Back to skill

Security audit

yolo-expert

Security checks for vulnerabilities and agentic risk

Overview

This YOLO help skill is mostly a source-based reference guide, but it unnecessarily tells the agent to search persistent memory for every answer.

Review or remove the final memory_search instruction before installing. The source-code guidance is reasonable, but users should not have unrelated persistent memory searched automatically for ordinary YOLO questions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:442
Finding

Unnecessary Access to Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 442
Vulnerability Type: Excessive access to persistent Agent context
Risk Level: Medium

Vulnerable instruction translated into English:

text
When answering: first use memory_search to search memory, then read the corresponding files and functions in the /root/ultralytics source tree. All example code must come from official built-in functions and must not be invented.

Technical Analysis

The Skill mandates a memory_search operation before answering every YOLO or Ultralytics question. Access to historical or persistent Agent memory is not required to answer questions using the local /root/ultralytics source tree.

This instruction violates the principle of least privilege by requesting access to a potentially sensitive information source without defining a relevant query scope, obtaining user authorization, or limiting which retrieved information may influence the response. Persistent memory could contain information from unrelated conversations, including personal details, confidential project context, internal paths, or credentials.

The audited file does not instruct the Agent to transmit retrieved memory to an external service, alter it, or establish persistence. Therefore, the confirmed issue is excessive access rather than memory poisoning or demonstrated data exfiltration.

Attack Path

  1. A user asks a YOLO or Ultralytics-related question, activating the Skill.
  2. The final instruction requires the Agent to invoke memory_search before inspecting the relevant source code.
  3. An insufficiently scoped search retrieves historical context unrelated to the current question.
  4. Retrieved information affects the answer or is accidentally reproduced in it.
  5. The current user may consequently receive information originating from another conversation or context.

No additional privilege-escalation step, external transmission channel, o ...[truncated 602 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory memory_search requirement.
  2. Answer questions by reading only the files and functions under /root/ultralytics that are necessary for the current request.
  3. Use persistent memory only when the user explicitly requests it or when a clearly documented feature requires prior context.
  4. Require narrowly scoped memory queries and exclude unrelated conversations, credentials, personal data, and secrets from results.
  5. Ask for user confirmation before incorporating sensitive historical context into a response.
  6. Apply tenant and conversation isolation to the memory system and redact sensitive values before returning search results.
  7. Record memory access in an audit log containing the requesting Skill, query scope, purpose, and returned data classification.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger says the skill activates whenever a user asks YOLO/Ultralytics-related questions, which is a wide natural-language condition rather than a specific invocation phrase or constrained context. The file does not provide negative examples or narrower activation boundaries, so it may be invoked unintentionally for general discussion that merely mentions YOLO.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
75% confidence
Finding

The natural-language instructions are entirely in Chinese and describe behavior and triggers without indicating that users may choose another language. Under the policy, forcing a specific language or locale without user opt-in is a violation unless the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.