Back to skill

Security audit

AEP Session Evidence (过程存证)

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent, but it should be reviewed carefully because it can create durable, exportable records of conversation content with broad activation cues.

Install only if you intentionally want AI session activity recorded as durable evidence. Use it with explicit start/stop consent, avoid storing secrets or private conversation text in session-log.md, review the log before adding it as an artifact or exporting a .aep package, and be cautious with auto mode or any setup that reads ~/.aep/.secret automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs creation of a running session-log.md containing key Q&A and decisions and states that the log itself must be preserved. This is particularly dangerous because it operationalizes persistent natural-language transcript retention, which can capture secrets, personal data, credentials, proprietary content, or regulated information and then bind it into durable evidence artifacts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description uses broad natural-language triggers such as mentions of process recording or conversation ending, which can overlap with ordinary chat and cause the skill to activate unexpectedly. In this skill's context, accidental activation is more dangerous because it can start evidence logging, exporting, or secret-dependent commands without a narrowly scoped user request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's core behavior is to preserve the creative process as independently verifiable evidence, yet the opening description does not provide a strong upfront privacy warning or clear consent boundary before conversation data is captured and packaged. That is dangerous because users may disclose sensitive information in normal dialogue without realizing it is being persistently logged and exportable.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly aims to store who did what, when, with what inputs, decisions, and intermediate outputs as a hash-linked evidence trail. Even if some fields default to hashed storage, the surrounding workflow encourages retention of rich process metadata that can include sensitive user-provided content, making privacy and data minimization failures likely in real use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Triggering on generic phrases like '开始吧' or broad session state inference creates ambiguous activation conditions. Because this skill persists session evidence and logs dialogue, an overly permissive trigger can initiate durable data capture when the user only intended ordinary conversation flow, making the context materially more sensitive.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to rely on a secret stored in the user's home directory (~/.aep/.secret) for command execution. Even if framed as convenience, directing an agent toward user-resident secrets increases the chance of implicit secret access or propagation without explicit per-run user consent, which is risky in an adversarial or over-broadly triggered skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The activation description is written exclusively around Chinese trigger phrases and conversational cues, with no indication that users may opt for another language or locale. This can be a language-policy issue when a skill effectively assumes one language for activation without documenting choice or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.