Back to skill

Security audit

Memory Transfer Enhanced

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real memory-transfer tool, but its filesystem scope and promised safety checks are not reliable enough for automatic installation.

Install only if you are comfortable reviewing commands manually and limiting source and target agent IDs to known safe workspaces. Use dry-run explicitly, avoid clone mode for memories that may contain user data or secrets, and treat share-mode filtering as incomplete until path validation and enforced confirmation are added.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
memory-transfer.js:50
Finding

Workspace Path Traversal Permits Access Outside Authorized Agent Directories

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
memory-transfer.js:306
Finding

Untrusted Content Can Be Persisted in Target-Agent Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
memory-transfer.js:148
Finding

Documented Confirmation and Dry-Run Safeguards Are Not Enforced

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
memory-transfer.js:438
Finding

Positional Argument Parser Misclassifies the Source Agent as a File Filter

Content
View full analysis
[file] [options]'); console.log('\nOptions:'); console.log(' --mode Transfer mode (default: share)'); console.log(' --topic Filter by topic keyword'); console.log(' --dry-run Preview only'); console.log('\nMode details:'); console.log(' share - Filter user info, adapt to target agent (knowledge sharing)'); console.log(' clone - Keep original verbatim (for backup/migration)'); console.log('\nExamples:'); console.log(' memory-transfer transfer main coder'); console.log(' memory-transfer transfer main coder --mode share'); console.log(' memory-transfer transfer main coder --mode clone'); console.log(' memory-transfer transfer main coder --topic project'); console.log(' memory-transfer transfer main coder --mode interactive'); console.log(' memory-transfer transfer main coder --dry-run'); } else { transferMemory(source, target, { topic, mode, dryRun, file }); } ``` ### Technical Analysis After `process.argv.slice(2)`, a documented invocation such as: ```bash node memory-transfer.js transfer main coder ``` produces: ```js args = ['transfer', 'main', 'coder']; ``` The parsing loop starts at index 1. The first non-option value is therefore `main`, and it is assigned to `file`. Later, t ...[truncated 1656 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The share-mode transformation rules are internally contradictory: one section says first-person pronouns remain first-person, while later examples convert "I/my" into either source-agent references or second-person forms like "you/your." In a memory-transfer skill, this ambiguity can cause identity confusion, incorrect attribution of statements, and accidental reassignment of sensitive or authoritative context to the wrong agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Clone mode is documented as preserving all content verbatim, including user names, preferences, contact details, and other personal information, but the documentation does not prominently warn about the privacy and data-governance consequences of copying that data between agents. In this context, the skill is explicitly designed to replicate persistent memory, so unclear privacy guidance materially raises the chance of unauthorized propagation of sensitive user data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The safety section claims dry-run by default and explicit confirmation before execution, but earlier command examples include direct transfer commands and mode flags that imply immediate execution. This mismatch can mislead operators into assuming a non-destructive preview when the tool may actually perform a real memory copy, increasing the risk of unintended data disclosure or overwrite.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
## Safety Features

1. **Dry-run by default** - Preview before executing
2. **Explicit confirmation** - Never auto-execute without approval
3. **Backup option** - Can create backup before overwriting
4. **Mode clarification** - Always ask to confirm share vs clone mode

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
## Safety Features

1. **Dry-run by default** - Preview before executing
2. **Explicit confirmation** - Never auto-execute without approval
3. **Backup option** - Can create backup before overwriting
4. **Mode clarification** - Always ask to confirm share vs clone mode

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The privacy filter relies on a narrow set of hard-coded Chinese and simple English-style regexes, creating a false sense of sanitization in share mode. Sensitive user information expressed in other languages, formats, or phrasings will pass through unredacted, so operators may incorrectly assume that shared memory is safe when it is not.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Clone mode writes source memory verbatim into another agent workspace with no mandatory confirmation, warning, or policy gate on the normal non-interactive path. Because memory files may contain sensitive user data, secrets, or prior prompt context, this enables easy cross-agent propagation of private information and increases the blast radius of any sensitive data already present in one workspace.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The help text says share mode leaves 'I, my, me' as first-person so the target agent adopts the knowledge as its own. However, transformForTarget replaces 'I', 'me', 'my', and related contractions with the source agent's name or possessive form, explicitly converting first-person source experience into third-person narration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation example states 'I work as helper' becomes 'I work as Agent Skill Master'. In code, the pattern /\bI work as\b/ is replaced with ' works as', so the result would be third-person with a conjugated verb, not the documented first-person phrasing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.