Back to skill

Security audit

memocap

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is purpose-aligned, but it can broadly auto-activate, persist detailed user data, and run unaudited local scripts from the user's home directory.

Install only if you intend to use a persistent local memory system and trust the separate ~/.local/share/忆时 scripts and data store. Before use, narrow activation to explicit commands, require confirmation before storing personal or sensitive details, verify the helper scripts' origin and integrity, and keep controls for review, deletion, and purging of stored records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:46
Finding

Persistent Memory Poisoning Through Mandatory Storage and Recall

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:44
Finding

Global Agent Behavior Hijacking Through Mandatory Skill Rules

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:19
Finding

Execution of Unverified Scripts Outside the Audited Skill Package

Content
View full analysis
--keywords "k1,k2" --emotion <0-1> "[完整内容]" # recall:检索/核实(默认最相关3条,勿多;相似>0.5 即看;--judge 判定模式输出全文+相似度/类型/创建日,值必存第一段用) python3 $YISHI recall "关键词" --judge # merge:梳理时语义合并高相关簇(锚记忆→预览簇→--content+--apply 删旧存新) python3 $YISHI merge --id <锚ID> --threshold 0.68 # 其余子命令:forget 删除 | stats 统计 | export 导出 | recover 恢复 | capsule 时间胶囊 # 可视化:python3 $LOCAL_BASE/scripts/viz/viz.py(全景)/ mindmap.py(网状记忆图谱,D3 力导向) # 人物画像:python3 $LOCAL_BASE/scripts/viz/profile.py ``` ```markdown ## 模块详情 细册在 `~/.local/share/忆时/docs/modules/`(13-retrieval-store.md 检索存储、12-viz-profile.md 可视化画像、11-quick-commands.md 快捷命令等)。渐进式披露——遇场景才读对应模块,勿一次全读。 ``` ### Technical Analysis The reviewed project contains only `SKILL.md`; it does not include the referenced `memory_core.py`, visualization scripts, profile script, or module documentation. The Skill directs the agent to execute and trust files under a mutable directory in the user's home directory without verifying their origin, ownership, integrity, permissions, or symbolic-link status. Because Python executes the referenced file with the agent's operating-system permissions, replacing that file changes the effective code executed by the Skill without modifying the audited package. External module documentation also creates an unaudited instruction channel that ...[truncated 1562 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description embeds broad trigger phrases such as '记忆', '记住', '回想', 'recall', and 'remember', which are common in ordinary conversation and can cause the skill to activate unintentionally. In this skill, accidental activation is more dangerous than usual because the skill is explicitly designed to retrieve and persist memory, potentially causing unintended access to stored user data or unexpected writes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill is explicitly built for session persistence and is granted Write and Bash capabilities while directing data storage into a local shared directory. Persistence itself may be intentional, but from a security perspective it expands the blast radius of accidental activation or over-collection because user data can be durably written and later retrieved across sessions.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
description: "忆时记忆系统 - 类人记忆检索/存储/遗忘/胶囊/可视化。让 AI 拥有会遗忘、会联想、会涌现、会封存的记忆。触发词:忆时、记忆、记住、回想、回忆、recall、remember、时间胶囊、记忆检索、可视化、记忆脑图、人物画像。"
allowed-tools:
  - Read
  - Write
  - Bash
  - Glob
  - Grep

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest trigger field contains ambiguous activation phrases without boundaries or opt-in semantics, including common words like '回忆', 'remember', and '记住'. Because this skill has read/write/bash-backed persistence features, ambiguous invocation can lead to unrequested memory retrieval, storage, or related filesystem actions from normal user phrasing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to proactively store 'valuable information' across broad categories like decisions, preferences, emotions, time, and context. This creates a strong natural-language privacy risk because sensitive user data may be retained persistently without granular consent, minimization, or category-based exclusions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The requirement that stored memory be 'self-sufficient' and 'uncompressed' encourages verbatim preservation of detailed context, causes, actions, and consequences. In a memory system, that materially increases the chance of storing secrets, health details, personal identifiers, or confidential conversation fragments in durable form.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The language-style section mandates a default response style in Chinese (“默认简约直给...自动恢复正常句式”) and does not indicate that users may select another language or locale. This can violate language/locale policy expectations when no user opt-in or configurable language preference is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.