Back to skill

Security audit

Super Memori GPT

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed project-continuity workflow with optional local ledger validation and no hidden execution, exfiltration, persistence hooks, or purpose-mismatched behavior found.

Install only if you want a workflow that may help maintain project continuity through project-scoped ledgers and platform memory/file tools. Review where your platform stores checkpoints, and do not authorize persistent writes for sensitive projects unless you are comfortable with the ledger content and retention controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description presents a continuity/resume skill for cross-platform project memory and context preservation, implying workflow restoration and use of GPT-specific history/file capabilities. The supplied code instead is a standalone Python script for structural validation of a specific JSON schema ('Super Memori schema-v2'). Its main function is checking schema_version, required fields, status/state rules, record IDs, project consistency, source/evidence references, timestamp formats, dependency propagation, relation validity, artifact verification linkage, and possible credential leakage in strings. It does not implement continuity recovery, synchronization between ChatGPT Work and Codex, checkpointing, or context restoration. The secret-pattern scan is also a substantive behavior not reflected in the description. This is a clear purpose/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a GPT-platform continuity/memory skill for resuming work across ChatGPT Work and Codex. The supplied code does not implement such a capability. Instead, it is a test file for a ledger_guard validator, focused on validating structured project ledger/checkpoint data and CLI behavior. While there is a loose thematic overlap with project state/checkpoint integrity, the primary purpose and actual behavior are materially different: this code tests validation logic, not continuity recovery or context maintenance using history/file tools. Therefore the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill references file and shell-based capabilities via the documented helper invocation (python3 <skill-root>/scripts/ledger_guard.py ...) but does not declare an explicit tool scope or permissions boundary. That creates an authorization ambiguity: an agent may infer it is expected to use filesystem and shell access without a clear least-privilege contract, increasing the risk of unintended command execution or broader file access than users expect.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/test_ledger_guard.py (reported line 149)May include surrounding context.

python
def test_cli_stdin_and_exit_status(self):
        cli = str(Path(__file__).with_name('ledger_guard.py'))
        good = subprocess.run([sys.executable, cli, '-'], input=json.dumps(self.data), text=True, capture_output=True)
        self.assertEqual(good.returncode, 0)
        self.assertTrue(json.loads(good.stdout)['ok'])
        bad = subprocess.run([sys.executable, cli, '-'], input='{broken', text=True, capture_output=True)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/test_ledger_guard.py (reported line 152)May include surrounding context.

python
good = subprocess.run([sys.executable, cli, '-'], input=json.dumps(self.data), text=True, capture_output=True)
        self.assertEqual(good.returncode, 0)
        self.assertTrue(json.loads(good.stdout)['ok'])
        bad = subprocess.run([sys.executable, cli, '-'], input='{broken', text=True, capture_output=True)
        self.assertEqual(bad.returncode, 1)
        self.assertFalse(json.loads(bad.stdout)['ok'])
        self.assertEqual(bad.stderr, '')

Static analysis

No suspicious patterns detected.