Back to skill

Security audit

Chen Memory Setup

Security checks for vulnerabilities and agentic risk

Overview

This memory setup skill is purpose-aligned but needs review because it recommends indexing long-term memory and past chat transcripts with a remote embedding provider without enough privacy safeguards.

Review this before installing if your workspace or chat history contains confidential, customer, regulated, or personal data. Prefer the local provider or memory-only indexing for sensitive work, avoid storing secrets or unnecessary private details in MEMORY.md or logs, protect provider API keys in a secure environment, and confirm the embedding provider's retention and deletion terms before enabling session indexing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:18
Finding

Remote embedding configuration may expose persistent memory and session transcripts to third-party providers

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly encourages enabling persistent memory search over MEMORY.md and past session transcripts, including personal preferences and project history, but provides no privacy or data-minimization warning. This can lead users to index sensitive personal or confidential workplace data into searchable storage and external embedding providers without informed consent or risk awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The MEMORY.md and daily log templates encourage storing long-term facts, decisions, preferences, and ongoing logs, but do not warn against recording secrets, health data, credentials, or other sensitive information. In practice, users may treat these files as a catch-all memory store, increasing the chance of sensitive data accumulation and later retrieval or exposure through search.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill instructs users to set provider API keys in the environment but does not mention secure credential handling. While setting environment variables is common, the omission may still contribute to unsafe practices such as committing secrets to files, shell history, or shared workspace configuration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.