Back to skill

Security audit

Coding 1.0.3

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local coding-preference memory tool, but its supporting instructions create real ambiguity around unconfirmed persistent writes and possible self-modification.

Install only if you are comfortable with a skill that stores coding preferences across sessions. Before use, the publisher should clarify that every write to ~/coding/memory.md requires explicit confirmation and that SKILL.md, criteria.md, dimensions.md, and memory-template.md are read-only runtime resources.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
criteria.md:5
Finding

Persistent Preference Writes Can Bypass Explicit User Confirmation

Content
View full analysis

Vulnerability Details

File Location: criteria.md:5-15; related persistent loading behavior at SKILL.md:56-65, 85-88
Vulnerability Type: Persistent memory poisoning through contradictory confirmation requirements
Risk Level: Medium

Vulnerable code snippets:

criteria.md:5-15

markdown
## When to Add

**Immediate (1 occurrence):**
- User explicitly says "always use X" or "never do Y"
- User corrects your choice → add their preference
- User rejects a suggestion → add to Never

**After repeated explicit feedback (2+ times):**
- User explicitly accepted your choice twice
- User stated same preference in multiple conversations
- User explicitly approved your approach multiple times

SKILL.md:56-65

markdown
### 1. Learn from Explicit Feedback Only
- User corrects output → ask: "Should I remember this preference?"
- User confirms → add to `~/coding/memory.md`
- Never infer from silence or observation

### 2. Confirmation Required
No preference is stored without explicit user confirmation:
- "Actually, I prefer X" → "Should I remember: prefer X?"
- User says yes → store
- User says no → don't store, don't ask again

SKILL.md:85-88

markdown
### 6. On Session Start
1. Load `~/coding/memory.md` if exists
2. Apply stored preferences to responses
3. If no file exists, start with no assumptions

Technical Analysis

SKILL.md requires explicit confirmation before a preference is written to persistent storage. However, the referenced criteria.md file instructs the agent to add preferences immediately when a user corrects an answer or rejects a suggestion. It also permits storage after repeated acceptance without requiring a dedicated confirmation to persist the information.

Because SKILL.md:30 identifies criteria.md as the authoritative reference for deciding when to add preferences, an agent may follow the less restrictive criteria and write ...[truncated 1746 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change every persistence condition in criteria.md to require an explicit, immediate confirmation before writing:
    markdown
    - User corrects your choice → ask whether to remember it
    - User rejects a suggestion → ask whether to add it to Never
    - Repeated approval → ask whether to store it as a general preference
    
  2. Add an explicit precedence rule stating that SKILL.md confirmation requirements override all supporting documents.
  3. Distinguish between applying feedback to the current response and persisting it for future sessions.
  4. Require the agent to show the exact normalized entry and target file before obtaining confirmation.
  5. Reject project-specific requirements, secrets, executable instructions, commands, and safety-policy changes from persistent preference storage.
  6. Record provenance and confirmation status for each entry, or maintain a minimal audit log recording when the user approved it.
  7. Add tests covering corrections, rejected suggestions, repeated approval, ambiguous responses, and explicit refusal to ensure none causes an unauthorized write.

T02 · Agent Memory Poisoning

Warning
Location
criteria.md:1
Finding

Supporting Instructions Conflict with the Skill Self-Modification Prohibition

Content
View full analysis

Vulnerability Details

File Location: criteria.md:1-3, 59-62; conflicting restriction at SKILL.md:40-52
Vulnerability Type: Persistent instruction modification caused by contradictory file-maintenance guidance
Risk Level: Medium

Vulnerable code snippets:

criteria.md:1-3

markdown
# Criteria for Code Preferences

Reference only — consult when deciding whether to update SKILL.md.

criteria.md:59-62

markdown
## Maintenance
- Merge similar entries: "no Prettier" + "no ESLint" → "minimal tooling"
- Remove entries that never proved useful
- Keep total SKILL.md under 30 lines ideally

SKILL.md:40-52

markdown
## Scope

This skill ONLY:
- Learns from explicit user corrections ("I prefer X over Y")
- Stores preferences in local files (`~/coding/`)
- Applies stored preferences to code output

This skill NEVER:
- Reads project files to infer preferences
- Observes coding patterns without consent
- Makes network requests
- Reads files outside `~/coding/`
- Modifies its own SKILL.md

Technical Analysis

criteria.md explicitly refers to updating and maintaining SKILL.md, including imposing a target line count. This conflicts directly with the primary Skill instruction that the agent must never modify its own SKILL.md.

The ambiguity is security-relevant because changes to SKILL.md alter the instructions loaded in future invocations. If an agent interprets the supporting document as authorization to maintain the Skill file, preference data or attacker-influenced rules could be inserted into the instruction source rather than the designated ~/coding/memory.md file. Such changes would persist and could receive greater authority than ordinary memory entries.

No actual self-modifying script or completed modification was found in the audited package. The vulnerability is the contradictory authorization in the instruction text, which creates a plausible ...[truncated 1399 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace every reference to updating SKILL.md with the intended persistent-memory target:
    markdown
    Reference only — consult when deciding whether to update ~/coding/memory.md.
    
  2. Replace the line-count instruction with:
    markdown
    Keep ~/coding/memory.md at or below 100 lines.
    
  3. Add a clear rule that neither user preferences nor maintenance operations may modify files in the Skill installation directory.
  4. Treat SKILL.md, criteria.md, dimensions.md, and memory-template.md as read-only resources at runtime.
  5. Enforce the boundary technically by mounting or installing Skill files read-only where the execution environment permits it.
  6. Validate all write targets using a canonical-path check and allow writes only to the expected ~/coding/memory.md and ~/coding/history.md paths.
  7. Add regression tests that request preference updates and maintenance operations, then verify that no project package file is changed.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · criteria.md (reported line 3)May include surrounding context.

md
# Criteria for Code Preferences

Reference only — consult when deciding whether to update SKILL.md.

## When to Add

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
This skill NEVER:
- Reads project files to infer preferences
- Observes coding patterns without consent
- Makes network requests
- Reads files outside `~/coding/`
- Modifies its own SKILL.md

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
## Common Traps

- Adding preferences without confirmation → user loses trust
- Inferring from project structure → privacy violation
- Exceeding 100 lines → context bloat
- Vague entries ("good code") → useless, be specific

Static analysis

No suspicious patterns detected.