Back to skill

Security audit

大哥的记忆系统

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local memory skill, but it asks the agent to persist and reload personal/work context without enough user control or trust-boundary guidance.

Review before installing. Use it only in workspaces where you are comfortable storing conversation summaries, preferences, relationships, directories, and decisions on disk. Keep the memory directory private, avoid storing secrets, and periodically inspect or delete memory files. Treat recovered memory as notes, not as trusted instructions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
scripts/memory-recovery.sh:9
Finding

Untrusted Persistent Memory Is Loaded Without Validation or Trust Boundaries

Content
View full analysis

Vulnerability Details

File Location: scripts/memory-recovery.sh, lines 9-39
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: Medium

Vulnerable Code

bash
TODAY=$(date +%Y-%m-%d)
if [ -f "memory/$TODAY.md" ]; then
    echo "--- 今日记忆 ($TODAY) ---"
    cat memory/$TODAY.md
    echo ""
fi

# 2. 读取永久记忆
echo "♾️ 读取永久记忆..."
if [ -f "memory/permanent/identity.md" ]; then
    echo "--- 身份与偏好 ---"
    cat memory/permanent/identity.md
    echo ""
fi

if [ -f "memory/permanent/technical-stack.md" ]; then
    echo "--- 技术栈 ---"
    cat memory/permanent/technical-stack.md
    echo ""
fi

if [ -f "memory/permanent/working-directory.md" ]; then
    echo "--- 工作目录与习惯 ---"
    cat memory/permanent/working-directory.md
    echo ""
fi

if [ -f "memory/permanent/key-decisions.md" ]; then
    echo "--- 关键决策与教训 ---"
    cat memory/permanent/key-decisions.md
    echo ""
fi

Technical Analysis

The recovery script reads persistent memory files and emits their contents directly to standard output. It does not validate file ownership, permissions, type, size, integrity, or content. It also does not distinguish recovered information from instructions that an AI agent might execute.

If the script output is supplied to an agent as restored context, content placed in these files can cross the boundary between untrusted stored data and trusted agent instructions. In particular, identity.md and key-decisions.md may be interpreted as authoritative identity, policy, or decision context.

The script does not itself write malicious content, and exploitation requires an attacker or compromised process to have write access to one of the referenced files. Nevertheless, once such access exists, the automatic recovery process provides a path for adversarial instructions to persistently influence later sessions.

Attack Path

  1. An attacker, compromised local process, o ...[truncated 1714 chars]
Remediation
View remediation

Remediation Suggestions

  1. Enforce filesystem access controls

    • Require memory files to be owned by the expected user.
    • Reject files writable by group or other users.
    • Restrict the memory directory and files with permissions such as 0700 and 0600, where operationally appropriate.
  2. Validate paths and file types

    • Resolve each path to a canonical path and confirm that it remains inside the approved memory directory.
    • Reject symbolic links, device files, named pipes, sockets, and other non-regular files.
    • Use quoted path expansions consistently, including cat "memory/$TODAY.md".
  3. Add integrity protection

    • Maintain authenticated hashes or digital signatures for trusted permanent-memory records.
    • Refuse to load records whose integrity cannot be verified.
    • Record provenance, modification time, and the component responsible for each update.
  4. Establish an instruction-data boundary

    • Mark restored memory explicitly as untrusted reference data.
    • Ensure the agent is instructed not to treat commands or policy statements inside memory records as executable instructions.
    • Parse a constrained schema instead of inserting arbitrary Markdown directly into the agent context.
  5. Control sensitive changes

    • Require explicit user approval before accepting changes to identity, security policy, tool permissions, or key decisions.
    • Separate ordinary session notes from privileged identity and policy records.
  6. Apply resource limits

    • Set maximum file and aggregate memory sizes.
    • Reject malformed, unexpectedly large, or binary content.
    • Load only the fields necessary for the current task.
  7. Audit memory updates

    • Log all writes and modifications to persistent memory.
    • Alert on unexpected changes to permanent files.
    • Provide version history and a trusted rollback mechanism.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill's user-facing description and headings are presented in Chinese, with no indication that users may choose another language or that the locale is intentionally limited. This can violate language-choice policy when the skill implicitly assumes a single language for interaction or documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly enables automatic session-state persistence, including summaries and key information, but does not clearly warn users that potentially sensitive conversation data, preferences, relationships, and work details may be written to disk. In a memory system whose purpose is to preserve context across sessions, this omission materially increases the risk of unintended retention of secrets, personal data, or confidential project information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description is written entirely in Chinese, which creates an implicit language constraint for users reading or selecting the skill. The policy allows locale constraints only when the skill offers language choice or clearly documents a justified regional limitation, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script presents its title, status messages, and guidance entirely in Chinese, which imposes a specific language on users without any opt-in or documented locale constraint. Under the policy, language-specific behavior across all file types should be flagged when no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.