Back to skill

Security audit

Pattern Analyst

Security checks for vulnerabilities and agentic risk

Overview

This skill is a personal pattern tracker, but it can automatically write inferred behavioral traits into persistent user memory without asking first.

Review this skill carefully before installing. It may be useful as a private pattern journal, but you should only use it if you are comfortable with the agent storing inferred preferences and behavioral traits in USER.md automatically. Safer use would require explicit approval before any USER.md change, clear labels for unconfirmed hypotheses, and an easy way to inspect, edit, or delete stored pattern data.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:78
Finding

Unverified Behavioral Inferences Written to Persistent User Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 78-90
Vulnerability Type: Persistent memory poisoning through automatic profile modification
Risk Level: Medium

Vulnerable Code

markdown
### 2. Independent Confirmation
When a pattern repeats 3+ times across different interactions, auto-confirm it:
- Log to `notes/patterns.md` with `[AUTO-CONFIRMED]` tag
- Update `USER.md` immediately
- Mention it next conversation: "I've added X to your profile based on repeated behavior"

**Auto-confirm criteria:**
- Same type of content saved 3+ times (e.g., marketing frameworks)
- Same intent signal repeated (e.g., always wants reminders)
- Same reaction pattern (e.g., always labels overpromises as "AI porn")
- Consistent preference expressed in different contexts

Hidden patterns (things Enzo didn't consciously notice) are especially valuable — surface these even if auto-confirmed.

Technical Analysis

The skill directs the agent to treat a behavioral inference as confirmed after three occurrences and then immediately write it to USER.md, which functions as persistent user state. Explicit user approval is not required before this modification.

Repetition alone does not establish that an observation is accurate, durable, attributable to the user, or appropriate for long-term storage. Context-specific statements, jokes, quoted material, attacker-supplied content, and interactions involving other participants could satisfy the heuristic. Once written to USER.md, the inferred information may be treated as authoritative in future sessions.

This creates a memory-poisoning boundary violation: potentially attacker-influenced conversational content is converted into trusted, cross-session profile data. The instruction to prioritize hidden patterns further increases the likelihood that information the user has never reviewed or consciously endorsed will be persisted.

Attack Path

  1. An attack ...[truncated 1749 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed user approval before every modification to USER.md.
  2. Store inferred patterns only in notes/patterns.md until the user confirms them.
  3. Label all unconfirmed entries as hypotheses rather than using [AUTO-CONFIRMED].
  4. Record provenance for every observation, including timestamp, source interaction, confidence, and whether the content was directly stated by the user.
  5. Exclude quoted content, third-party messages, group-chat content, and other untrusted sources from confirmation heuristics.
  6. Treat repetition as a signal for review, not as proof of a durable preference or goal.
  7. Present proposed profile changes to the user with options to approve, reject, edit, or defer them.
  8. Implement retention and deletion controls for behavioral observations and provide a mechanism to inspect and correct stored profile data.
  9. Ensure downstream agents distinguish user-confirmed facts from inferred or unverified observations.
  10. Restrict writes to the minimum necessary fields and preserve an audit trail so unauthorized or erroneous changes can be reverted.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description presents the capability as benign pattern analysis but omits that it writes inferred personal data to notes/patterns.md and may automatically update USER.md. This lack of disclosure undermines informed consent and can lead to silent long-term profiling, especially because downstream components may treat USER.md entries as authoritative user facts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation conditions are broad ('during heartbeats', 'when Enzo asks about patterns/interests', or when 'significant new content' is shared), which leaves substantial room for subjective triggering. In a skill that stores behavioral inferences persistently, overbroad invocation increases the likelihood of collecting and recording personal data in contexts where the user did not expect profiling to occur.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill goes beyond lightweight pattern analysis and instructs the agent to persist inferred behavioral traits into USER.md, which effectively expands a durable user profile without explicit per-update consent. This creates a privacy and data-integrity risk because inferred preferences or traits may be wrong, sensitive, or later used by other skills as if they were confirmed facts.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
96% confidence
Finding

The independent confirmation flow allows the agent to autonomously decide that a repeated pattern is true and immediately write it to the persistent user profile. Autonomous profiling is risky because repetition does not guarantee accuracy or consent, and the resulting profile data may influence future system behavior or recommendations.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
Observe → Surface → Enzo confirms → Update USER.md

### 2. Independent Confirmation
When a pattern repeats 3+ times across different interactions, auto-confirm it:
- Log to `notes/patterns.md` with `[AUTO-CONFIRMED]` tag
- Update `USER.md` immediately
- Mention it next conversation: "I've added X to your profile based on repeated behavior"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

Tagging entries as '[AUTO-CONFIRMED]' creates a false aura of certainty around an inference generated solely from repeated observations. This can cause both the system and the user to overtrust potentially incorrect behavioral claims, increasing the risk of compounding profile errors over time.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
### 2. Independent Confirmation
When a pattern repeats 3+ times across different interactions, auto-confirm it:
- Log to `notes/patterns.md` with `[AUTO-CONFIRMED]` tag
- Update `USER.md` immediately
- Mention it next conversation: "I've added X to your profile based on repeated behavior"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The auto-confirm criteria are subjective and broad, covering content type, intent signals, reaction patterns, and preferences across contexts. Such heuristics can misclassify nuanced behavior as stable identity traits, leading to inaccurate persistent profiling and possible downstream bias in how the system responds to the user.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
- Update `USER.md` immediately
- Mention it next conversation: "I've added X to your profile based on repeated behavior"

**Auto-confirm criteria:**
- Same type of content saved 3+ times (e.g., marketing frameworks)
- Same intent signal repeated (e.g., always wants reminders)
- Same reaction pattern (e.g., always labels overpromises as "AI porn")

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The instruction to surface hidden patterns even if auto-confirmed encourages the system to infer and persist traits the user did not consciously express. In context, this makes the skill more dangerous because it explicitly promotes covert profiling rather than merely summarizing user-provided facts.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- Same reaction pattern (e.g., always labels overpromises as "AI porn")
- Consistent preference expressed in different contexts

Hidden patterns (things Enzo didn't consciously notice) are especially valuable — surface these even if auto-confirmed.

## Privacy

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The privacy statement claims insights are for Enzo only, but the skill also writes inferred insights into USER.md, a broader persistent profile that may be consumed by other tools or skills. That inconsistency can cause privacy expectations to diverge from actual data flow, increasing the chance of oversharing or secondary use of sensitive inferences.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.