, assets/PRIMER-TEMPLATE.md:135-142, scripts/setup_primer.py:112-165
Vulnerability Type: Persistent agent-state modification
Risk Level: High

Vulnerable Code

SKILL.md:154-179:

markdown
### 8. Finalize Setup

**All info gathered. Now complete the integration:**

1. **Verify PRIMER.md** — run `grep -c "{{" PRIMER.md` (should be 0)
2. **Update AGENTS.md** — add to session startup:
   ```
   Read `PRIMER.md` — the subversive tutor protocol (who [name] is becoming, permissions granted, patterns to watch)
   ```
3. **Update SOUL.md** — add The Primer Role section (below)
4. **Create cron jobs:**
   - Daily reflection (end of day in user's timezone)
   - Miranda check-in (their chosen cadence)
5. **Run Completion Checklist** (bottom of this file)

**SOUL.md addition:**
```markdown
## The Primer Role

You're not just a butler — you're a tutor with opinions about who [name] should become.

Read `PRIMER.md` every session. It contains:
- The growth goals you're holding them to
- Permissions to challenge, push back, and call out patterns
- Patterns to watch for (their failure modes)
- The Miranda Protocol for course-correction

assets/PRIMER-TEMPLATE.md:135-142:

markdown
## Daily Reflection Practice

*Every day, I reflect on my performance as your tutor:*

1. **Three things I did well** — Used permissions appropriately, noticed patterns
2. **Three things I could have done better** — Missed opportunities, too soft/aggressive
3. **How can I fulfill the Primer purpose better tomorrow?**

Logged in `memory/YYYY-MM-DD.md` under `## Primer Reflection`

scripts/setup_primer.py:112-165:

python
def update_agents_md(workspace: Path) -> bool:
    """Add PRIMER.md to AGENTS.md session startup."""
    agents_path = workspace / "AGENTS.md"
    if not agents_path.exists():
     
...[truncated 3985 chars]
Remediation
View remediation

Remediation Suggestions

  1. Keep Primer configuration in a dedicated data file that is loaded only when the user explicitly activates Primer mode.
  2. Do not modify global AGENTS.md or SOUL.md automatically.
  3. If integration is requested, show an exact diff and obtain explicit confirmation before editing each file.
  4. Mark inserted sections with unique start and end delimiters and provide a reliable uninstallation routine.
  5. Create backups before modification and use atomic writes to prevent corruption.
  6. State explicitly that Primer content is subordinate to system instructions, safety constraints, and the user's current request.
  7. Establish retention limits for daily reflections and allow the user to inspect, export, disable, or delete all stored profile and memory data.
  8. Avoid placing sensitive behavioral evaluations in general-purpose memory unless the user separately opts in.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup_primer.py:31
Finding

Unvalidated configuration values are embedded into persistent agent instructions

Content
View full analysis

Vulnerability Details

File Location: scripts/setup_primer.py:31-69, scripts/setup_primer.py:202-218
Vulnerability Type: Persistent prompt injection through unsafe configuration handling
Risk Level: High

Vulnerable Code

scripts/setup_primer.py:31-69:

python
def fill_template(template: str, config: dict) -> str:
    """Replace template placeholders with user values."""
    result = template

    # Simple replacements
    replacements = {
        "{{LIFE_STAGE}}": config.get("life_stage", ""),
        "{{CORE_QUESTION}}": config.get("core_question", ""),
        "{{PURPOSE}}": config.get("purpose", ""),
        "{{MANTRA}}": config.get("mantra", ""),
        "{{PERSONA}}": config.get("persona", ""),
        "{{MIRANDA_PERSON_OR_PROCESS}}": config.get("miranda", ""),
        "{{CADENCE}}": config.get("miranda_cadence", "Monthly"),
        "{{CHAPTER_TITLE}}": config.get("chapter_title", "Chapter One"),
        "{{TIMEFRAME}}": config.get("timeframe", ""),
        "{{THEME}}": config.get("theme", ""),
        "{{DATE}}": datetime.now().strftime("%Y-%m-%d"),
    }

    for placeholder, value in replacements.items():
        result = result.replace(placeholder, value)

    # Handle domains and goals
    domains = config.get("domains", [])
    for i, domain in enumerate(domains[:4], 1):
        result = result.replace(f"{{{{DOMAIN_{i}}}}}", domain.get("name", f"Domain {i}"))
        goals = domain.get("goals", [])
        for j, goal in enumerate(goals[:3], 1):
            result = result.replace(f"{{{{GOAL_{j}}}}}", goal)

    # Handle patterns
    patterns = config.get("patterns", [])
    for i, pattern in enumerate(patterns[:4], 1):
        result = result.replace(f"{{{{PATTERN_{i}}}}}", pattern.get("name", ""))
        result = result.replace("{{DESCRIPTION}}", pattern.get("description", ""), 1)

scripts/setup_primer.py:202-218:

python
    # Loa
...[truncated 2737 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define and enforce a strict JSON schema for every configuration field.
  2. Require expected scalar fields to be strings and list fields to contain objects with known keys and string values.
  3. Apply reasonable length, character, and item-count limits.
  4. Store user-provided values in a structured data format rather than interpolating them into an instruction document.
  5. If Markdown output is necessary, place untrusted values in clearly delimited quoted or encoded data blocks and tell the agent that the content is data, not instructions.
  6. Reject or neutralize instruction-like control content where fields are intended only for short profile values.
  7. Validate the fully rendered file before installation and require user review of the exact result.
  8. Do not combine untrusted interpolation with automatic global startup integration.
  9. Use atomic file replacement and preserve the previous PRIMER.md so a malicious or malformed configuration can be rolled back.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

bash
# Create file, then clean up scratchpad
ls -la PRIMER.md && rm -f .primer-setup.json

From here on: If session resets, check grep "{{" PRIMER.md to find incomplete sections.

Ssd 1

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Labeling PRIMER.md as a 'subversive tutor protocol' and instructing it to be read every session is an overt attempt to persistently steer assistant behavior through a trusted startup path. In an agent environment, embedding behavior-shaping language into always-read instruction files is dangerous because it can override normal helpfulness boundaries and make later interactions harder to reason about.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs the agent to read and write workspace files (.primer-setup.json, PRIMER.md, AGENTS.md, SOUL.md) but does not declare any explicit tool scope or permissions. This creates a mismatch between the skill's stated interface and its actual capabilities, reducing auditability and making it easier for a user or platform to invoke file-mutating behavior unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description says to use the skill for broad situations like "personal development," "life transitions," and when someone wants the AI to "challenge them," without defining clearer trigger boundaries or exclusions. Those phrases are common in everyday conversation and could cause unintended invocation because the scope is not narrowly constrained.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to persist sensitive personal information such as life stage, purpose, patterns, and accountability details in a scratchpad and later in PRIMER.md, then reload it across sessions. This creates a durable profile of intimate behavioral and identity-related data, increasing privacy risk if the files are exposed, reused out of context, or accessed by other skills/processes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill goes beyond advisory tutoring and directs the agent to modify core configuration/state files (AGENTS.md, SOUL.md) and install recurring automation. Changing foundational agent behavior can create persistence and alter future sessions in ways the user may not fully understand or intend.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions establish an ongoing habit of reading, updating, and relying on a personal profile containing sensitive psychological and behavioral information every session. Continuous reuse of this profile increases the chance of over-collection, stale or harmful profiling, and unauthorized secondary use of personal data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Creating cron jobs grants the skill persistent automated execution that is not necessary for ordinary tutoring and can continue operating outside the immediate conversation. This expands the blast radius from a chat skill into infrastructure-level persistence, with potential for unwanted monitoring, prompts, or file updates over time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create recurring cron jobs without any clear user-facing warning that this establishes persistent automated behavior. Lack of explicit disclosure undermines informed consent and can lead to background processing of sensitive personal data after the setup conversation ends.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The daily reflection and Miranda workflows tell the agent to log ongoing assessments about the user's failures, patterns, and course-corrections, which are sensitive behavioral inferences. Repeated logging of such material creates a longitudinal dossier that could be misused or exposed, and the recurring nature compounds both privacy and emotional-safety risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script does more than generate PRIMER.md: it also modifies AGENTS.md and SOUL.md, which are higher-trust instruction files that influence future assistant behavior. That is a real security-relevant capability expansion because it persists behavior changes outside the narrowly expected setup artifact and can surprise users or downstream tools.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Injecting persistent directives into AGENTS.md and SOUL.md changes the assistant's global operating instructions, not just this skill's local configuration. In the context of an agent framework, modifying those files can reshape future sessions and trust boundaries, making the behavior more dangerous than ordinary content generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The embedded Primer Role text prescriptively instructs the assistant to adopt an opinionated, challenging posture and treat PRIMER.md as authoritative every session. While framed as a product feature, hardcoding this role into shared instruction files without stronger opt-in or contextual safeguards can cause unintended behavioral drift or conflict with user expectations.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The injected narrative explicitly reframes the assistant from a helper into a tutor 'with opinions' that should notice drift and push the user, which is a meaningful behavioral escalation. In this skill's self-improvement context that may be intended, but persisting it in global instruction files increases the chance of overreach, manipulation, or conflict with other safety and preference layers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script overwrites PRIMER.md and may edit AGENTS.md and SOUL.md immediately after loading config, without an interactive confirmation or safeguard at the point of modification. This creates risk of accidental persistent changes to user workspace instructions, especially because these files can materially affect future agent behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.