Back to skill

Security audit

Active Memory for Calculus Teaching

Security checks for vulnerabilities and agentic risk

Overview

This skill is a calculus tutor memory system, but it automatically profiles and stores student learning data without clear consent, retention, or deletion controls.

Install only if you are comfortable with automatic local profiling of student learning behavior. Before use, disable transcript persistence or dreaming if not needed, choose a protected storage directory, establish consent for students, and define how users can inspect, correct, and delete saved profiles, transcripts, dream summaries, and knowledge graphs.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (33)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The report explicitly advertises a 'zero-trigger memory' feature that stores or infers student information without an explicit 'remember this' command. In an educational skill handling learner preferences and mastery state, this creates a real risk of unintended data capture and retention without clear user consent or activation boundaries.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The quickstart explicitly promotes automatic memory recording, mastery tracking, error warning, and generated summaries stored under the user's home directory, but it does not warn users that conversation-derived data will be persisted locally and potentially contain sensitive educational or behavioral information. In a quickstart guide, omission of privacy and retention guidance increases the chance that users enable the feature without informed consent or understanding of where their data is stored.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The README explicitly advertises zero-trigger automatic memory extraction from student conversations and persistent learner profiling, but does not warn users that potentially sensitive educational data may be collected and retained without an explicit consent step. In an education context, this can expose personal preferences, learning weaknesses, and performance history, increasing privacy and compliance risk if users or deployers enable it without clear notice.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documented 'dreaming' feature performs background summarization, knowledge graph generation, and risk detection on learning sessions, yet the README does not clearly inform users that ongoing post-session processing may continue after the main interaction ends. Background processing of student data can surprise users and expand the amount of derived sensitive data stored or inferred about them.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The configuration examples show transcript persistence enabled and dream diary output written to a local filesystem path, but there is no explicit warning that sensitive student conversations and inferred learning data may be stored on disk. Local file persistence increases exposure to unauthorized access, accidental backup/sync leakage, and long-term retention beyond user expectations.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill explicitly advertises 'zero-trigger' automatic memory extraction and application, which creates an effectively unconstrained activation scope over ordinary educational conversation. In a tutoring context this can cause the system to collect and act on sensitive student data without clear invocation boundaries, informed consent, or predictable user control.

Vague Triggers

High
Confidence
95% confidence
Finding
The usage section says the skill works automatically during teaching scenarios without concretely specifying when it may activate or what inputs are in scope. That ambiguity increases the chance of over-collection, unintended profiling, and unauthorized downstream use of student conversation data.

Missing User Warnings

High
Confidence
97% confidence
Finding
The description promotes automatic remembering of preferences, mastery, and error patterns, but does not present a prominent user warning that transcripts and derived student profiles may be persistently stored. Because the data concerns learners and potentially minors, lack of notice materially increases privacy and compliance risk.

Missing User Warnings

High
Confidence
98% confidence
Finding
The configuration enables transcript persistence, periodic summarization, and diary output to a filesystem path, yet no prominent warning accompanies these settings. This is dangerous because operators may deploy privacy-invasive defaults that silently retain raw conversations and derived educational inferences.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The dream-system example shows generation of a DREAMS.md record containing detailed weaknesses, root causes, and mastery levels derived from student sessions without any user-facing privacy disclosure. Written summaries like this can be easier to browse, share, or leak than transient conversation state, increasing exposure of sensitive educational data.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The summary explicitly advertises automatic memory collection of student preferences, mastery tracking, error-pattern monitoring, and sharing of preference/path data with integrated skills, but it does not mention consent, minimization, retention, or access controls. In an education context, this can lead to silent collection and propagation of potentially sensitive learner profile data across components without users understanding the privacy impact.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The phrase '零触发自动记忆学生偏好' suggests always-on or triggerless collection of student preference data, but it does not define boundaries, consent conditions, or scope. That ambiguity is dangerous because it normalizes background behavioral collection and can be implemented far more broadly than users expect, especially for minors or educational environments where privacy expectations are higher.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The manifest description advertises automatic memory and insight generation 'without manual triggers,' which implies broad autonomous activation without clearly scoped conditions or user-controlled boundaries. In a skill that stores learner data and processes it over time, this can lead to unexpected collection or background handling of personal educational data beyond what a user reasonably anticipates.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The description explicitly promises auto-remembering student preferences, tracking concept mastery, and generating learning insights without any mention of consent, retention limits, or privacy policy framing. Because this skill is educational and appears designed to build persistent learner profiles, the lack of opt-in and policy guardrails increases the risk of silent profiling and unauthorized retention of user data.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The examples normalize automatic collection and reuse of a student's preferences, mastery level, and recurring mistakes without any visible notice, consent flow, retention policy, or privacy controls. In an educational context this creates behavioral profiling of a potentially sensitive user population and could lead implementers to store personal learning data by default in ways users do not expect.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The document explicitly describes cross-skill collection and sharing of student interaction records, error analysis, correctness, and timing data, but provides no indication of consent, minimization, retention limits, or access controls. In an educational context involving student data, this creates a real privacy and compliance risk because downstream skills may process behavioral and performance data without transparent notice or safeguards.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The configuration explicitly enables `active_memory` and `persist_transcripts: true`, while also defining automatic extraction rules over user messages without any visible scope limits, consent gate, or minimization controls. In a tutoring context, this can silently retain sensitive educational and behavioral data far beyond what is necessary for immediate assistance, increasing privacy and data exposure risk.

Missing User Warnings

High
Confidence
98% confidence
Finding
The manifest describes persistent transcript storage, profile updates, knowledge-graph building, fact extraction, and automatic interventions, but contains no indication of user notice, consent, retention period, or privacy safeguards. Because the skill is designed to infer mastery, errors, preferences, and learning gaps from conversations, it creates a substantial profiling and surveillance risk if deployed as-is.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The prompt instructs the agent to automatically collect, retain, and summarize user learning data in the background without a clear user-facing notice or consent flow. This creates a privacy risk because students may disclose sensitive educational or behavioral information that is persistently profiled and processed beyond the immediate conversation.

Missing User Warnings

High
Confidence
99% confidence
Finding
The skill directs the AI to remember user preferences and performance signals without asking, including inferred traits such as style, pace, and error patterns. This is dangerous because it enables silent profiling of a student over time, which can capture personal characteristics and educational performance data without informed consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The page explicitly advertises 'automatic memory' and periodic summarization of student learning data, including preferences, learning style, mastery, and historical error patterns, but provides no notice about retention, consent, storage, sharing, or deletion. In an education context this is sensitive behavioral data, so silently retaining and profiling students increases privacy and compliance risk even if the page itself is only promotional HTML.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The file contains a full conversational transcript plus derived learner facts, which is broader than minimally necessary and includes educational preference and performance information. Storing raw transcript content without any stated scope, minimization rule, retention limit, or activation constraint increases privacy risk because sensitive user data can be collected or reused beyond the immediate task.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The tool persists session-derived learning summaries to a markdown file automatically, including inferred mastery, errors, and knowledge-graph data, without any consent, warning, retention control, or access restriction. Because the content is derived from transcripts and extracted facts, it may contain sensitive educational or personal data and create an unintended local privacy leak.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The tool loads per-student profile and recent memory data from disk based solely on a provided student_id, with no visible consent, access control, disclosure, or validation in this component. In an agent setting, this can expose sensitive educational history or behavioral data to unauthorized callers if the tool is invoked for arbitrary students.

Ssd 3

Medium
Confidence
91% confidence
Finding
The feature description promotes automatic retention, summarization, and organization of student conversations without stating consent boundaries, minimization rules, or limits on what is kept. Because the skill is designed for educational use and handles learner performance and error patterns, the derived data can be sensitive and create meaningful privacy harm if collected broadly by default.

Static analysis

No suspicious patterns detected.