Back to skill

Security audit

Memory Self-Heal

Security checks for vulnerabilities and agentic risk

Overview

This skill is not deceptive, but it asks agents to scan broad memory/log/task state and write reusable recovery rules with limited scoping or validation.

Review before installing. This skill may be useful for resilient agent workflows, but it should be used only where the agent's memory, task files, and logs are scoped to the current project and do not contain secrets. Prefer adding limits for which files may be scanned, redaction of credentials, and user approval before storing reusable rules that affect future sessions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:36
Finding

Overbroad Recursive Inspection of Potentially Sensitive Agent State

Content
View full analysis
/dev/null ``` ``` ### Technical Analysis The skill instructs the agent to inspect workspace memory, task queues, runtime logs, channel logs, other skills, and core agent documentation. The example commands recursively search entire directory trees and return surrounding context for matches including `auth` and `token`. This collection strategy is broader than necessary to diagnose a specific failure. Files and surrounding lines unrelated to the current task may contain credentials, private conversation content, authentication diagnostics, internal configuration, or data belonging to other tasks. The safety rule against logging secrets does not prevent these commands from reading secrets or returning them into the active agent context. The skill does not define task-level scoping, file allowlists, secret redaction, access approval, or isolation between projects. It therefore weakens least-privilege boundaries at the application level. It does not independently grant new operating-system privileges; exposure is limited to files already readable by the invoking agent. ### Attack Pa ...[truncated 1328 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:110
Finding

Unvalidated Recovery Guidance Can Be Written to Persistent Agent Memory

Content
View full analysis
- Signature: - Class: - Attempt1: -> - Attempt2: -> - Final: - Artifact/Evidence: - Reusable rule: ``` ``` ### Technical Analysis The workflow requires an entry to be appended after each self-healing cycle, including a reusable rule. Recovery decisions may be derived from memory, task files, queues, runtime logs, channel logs, other skills, or core documentation. Some of those sources may contain attacker-controlled or otherwise untrusted text. The skill does not require provenance checks, trust classification, sanitization, independent validation, or user approval before converting recovered information into persistent guidance. Consequently, misleading content can be interpreted as a successful fix and preserved as a reusable rule that affects later sessions. The issue is amplified by the direct-fix policy, which tells the agent to apply a best-known fix from memory. A poisoned rule can therefore cross a session boundary and repeatedly influence future recovery behavior. The documentation does limit retries and prohibits unconfirmed destructive operations, which reduces but does not eliminate the risk. ### Attack Path 1. An attacker gains the ability to influence a scanned task file, queue entry, log, channel record, or existing memory entry. 2. The attacker inserts a plausible recovery instruction associated with a recognizable error signature. 3. The corresponding failure triggers the evidence scan. 4. The agent treats the planted content as a known fix and attempts ...[truncated 1309 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is framed as a general-purpose recovery mechanism for repeated failures, stalls, and inference from prior evidence, which makes its invocation scope broad and applicable across many task types. Broad trigger scope can cause the agent to activate autonomous retry, evidence scanning, and memory reuse behaviors in contexts where they are unnecessary or inappropriate, increasing the chance of unintended actions or data exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Using 'Agent claims completion without verifiable artifact' as a trigger assumes artifacts are the right success signal for all tasks, but many legitimate tasks are advisory, conversational, or analytical and may not produce files or links. In those cases, the skill could spur unnecessary self-heal loops, repeated tool use, or escalation attempts based on a false failure condition.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
## Safety Rules

- Never auto-run destructive operations without confirmation
- Never log secrets/tokens in memory files
- Max 3 retries per blocker signature per task
- Prefer deterministic steps over broad speculative retries

Static analysis

No suspicious patterns detected.