Back to skill

Security audit

Hermes Memory CN

Security checks for vulnerabilities and agentic risk

Overview

This local memory skill is mostly coherent, but it needs review because it can persist broad conversation data and contains file-writing paths that can overwrite Markdown or instruction files.

Install only if you are comfortable with a local tool storing conversation memories, trading details, preferences, and generated Markdown on disk. Avoid storing secrets or regulated data, review generated skill drafts manually, and restrict exports/drafts to safe directories until path validation and consent/redaction controls are added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/memdb.py:291
Finding

Arbitrary Markdown File Overwrite Through an Unsanitized Memory Type

Content
View full analysis
int: """添加记忆,自动去重(相似度>0.95则更新)""" vec = embed(content) rows = self.conn.execute("SELECT id, embedding FROM memories_vec").fetchall() for row_id, emb_bytes in rows: if emb_bytes and cosine_sim(vec, emb_bytes) > 0.95: self.conn.execute(""" UPDATE memories SET content=?, updated_at=CURRENT_TIMESTAMP, type=COALESCE(?,type), entity=COALESCE(?,entity), severity=COALESCE(?,severity) WHERE id=? """, (content, type, entity, severity, row_id)) self.conn.execute("UPDATE memories_vec SET embedding=? WHERE id=?", (vec, row_id)) self.conn.commit() return row_id ``` ```python def export_markdown(self, output_dir: str): os.makedirs(output_dir, exist_ok=True) rows = self.conn.execute( "SELECT content, type, entity, status, severity, source, created_at, updated_at FROM memories ORDER BY type, updated_at DESC" ).fetchall() by_type = {} for r in rows: t = r[1] or "note" by_type.setdefault(t, []).append(r) for t, items in by_type.items(): path = os.path.join(output_dir, f"{t}.md") with open(path, "w", encoding="utf-8") as f: f.write(f"# {t}\n\n") for item in items: content, _, entity, status, severity, source, created, updated = item date = (created or "")[:10] f.write(f"- [{date}] [{status or 'active'}] {content}") ``` ### Technical Analysis The memory `type` fie ...[truncated 2072 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/skill_evolve.py:137
Finding

Arbitrary File Overwrite and Instruction Injection in Generated Skill Drafts

Content
View full analysis
## 执行步骤 1. {content} ## 输入输出 - **输入**: - **输出**: ## 注意事项 --- *此草案由 skill_evolve 自动生成,需人工审核后发布* """ with open(draft_path, "w", encoding="utf-8") as f: f.write(draft) ``` ```python p = sub.add_parser("draft", help="生成skill草案") p.add_argument("pattern_id", type=int) p.add_argument("--name", default=None) sub.add_parser("list", help="列出所有模式") p = sub.add_parser("promote", help="确认升级为skill") p.add_argument("pattern_id", type=int) p.add_argument("--name", required=True) ``` ### Technical Analysis The caller-controlled `--name` value is incorporated directly into `draft_path`. It is not checked for absolute paths, directory separators, traversal components, or unsafe characters. As a result, the generated file can escape `skill_drafts`. Opening it with `"w"` replaces any existing writable Markdown file. The generated document also interpolates untrusted pattern content and similar-memory content directly into: - YAML front matter. - Markdown headings and lis ...[truncated 2280 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/install.md:10
Finding

Unpinned Python Dependencies and Mutable Model Downloads

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/memory_tool.py:43
Finding

Automatic Persistence of Broad Raw Conversation Content in Plaintext

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a general-purpose 'human-brain-level' memory system for remembering important information from conversations and automatically recalling it later. The supplied code chunk does provide local memory operations and some automatic writing/search support, so it partially aligns. However, its core implemented intelligence is not general-purpose: the automatic memory extraction is heavily tailored to trading/investment concepts like positions, strategy, and lessons, with only one broader category for preferences. Also, the declared trigger phrases such as '之前说过' or '上次聊到' are not reflected in this script's write heuristics; the script instead responds to specific hardcoded keywords. Finally, the claim that it will 'automatically remember next chat' is not demonstrated by this code chunk, which only exposes explicit commands and a wrapper over memdb.py. Therefore the description materially overstates and mischaracterizes the behavior of the provided code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是通用对话长期记忆:记住用户说过的重要信息、按“我上次说了什么”等触发进行回忆/搜索,并自动遗忘过时信息。实际代码并未实现这些功能。它没有处理用户会话记忆的存取、查询、回忆触发或遗忘策略;相反,它专门处理 pattern 类型的操作模式,统计重复次数,达到阈值后生成 skill 草案,并支持 promote 为正式 skill。这是一个用于从重复行为中演化新技能的开发/管理脚本,其主要目的与“人脑级记忆系统”明显不同,因此构成实质性描述不符。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, common conversational terms such as '记住', '之前说过', and '忘了什么', making accidental activation likely. In this skill's context, accidental activation is more dangerous because activation can lead to persistent storage of user data and shell/file operations, creating unintended retention and side effects from ordinary chat.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
python3 scripts/memdb.py search "止损策略" --limit 5

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents shell execution plus file read/write behavior but declares no tool scope or permission boundaries. In an agent environment, this creates an unnecessarily broad capability surface: a memory-oriented skill could invoke arbitrary local commands and persist or modify local data without any explicit restriction, increasing the risk of misuse or prompt-triggered side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill strongly encourages long-term retention of 'everything important' said by the user, but does not clearly warn that this creates persistent local records of potentially sensitive personal, financial, or strategic information. The local-only claim reduces cloud exposure but does not remove privacy or endpoint-compromise risk; it may even lull users into oversharing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Marketing the skill as remembering everything important across chats encourages broad, normalized retention of personal data. Even without overtly malicious intent, this framing increases the chance that both users and agents will treat persistent capture as default behavior, which raises privacy and misuse risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.