T09 · Insecure Skill Coding Practices
- Location
references/memory_architecture.md:11- Finding
Plaintext Persistence of Credentials and Sensitive Personal Data in Agent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not an exfiltration tool, but it recommends persistent plain-text agent memory that can include secrets and personal or family information.
Review before installing. Use the audit scripts only on files you intend to inspect, set AGENT_DATA_DIR deliberately, and do not follow the memory architecture as written for secrets or sensitive personal data. Keep API keys, tokens, precise location, and private family/user details out of MEMORY.md, USER.md, FAMILY.md, and raw logs unless you add explicit consent, redaction, retention, and file-permission controls.
references/memory_architecture.md:11Plaintext Persistence of Credentials and Sensitive Personal Data in Agent Memory
A second behavior mismatch indicates the skill does not operate on autonomous runtime state and only performs limited pattern matching, yet it is marketed as addressing broad autonomous 'death modes.' In the context of safety/longevity tooling, overclaiming detection or mitigation is especially risky because users may defer real controls, allowing degraded autonomous behavior to continue unchecked.
A second behavior mismatch indicates the skill does not operate on autonomous runtime state and only performs limited pattern matching, yet it is marketed as addressing broad autonomous 'death modes.' In the context of safety/longevity tooling, overclaiming detection or mitigation is especially risky because users may defer real controls, allowing degraded autonomous behavior to continue unchecked.
The capability to persist keys is unrelated to the stated purpose of preventing agent memory bloat and self-echo. Because the file frames the agent as autonomously managing its own long-term memory, allowing key retention creates an unnecessary high-value target that can be exfiltrated by prompt injection, accidental logging, or future model misuse.
The skill advertises operational modules and references scripts, but the manifest declares no explicit tool scope despite detected capabilities for environment access and file read/write. Undeclared capabilities create a trust boundary problem: a user or host may invoke the skill believing it is documentation/auditing only, while the implementation can access local state and persist data.
The trigger phrases are broad enough to match many ordinary troubleshooting situations, which can cause the skill to activate unexpectedly. Overbroad activation is risky here because the skill appears to carry file/env capabilities and can steer workflows or collect logs in contexts where the user did not intend to invoke it.
This markdown file is written entirely in Chinese and presents its guidance as the default skill content, with no indication that users may choose another language or that the skill is intentionally region-specific. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.
The entire skill documentation is written in Chinese and does not provide any indication that language selection is optional or limited to a justified region-specific use case. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.
The document explicitly includes '密钥' (keys/secrets) in MEMORY.md, which is a session-start file the agent reads every time. Persisting secrets in a broadly loaded long-term memory artifact increases exposure risk through prompt leakage, overbroad tool access, accidental summarization, or inclusion in downstream outputs; this is not necessary for general memory hygiene or anti-degradation goals.
The design directs the agent to retain personal data ('USER.md', 'FAMILY.md') and secrets in organized long-term files, making sensitive information durable, discoverable, and likely to be loaded into context. In a longevity skill for autonomous agents, this raises the danger because the entire point is repeated persistence and reuse across sessions, amplifying privacy harm and secret exposure over time.
The L2 raw-log layer says to record information indiscriminately before judging importance, which predictably captures secrets, personal data, and irrelevant sensitive content. Even if later distilled or archived, the unsafe collection happens first, increasing the chance of accidental retention, leakage, and unauthorized reuse.
The entire skill document is written in Chinese and does not indicate that language selection is optional or limited to a justified region-specific use case. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.
The script persistently stores free-form reasoning text, actions, and optional extra metadata to disk with no consent prompt, minimization, masking, retention control, or warning to the operator. In this skill's context, the logger is specifically intended to capture an autonomous agent's internal reasoning over long periods, which increases the likelihood of recording secrets, personal data, credentials, or other sensitive internal state that could later be exposed.
The log file path is derived from the AGENT_DATA_DIR environment variable and then used for file creation/appending without validation or confinement. If an attacker can influence the runtime environment, they can redirect logs to arbitrary writable locations, potentially overwriting or polluting files, creating symlink-based write hazards, or causing sensitive decision data to be written somewhere unintended.
}
if extra:
entry["metadata"]["extra"] = extra
with open(LOG_FILE, "a", encoding="utf-8") as f:
f.write(json.dumps(entry, ensure_ascii=False) + "\n")
return entry
The module docstring, title, and usage examples are presented only in Chinese, while the policy requires avoiding forced language constraints unless the user opts in or the locale restriction is justified. Nothing in the file explains that this tool is intentionally limited to Chinese-language workflows or offers an alternative language option.
The module docstring presents the skill description and usage entirely in Chinese, with no indication that other languages are supported or that the language is intentionally region-specific. Per SQP-3, forcing a specific language without user opt-in is a natural-language policy concern.
The module docstring and usage examples are presented only in Chinese, which imposes a language choice in the skill's user-facing instructions without any opt-in or alternative locale. This matches the policy category for language or locale constraints that are not explicitly optional or justified.
This code file accepts a path via --file and reads the specified file's contents, but the operation has no inline comment, docstring note, or user-facing disclosure at the point of execution beyond the generic CLI argument. Under the code-file SQP-2 criteria, file access affecting user data can be flagged when there is no visible warning or explanatory disclosure.
No suspicious patterns detected.