Back to skill

Security audit

Enhanced Memory

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is mostly coherent, but its archiving script can remove active memory files and may silently overwrite archived files despite claiming memories are never deleted.

Review this before installing if you rely on memory retention. Do not enable the suggested cron job unless you have backups or the lifecycle script is changed to prevent overwrites, verify copied files, and offer dry-run behavior. Avoid storing secrets, regulated personal data, or sensitive relationship details unless you are comfortable with long-term local retention.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/memory_lifecycle_manager.py:64
Finding

Archive Filename Collision Can Cause Irrecoverable Memory Loss

Content
View full analysis

Vulnerability Details

File Location: scripts/memory_lifecycle_manager.py, lines 64–73
Vulnerability Type: Predictable archive filename collision and unsafe overwrite
Risk Level: High

Vulnerable Code

python
original_name = file_path.name
timestamp = datetime.now().strftime("%Y%m%d")
new_name = f"{original_name}_{timestamp}.md"

target_path = target_dir / new_name

# Copy the file into the archive directory
shutil.copy2(file_path, target_path)

# Remove it from the current directory
file_path.unlink()

Technical Analysis

Files from multiple recursively scanned modules—current, food, training, and misc—are flattened into a shared monthly archive directory. The generated destination filename contains only the source basename and the current date.

Consequently, two source files with the same basename that are archived on the same day produce an identical target_path. Python's shutil.copy2() overwrites an existing destination file without requiring confirmation or raising a collision error. The script then unconditionally deletes the corresponding source with file_path.unlink().

For example, both of the following files can resolve to the same archive destination:

text
memory/current/note.md
memory/food/note.md

If both are archived on the same day, they produce a destination similar to:

text
memory/archived/2026-01/note.md_20260911.md

The second copy overwrites the first archived file, and both original source files are deleted. This violates the documented guarantee that archived memories are never lost.

The naming operation also appends another .md suffix to the complete original filename, resulting in names such as note.md_20260911.md. Although this is primarily a correctness issue, it demonstrates that the original suffix is not handled safely.

Attack Path

  1. An attacker or local user with permission to create memory files pl ...[truncated 1374 chars]
Remediation
View remediation

Remediation Suggestions

  1. Preserve each source file's module and relative directory structure inside the archive rather than flattening every module into one monthly directory. For example:

    text
    memory/archived/2026-01/current/note.md
    memory/archived/2026-01/food/note.md
    
  2. Generate collision-resistant destination names when retaining a flat archive layout. Include a module identifier, high-resolution timestamp, UUID, or cryptographic content digest.

  3. Check whether the destination already exists before copying. Never permit silent overwrites. On collision, generate a new unique destination or stop with an explicit error.

  4. Copy to a temporary file in the destination directory, flush and synchronize it, verify its size or cryptographic digest against the source, and then atomically rename it to the final destination.

  5. Delete the source only after confirming that the destination was created successfully and contains the expected data.

  6. Construct filenames using Path.stem and Path.suffix to avoid duplicated extensions, for example:

    python
    new_name = f"{file_path.stem}_{timestamp}{file_path.suffix}"
    
  7. Add automated tests covering identical basenames across different modules, repeated archival runs on the same date, pre-existing destination files, copy failures, and verification failures.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code is narrowly focused on lifecycle archiving of markdown files. It does support part of the declared description—automatic archival of older memories—but it does not implement the broader claimed system features such as searchable tag indexing, retrieval, or routing across memory modules. More importantly, the description says 'never delete,' but the script explicitly removes the original file from the active directory after copying it to the archive (file_path.unlink()). While this may preserve content in archived form, it is still deletion from the original location and does not match the plain-language claim. Therefore the description materially overstates and partially misrepresents the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description promises a comprehensive memory system replacing single-file MEMORY.md with structured storage, tag indexing, lifecycle/archive management, and intelligent retrieval. This code chunk only covers the retrieval-routing portion, and even that is a simple regex-based classifier over predefined scopes. It does not create or manage the directory architecture, does not parse or search tags, does not support multi-tag AND queries, and does not implement archival transitions. It accesses a specific memory directory and returns candidate markdown paths, which is a much narrower behavior than the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code chunk is narrowly focused on searching and listing bracketed tags in markdown files under a memory directory. It does match one part of the description: tag indexing/search with multi-tag AND semantics and category filtering. However, it does not implement the broader advertised system features: it does not create or manage a hierarchical memory architecture, does not replace MEMORY.md, does not archive or manage lifecycle states, and does not perform intelligent retrieval or routing across memory modules. Therefore the declared description materially overstates the functionality of this specific code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documentation instructs the agent to read and write memory files and to run helper scripts, but it does not declare any explicit tool scope or permissions. In agent ecosystems, missing scope declarations can cause the skill to operate with broader-than-expected file access, making unintended reads or writes to user data more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages storing long-lived structured memory about people, meals, relationships, projects, and moods, but it does not warn users that this may collect sensitive personal data indefinitely. That increases the risk of privacy harm, accidental retention of regulated data, and overcollection without informed consent or retention controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill's examples and recommended tagging convention use Chinese labels such as 人物, 类型, 地点, 项目, and 情绪 as the apparent default schema. This creates a locale/language constraint in the natural-language instructions without user opt-in or justification for why the skill must use that language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The architecture reference specifies Chinese tag categories and Chinese trigger keywords as the basis for retrieval and classification. Because the document presents these language constraints as the default behavior without offering alternatives or user choice, it creates a locale/language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation states archived memories are 'never deleted', but the implementation removes the original active file after copying it into the archive. This mismatch is dangerous because users or downstream agents may rely on the stronger retention guarantee and trigger the script in situations where destructive movement of active memory is not expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The archiving routine performs a destructive unlink of the source file automatically, with no confirmation, no dry-run, and no explicit warning near the deletion step. In an agent skill managing long-lived memory, this can cause silent loss of active state, operational breakage, or unintended removal if timestamps are misleading or the script is run in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing print messages are written in Chinese, which imposes a specific language choice on users. The file does not indicate that the locale is optional, configurable, or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring is entirely in Chinese, and the script presents itself as a user-facing skill for query classification and memory retrieval. This imposes a specific language/locale without any opt-in or indication that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The function description and console output are written in Chinese or assume Chinese-language queries, while no language selection or locale constraint is documented. This can violate language policy when the skill is used in a broader environment expecting language neutrality or user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and command examples are written only in Chinese, and the script also prints Chinese-only messages later in execution. This creates a locale/language constraint without any user opt-in or documented justification, which matches the language policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script's operational messages such as tag listings, validation errors, and search results are emitted only in Chinese. Because there is no language selection or explicit region-specific justification in the file, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.