T02 · Agent Memory Poisoning
- Location
scripts/fetch_events.py:202- Finding
Untrusted Remote Event Content Persisted in Agent Memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill fetches public Luma event listings and stores a disclosed local event cache, with no evidence of credential theft, code execution, or deceptive behavior.
Install only if you are comfortable with the skill contacting lu.ma and saving fetched public event metadata locally for follow-up questions. Treat event names, venues, and host text as untrusted external content, and clear the memory file if you do not want prior event lookups retained.
scripts/fetch_events.py:202Untrusted Remote Event Content Persisted in Agent Memory
Referenced artifact was not completely inspected
- Removed obsolete `README.md`; consolidated docs in `SKILL.md`.
The skill advertises and relies on network access plus local file read/write persistence, but it does not declare any explicit tool scope or permissions boundaries. That increases the chance the agent invokes the skill with broader capabilities than the user expects, weakening least-privilege controls and making unintended data access or persistence harder to audit.
The invocation description is broad enough to match many generic requests about events, meetups, conferences, and things happening in cities, which can cause over-triggering. In an agent environment, an over-broad trigger can silently expand network activity and local persistence into conversations where the user did not specifically ask to use Luma or fetch/store external event data.
The skill auto-persists fetched event data to a local memory file, but this retention behavior is not clearly surfaced in the high-level description where a user or orchestrator would expect privacy-relevant behavior to be disclosed. Hidden or under-disclosed persistence can create privacy and compliance issues, especially if queries, venues, hosts, or user-interest patterns are later inferred from stored event data.
The skill silently persists fetched event data to a workspace memory file even though its declared purpose is just to fetch and return upcoming events. Hidden statefulness increases data-retention risk, creates side effects across runs, and can surprise operators who expect a read-only lookup tool.
This code manages local event history by loading, overwriting, and pruning records on disk, adding undisclosed stateful behavior. Such persistence can accumulate external content across sessions and expose prior query history or fetched metadata to other components that can access the workspace.
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
def save_events(events):
"""Save events to JSON file, overwriting."""
ensure_memory_dir()
with open(EVENTS_FILE, 'w', encoding='utf-8') as f:
json.dump(events, f, indent=2, ensure_ascii=False)
def prune_old_events(events, hours=24):
During standard execution, the skill updates and saves event history as a side effect of answering requests, rather than only returning fetched results. In an agent environment, this is more dangerous because workspace memory may be shared or later consumed by other skills, enabling unintended cross-session data exposure and behavior not described to users.
No suspicious patterns detected.