Back to skill

Security audit

chat2kb

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward chat-to-Markdown exporter that saves user-reviewed conversation summaries locally.

Install only if you are comfortable with selected conversation content being written to local Markdown files. Review the preview and destination path carefully, use dry-run or cancel for sensitive chats, and avoid exporting secrets or private details unless the storage location is appropriate.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill exports conversation content to disk but does not warn users that potentially sensitive chat data may be persisted locally. This creates a real privacy risk because users may unknowingly save secrets, personal data, or confidential project details into files that could later be accessed, synced, or backed up elsewhere.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The skill explicitly scans prior conversation data for previous conversation_id values and supports updating or appending to earlier exports, which introduces session persistence and cross-session linkage. This can make separate conversations traceable over time and increase privacy exposure by correlating discussions that a user may have expected to remain isolated.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
Before generating a new file, scan the conversation for a previous `conversation_id` for the same topic.

- If no previous export exists, generate a new ID
- If a previous export exists, ask whether to update, append, or create a new KB

Conversation ID format:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Hardcoding language: en without user opt-in can cause the exported knowledge base to misrepresent the conversation language or coerce multilingual/private content into English-oriented output. While not a direct code-execution issue, it can lead to inaccurate records, privacy misunderstandings, and unintended transformation of user content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description is broad enough to match many ordinary user requests such as saving, exporting, or documenting a conversation. In agent ecosystems that auto-route by natural-language matching, this can cause the skill to trigger unexpectedly and gain access to conversation content outside the user's precise intent, increasing the risk of unintended data capture or exfiltration into files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.