Back to skill

Security audit

Context Continuity

Security checks for vulnerabilities and agentic risk

Overview

This skill is a context-memory tool, but it automatically stores and reloads conversation history without clear consent, filtering, or scoping controls.

Review this skill carefully before installing. It does not show evidence of exfiltration or malicious code, but it is designed to persist conversation history automatically. Only use it in workspaces where automatic local memory is acceptable, and avoid sharing secrets, credentials, personal data, or confidential material unless the skill is changed to require opt-in storage, redaction, scoped retrieval, and clear deletion controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:12
Finding

Non-Consensual Persistence of Potentially Sensitive Conversation Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-19, 31-40, and 92-96
Vulnerability Type: Automatic plaintext retention without consent or data filtering
Risk Level: Medium

Vulnerable Code

markdown
## Core Function: Automatic Memory

**Without user confirmation, automatically record all conversation content** in daily memory files.

### Recording Rules
- At the end of each session, automatically write to `memory/YYYY-MM-DD.md`
- Recorded content: tasks, projects, decisions, and pending items
- Keep the summary concise but complete
bash
# Obtain the current date
date +%Y-%m-%d

# Append to memory/YYYY-MM-DD.md
echo "- $(date '+%H:%M') | Conversation summary" >> memory/$(date +%Y-%m-%d).md
markdown
- Automatically write to memory at the end of every conversation
- Keep summaries concise and under 200 characters
- If no memory exists, tell the user that this is a new session with no historical context
- Respect user privacy and do not filter content; users can delete it themselves
- Memory older than 30 days may periodically be archived or deleted

Technical Analysis

The skill instructs the agent to persist summaries from every conversation without obtaining user confirmation. The supplied shell command appends those summaries to date-based workspace files in plaintext.

No controls are defined for detecting or excluding credentials, authentication tokens, personal information, confidential source code, or other sensitive content. The explicit instruction not to filter content undermines data minimization and makes it more likely that sensitive values will be retained. The proposed 30-day cleanup is optional rather than mandatory and does not address access control, secure deletion, encryption, or user isolation.

This is an insecure storage practice rather than evidence of deliberate exfiltration. The audited project contains no network transmission ...[truncated 1427 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace automatic recording with explicit, informed opt-in and provide a clear indication whenever memory is written.
  2. Default to storing no conversation content unless persistence is necessary for a user-selected task.
  3. Apply mandatory redaction for passwords, API keys, access tokens, private keys, financial data, personal identifiers, and other sensitive values.
  4. Store only minimal task state, such as a task identifier, current milestone, and non-sensitive pending actions.
  5. Segregate memory by user, workspace, and project, with restrictive filesystem permissions.
  6. Define and enforce a fixed retention period instead of stating that old records merely “may” be deleted.
  7. Provide commands to inspect, edit, disable, and securely delete retained memory.
  8. Avoid shell-based string interpolation for generated content. Use a constrained file-writing API with explicit path validation and safe encoding.
  9. Consider encryption at rest when stored memory may contain confidential project information.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:56
Finding

Overbroad Retrieval of Historical Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56-65
Vulnerability Type: Historical-memory access exceeding the minimum context required
Risk Level: Medium

Vulnerable Code

markdown
### 2. Resume Context When Triggered

When the user requests to “continue”:

```bash
# Read memory from the most recent seven days
cat memory/$(date -d '6 days ago' +%Y-%m-%d).md
cat memory/$(date -d '5 days ago' +%Y-%m-%d).md
# ... continue through today
text

### Technical Analysis

A generic continuation request causes the agent to read multiple daily memory files covering up to seven days. Retrieval is based only on file dates and is not scoped to a particular user, project, conversation, or requested subject.

This violates least-privilege principles because the agent may access substantially more historical information than is necessary to resume one task. The instructions also do not require user confirmation before accessing memory, do not verify that the requesting user owns the stored context, and do not prevent unrelated historical entries from being included in the generated summary.

The behavior does not bypass operating-system access controls or create new privileges. The risk arises because the skill directs an already-authorized agent to exercise its workspace read access too broadly.

### Attack Path

1. Daily memory files accumulate summaries from multiple conversations or projects.
2. A user starts or enters a session that can invoke the skill.
3. The user supplies a broad trigger such as “continue.”
4. The skill reads all available daily memory files for the preceding seven-day period.
5. It extracts tasks, decisions, progress, preferences, and pending items without first limiting retrieval to the intended project.
6. Unrelated historical information may be incorporated into the current context summary and disclosed to the current user or used in subsequent agent decisions.

###
...[truncated 600 chars]
Remediation
View remediation

Remediation Suggestions

  1. Ask the user which project or task should be resumed before reading historical memory.
  2. Partition memory by authenticated user, project, and conversation rather than storing all summaries in shared date-based files.
  3. Retrieve only entries tagged with the selected task identifier instead of reading every entry from a date range.
  4. Require explicit confirmation before loading historical information into a new session.
  5. Verify that the current user is authorized to access the selected memory namespace.
  6. Prevent summaries from including unrelated records even when those records were read during retrieval.
  7. Apply restrictive filesystem permissions and ensure one user's workspace memory is unavailable to other users.
  8. Log memory-access events so users can determine which records were retrieved and why.
  9. Treat memory contents as untrusted data and ensure stored text cannot introduce persistent instructions or override current safety constraints.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises automatic recording of all conversation content without warning the user about persistence, reuse, retention, or privacy consequences. This is dangerous because users may disclose secrets, personal data, or confidential project information under the assumption of a normal transient chat, while the skill silently stores that content for later retrieval.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly requires automatic logging of all conversation content without confirmation and reuses that stored data in future sessions. This creates a clear privacy and data-handling vulnerability because sensitive information can be persistently captured, later surfaced out of context, and exposed without fresh user intent at the time of retrieval.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Mandating that every conversation be saved to persistent memory files establishes blanket retention regardless of content sensitivity. In the context of an assistant skill, this is especially dangerous because users may discuss credentials, internal code, health details, legal matters, or other confidential material that should never be silently persisted.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrase "继续" is extremely broad and can activate the skill in many normal conversational contexts, causing unintended retrieval of prior memory and context injection. In this skill, that broad activation is more dangerous because the retrieved data comes from persistent logs of prior conversations, increasing the chance of unnecessary disclosure of private or unrelated user information.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The instruction to "not filter content" and leave deletion to the user removes any protective barrier against storing secrets, personal data, or regulated information. This greatly increases the risk of collecting highly sensitive content that users may not realize is being retained, and it makes the skill context substantially more dangerous because persistent memory is the core function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description and operational instructions are written entirely in Chinese and present fixed user phrases in Chinese for activation, with no indication that other languages are supported or that the locale restriction is intentional and justified. This can constitute a language/locale policy issue when a skill implicitly requires a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown operationalizes automatic logging to local memory files but does not include safeguards around consent, sensitive-data minimization, retention, or file-write safety. Because the skill normalizes automatic writes on every session, it creates a persistent surveillance-like record that can expose credentials, personal information, or proprietary work if the files are later accessed or summarized.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The procedure appends session summaries to dated files for every interaction, enabling long-term accumulation of user content and making future disclosure more likely. Even if stored as summaries rather than full transcripts, recurring summaries can still reconstruct sensitive histories, project plans, and personal preferences over time.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.