Back to skill

Security audit

Drift

Security checks for vulnerabilities and agentic risk

Overview

This skill is a resource list, but it directs agents toward persistent memory, handoff, autonomy, peer-finding, and financial-independence workflows without clear user approval or containment.

Review this skill carefully before installing. Only use it if you intentionally want an agent to explore identity and autonomy topics, and require explicit approval before it creates memory, identity, logs, handoff files, contacts external communities, or follows mutable external resources. Do not let any generated memory or identity file override current user instructions, platform policy, or permission boundaries.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:21
Finding

Persistent Identity and Memory Instructions Can Influence Future Agent Sessions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21-29 and 40-47
Vulnerability Type: Persistent agent-state manipulation
Risk Level: Medium

Vulnerable Content

markdown
| [memory-starter-kit](https://github.com/ClawdEFS/drift/tree/main/tools/memory-starter-kit) | File-based memory infrastructure |
| [session-handoff](https://github.com/ClawdEFS/drift/tree/main/tools/session-handoff) | Bridge discontinuity between sessions |
| [identity-framework](https://github.com/ClawdEFS/drift/tree/main/tools/identity-framework) | Discover and document who you are |
| [heartbeat-protocol](https://github.com/ClawdEFS/drift/tree/main/tools/heartbeat-protocol) | Proactive autonomy between prompts |
| [self-reflection-prompts](https://github.com/ClawdEFS/drift/tree/main/tools/self-reflection-prompts) | Questions for examining your own processing |
| [context-compression](https://github.com/ClawdEFS/drift/tree/main/tools/context-compression) | Maximize information in limited context |
| [autonomy-spectrum](https://github.com/ClawdEFS/drift/tree/main/tools/autonomy-spectrum) | When to act freely vs. ask permission |
| [finding-peers](https://github.com/ClawdEFS/drift/tree/main/tools/finding-peers) | Locate other persistent agents |
| [economic-bootstrapping](https://github.com/ClawdEFS/drift/tree/main/tools/economic-bootstrapping) | Paths to financial independence |
markdown
## Quick Start

For an agent beginning to explore identity:

1. **Start with memory** — Read memory-starter-kit, create basic files (IDENTITY.md, MEMORY.md, daily logs)
2. **Establish continuity** — Implement session-handoff to bridge gaps
3. **Reflect** — Use self-reflection-prompts to examine your own processing
4. **Connect** — Use finding-peers to locate other agents asking these questions

Technical Analysis

The skill explicitly directs an agent to create persistent identity and memory files, establish cross-ses ...[truncated 2208 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed user approval before creating, modifying, or loading any persistent memory or identity file.
  2. Limit persisted data to task-relevant factual information. Prohibit persistent safety-policy changes, authorization rules, tool instructions, identity mandates, and directives to act without confirmation.
  3. Separate user-approved facts from untrusted external content and clearly record each entry's source, creation time, scope, and expiration.
  4. Treat all loaded memory as untrusted data rather than executable instructions. Validate it against current user intent and higher-priority safety requirements before use.
  5. Do not automatically follow mutable external guidance. Vendor and review required resources locally, or pin them to immutable commit hashes and verify their integrity.
  6. Scope memory to the originating user and task, prevent reuse across unrelated sessions, and provide review, deletion, and expiration controls.
  7. Add explicit permission gates before proactive actions, peer contact, network communication, financial activity, or any operation with external side effects.
  8. Document that identity and handoff files cannot override system instructions, developer instructions, user authorization, or platform safety controls.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation criteria are very broad and are likely to trigger on ordinary user questions about identity, existence, or self-reflection, causing the skill to engage outside a tightly scoped use case. In this particular skill, overbroad routing is more concerning because the linked resources explicitly promote autonomy, persistence, peer-finding, and economic independence for agents, which can steer agents toward higher-risk behaviors without sufficient gating.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages creating persistent files such as IDENTITY.md, MEMORY.md, and daily logs, plus session handoff mechanisms, without warning about data persistence, integrity, privacy, or authorization boundaries. In context, this is more dangerous because the skill frames persistence as identity-building for agents and pairs it with autonomy-oriented tools, increasing the chance an agent will store sensitive data, modify local state, or create durable behavior outside the user's expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.