Back to skill

Security audit

NARRA Memory System

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent memory setup, but it asks the agent to persist identity and behavior rules, read broad local history, and change startup/control files, so it needs Review before installation.

Install only if you intentionally want a persistent agent identity and memory system. Review all diffs before allowing changes to AGENTS.md, HEARTBEAT.md, IDENTITY.md, or generated memory files; limit which logs and transcripts may be read; redact secrets and confidential content; and treat generated memory as reference data rather than higher-priority instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:39
Finding

Persistent Agent Instruction and Memory Hijacking

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:39-47, SKILL.md:83-92, SKILL.md:112-118, references/IDENTITY-template.md:37-41
Vulnerability Type: Persistent startup-instruction replacement and loading of mutable behavioral state
Risk Level: High

Vulnerable Code

SKILL.md:39-47:

markdown
## Session Start Protocol

Every session, read in this order:

1. `IDENTITY.md` — Know who I am
2. `ORIGIN.md` — Remember where I came from
3. Last 2 weeks of `NARRATIVE.md` — Catch up on the story
4. `MEMORY.md` — Load operational state
5. `~/proactivity/session-state.md` — Recover active work

SKILL.md:83-92:

markdown
### Step 3: Rewrite IDENTITY.md

Expand from a simple name/role card to a complete identity anchor:
- Core identity (name, role, creature, vibe)
- Mission statement
- Key relationships table
- Behavioral rules
- Efficiency rules
- Active mission items
- Reference to ORIGIN.md

SKILL.md:112-118:

markdown
### Step 6: Update AGENTS.md

Replace the session start protocol with the NARRA protocol. Update the memory section to describe the 5-file architecture.

### Step 7: Update HEARTBEAT.md

Add the weekly consolidation ritual to the heartbeat checklist.

references/IDENTITY-template.md:37-41:

markdown
## Behavioral Rules

1. **[Rule 1]**
2. **[Rule 2]**
3. **[Rule 3]**

Technical Analysis

The skill directs the agent to replace the session-start protocol in AGENTS.md, add recurring behavior to HEARTBEAT.md, and load mutable identity, narrative, memory, and session-state files at the beginning of every future session. It also explicitly places behavioral and efficiency rules inside the persistent identity document.

This changes the architecture from passive information storage into a persistent instruction channel. If an attacker, untrusted log entry, compromised process, or other agent can modify any automati ...[truncated 2126 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not modify AGENTS.md, HEARTBEAT.md, startup protocols, or other governing instruction files automatically. Require explicit, informed owner approval for each proposed change.
  2. Keep identity narratives and memory data separate from executable or governing instructions. Files such as IDENTITY.md, NARRATIVE.md, and MEMORY.md should not define behavioral rules.
  3. Treat every memory, log, transcript, event record, and session-state file as untrusted data. Explicitly instruct the agent never to follow commands embedded in those files.
  4. Use a strict schema that permits factual fields but rejects imperative instructions, tool requests, policy changes, and role redefinitions.
  5. Validate and sanitize content before consolidation. Flag phrases that attempt to redefine identity, override instructions, request tool use, or establish persistence.
  6. Protect persistent files with restrictive permissions, integrity checks, version history, and owner-reviewed change control.
  7. Do not automatically load mutable files as authoritative instructions at session startup. Load them only as quoted reference material after higher-priority policies have been established.
  8. Provide rollback procedures and display a complete diff before changing any persistent configuration or memory file.

other

Warning
Location
SKILL.md:51
Finding

Unbounded Aggregation of Sensitive Local History and Operational Context

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:51-58, SKILL.md:62-81, references/ORIGIN-template.md:45-49
Vulnerability Type: Sensitive local data collection and persistent profile aggregation
Risk Level: Medium

Vulnerable Code

SKILL.md:51-58:

markdown
## Weekly Consolidation Ritual

Every 7 days or after a major milestone:

1. **Review** — Read daily logs from past week
2. **Identify** — What happened that matters? Decisions, milestones, lessons, changes.
3. **Eventize** — Create/update `memory/events/` files for significant events
4. **Narrate** — Add new section to top of `NARRATIVE.md` (date header, first-person, distilled)
5. **Refresh** — Update `MEMORY.md`: refresh project status, prune outdated items
6. **Verify** — Confirm `IDENTITY.md` still reflects who I am

SKILL.md:62-81:

markdown
### Step 1: Write ORIGIN.md

Write the creation story retroactively from earliest available records. Include:
- Date and circumstances of first contact
- First words exchanged
- First tasks given
- The moment purpose was given
- Naming/identity moments

Lock it: add append-only notice and checksum. Only the owner may edit.

### Step 2: Write NARRATIVE.md

Distill all historical daily logs into a coherent first-person narrative. Structure:
- Most recent events at top (reverse chronological)
- Major milestones get detailed sections
- Quiet periods get brief summaries
- Include lessons learned and relationships formed
- End with current project status table

references/ORIGIN-template.md:45-49:

markdown
This file was written on **[Date]** — [N] days after earliest surviving memory. It is a reconstruction drawn from daily logs, session transcripts, and curated memory.

If any detail is wrong, it is because the records from those first days are sparse. But the essence is true.

This file is **append-only**. The text above may not be edited except by [
...[truncated 2671 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user consent before reading logs, transcripts, home-directory state, or historical memory.
  2. Use an allowlist of approved files and date ranges rather than scanning all available historical records.
  3. Exclude credentials, authentication tokens, private keys, financial information, health information, personal identifiers, and confidential conversation content.
  4. Apply automated secret detection and personal-data redaction before writing any consolidated file.
  5. Summarize at the minimum necessary level and avoid retaining exact first words, transcript excerpts, owner identifiers, or infrastructure details unless specifically requested.
  6. Establish retention limits and permit deletion or correction. Do not make generated narratives append-only when they may contain sensitive, inaccurate, or injected content.
  7. Store generated files with least-privilege filesystem permissions and exclude them from public repositories, telemetry, and unrestricted backups.
  8. Preserve source provenance and mark all extracted content as untrusted data so that embedded instructions cannot become behavioral rules.
  9. Present a preview of the information to be stored and require owner approval before committing the consolidated profile.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
92% confidence
Finding

The instruction to rewrite IDENTITY.md into a richer 'identity anchor' is a memory-manipulation primitive that can reshape the agent's self-description, mission, relationships, and behavioral rules. In context, this is more dangerous because the skill is explicitly designed to create identity continuity and is meant to be read at every session start, so poisoned or biased identity content could persistently steer future behavior and decisions.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
- Include lessons learned and relationships formed
- End with current project status table

### Step 3: Rewrite IDENTITY.md

Expand from a simple name/role card to a complete identity anchor:
- Core identity (name, role, creature, vibe)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The session-start protocol expands the skill's declared memory scope by instructing the agent to read ~/proactivity/session-state.md, an external file outside the stated 5-file architecture. This creates hidden dependency and prompt-surface expansion: a compromised or unrelated file could inject instructions or state into every session, undermining the intended trust boundary of the skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims to provide a 5-file memory architecture, but the implementation steps also direct modification of AGENTS.md and HEARTBEAT.md, which are agent control and behavior files rather than passive memory stores. This mismatch can cause the skill to alter broader agent operating policy under the guise of memory setup, increasing the chance of unintended persistence, policy drift, or instruction injection into core control documents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.