Back to skill

Security audit

Agent Longevity

Security checks for vulnerabilities and agentic risk

Overview

The skill is not an exfiltration tool, but it recommends persistent plain-text agent memory that can include secrets and personal or family information.

Review before installing. Use the audit scripts only on files you intend to inspect, set AGENT_DATA_DIR deliberately, and do not follow the memory architecture as written for secrets or sensitive personal data. Keep API keys, tokens, precise location, and private family/user details out of MEMORY.md, USER.md, FAMILY.md, and raw logs unless you add explicit consent, redaction, retention, and file-permission controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/memory_architecture.md:11
Finding

Plaintext Persistence of Credentials and Sensitive Personal Data in Agent Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A second behavior mismatch indicates the skill does not operate on autonomous runtime state and only performs limited pattern matching, yet it is marketed as addressing broad autonomous 'death modes.' In the context of safety/longevity tooling, overclaiming detection or mitigation is especially risky because users may defer real controls, allowing degraded autonomous behavior to continue unchecked.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

A second behavior mismatch indicates the skill does not operate on autonomous runtime state and only performs limited pattern matching, yet it is marketed as addressing broad autonomous 'death modes.' In the context of safety/longevity tooling, overclaiming detection or mitigation is especially risky because users may defer real controls, allowing degraded autonomous behavior to continue unchecked.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The capability to persist keys is unrelated to the stated purpose of preventing agent memory bloat and self-echo. Because the file frames the agent as autonomously managing its own long-term memory, allowing key retention creates an unnecessary high-value target that can be exfiltrated by prompt injection, accidental logging, or future model misuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises operational modules and references scripts, but the manifest declares no explicit tool scope despite detected capabilities for environment access and file read/write. Undeclared capabilities create a trust boundary problem: a user or host may invoke the skill believing it is documentation/auditing only, while the implementation can access local state and persist data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to match many ordinary troubleshooting situations, which can cause the skill to activate unexpectedly. Overbroad activation is risky here because the skill appears to carry file/env capabilities and can steer workflows or collect logs in contexts where the user did not intend to invoke it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese and presents its guidance as the default skill content, with no indication that users may choose another language or that the skill is intentionally region-specific. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill documentation is written in Chinese and does not provide any indication that language selection is optional or limited to a justified region-specific use case. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document explicitly includes '密钥' (keys/secrets) in MEMORY.md, which is a session-start file the agent reads every time. Persisting secrets in a broadly loaded long-term memory artifact increases exposure risk through prompt leakage, overbroad tool access, accidental summarization, or inclusion in downstream outputs; this is not necessary for general memory hygiene or anti-degradation goals.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The design directs the agent to retain personal data ('USER.md', 'FAMILY.md') and secrets in organized long-term files, making sensitive information durable, discoverable, and likely to be loaded into context. In a longevity skill for autonomous agents, this raises the danger because the entire point is repeated persistence and reuse across sessions, amplifying privacy harm and secret exposure over time.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The L2 raw-log layer says to record information indiscriminately before judging importance, which predictably captures secrets, personal data, and irrelevant sensitive content. Even if later distilled or archived, the unsafe collection happens first, increasing the chance of accidental retention, leakage, and unauthorized reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill document is written in Chinese and does not indicate that language selection is optional or limited to a justified region-specific use case. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persistently stores free-form reasoning text, actions, and optional extra metadata to disk with no consent prompt, minimization, masking, retention control, or warning to the operator. In this skill's context, the logger is specifically intended to capture an autonomous agent's internal reasoning over long periods, which increases the likelihood of recording secrets, personal data, credentials, or other sensitive internal state that could later be exposed.

Content

No source excerpt is available for this finding.

Tainted flow: 'LOG_FILE' from os.environ.get (line 21, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
88% confidence
Finding

The log file path is derived from the AGENT_DATA_DIR environment variable and then used for file creation/appending without validation or confinement. If an attacker can influence the runtime environment, they can redirect logs to arbitrary writable locations, potentially overwriting or polluting files, creating symlink-based write hazards, or causing sensitive decision data to be written somewhere unintended.

Content

Scanner excerpt · scripts/decision_logger.py (reported line 44)May include surrounding context.

python
}
    if extra:
        entry["metadata"]["extra"] = extra
    with open(LOG_FILE, "a", encoding="utf-8") as f:
        f.write(json.dumps(entry, ensure_ascii=False) + "\n")
    return entry

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring, title, and usage examples are presented only in Chinese, while the policy requires avoiding forced language constraints unless the user opts in or the locale restriction is justified. Nothing in the file explains that this tool is intentionally limited to Chinese-language workflows or offers an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring presents the skill description and usage entirely in Chinese, with no indication that other languages are supported or that the language is intentionally region-specific. Per SQP-3, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The module docstring and usage examples are presented only in Chinese, which imposes a language choice in the skill's user-facing instructions without any opt-in or alternative locale. This matches the policy category for language or locale constraints that are not explicitly optional or justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code file accepts a path via --file and reads the specified file's contents, but the operation has no inline comment, docstring note, or user-facing disclosure at the point of execution beyond the generic CLI argument. Under the code-file SQP-2 criteria, file access affecting user data can be flagged when there is no visible warning or explanatory disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.