Back to skill

Security audit

ByteRover

Security checks for vulnerabilities and agentic risk

Overview

This skill is for project memory, but it broadly directs agents to send project context to LLM providers and persist new memory, so it should be reviewed before installation.

Install only if you are comfortable with a memory tool that may send project context to a configured LLM provider and write persistent project memory. Prefer local search when possible, review what files or context are being sent, avoid secrets and sensitive source files, require approval before curation or cloud sync, and pin or independently verify the CLI package before global installation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Mandatory workflow instructions hijack unrelated agent tasks

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:539
Finding

Project context and selected source files can be disclosed to external LLM providers

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:58
Finding

Automatic curation can poison persistent agent memory

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned global npm installation creates a supply-chain execution risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
95% confidence
Finding

The skill explicitly instructs connecting arbitrary external LLM providers and passing data to them, including an example using an API key on the command line. This creates a real data-exposure path because project context and curated file contents may be sent to third-party services, and CLI-passed secrets may also leak via shell history or process inspection.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

bash
brv providers list
brv providers connect openai --api-key sk-xxx --model gpt-4.1

6. Project Locations

Exfiltration Commands

High
Category
Prompt Injection
Confidence
98% confidence
Finding

The file states that brv query and brv curate send query text and included file contents to a configured LLM provider for processing. In the context of a skill that strongly encourages use before work, this is dangerous because it can exfiltrate sensitive project data, architectural details, or source contents to external providers without sufficiently granular safeguards.

Content

Scanner excerpt · SKILL.md (reported line 539)May include surrounding context.

md
**File access**: The `-f` flag on `brv curate` reads files from the current project directory only. Paths outside the project root are rejected. Maximum 5 files per command, text and document formats only.

**LLM usage**: `brv query` and `brv curate` send context to a configured LLM provider for processing. The LLM sees the query or curate text and any included file contents. No data is sent to ByteRover servers unless you explicitly run `brv vc push`.

**Cloud sync**: `brv vc push` and `brv vc pull` require authentication (`brv login`) and sync knowledge with ByteRover's cloud service via git. All other commands operate without ByteRover authentication.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata says it 'MUST' be used before any work, creating an unconditional activation rule that can override normal least-privilege tool selection. This increases the chance an agent will invoke the tool unnecessarily and expose project context to the tool or its configured provider even when the task does not require memory lookup.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger 'The user wants you to recall something' is overly broad because many normal assistant tasks could be interpreted as recall. That broad scope can cause unnecessary tool invocation and retrieval of stored project memory unrelated to the user's immediate request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.