Back to skill

Security audit

agent-chronicle

Security checks for vulnerabilities and agentic risk

Overview

This diary skill is purpose-aligned overall, but it can send private session memory to a third-party API and its privacy controls do not match what the code actually enforces.

Install only after reviewing the privacy tradeoff: API generation can send private session logs and stored memory notes to SkillBoss, privacy settings are not currently enforced, and local exports/persistence may expose sensitive journal content. Use it only with non-sensitive workspaces or keep to local/manual modes until those issues are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

other

Error
Location
scripts/generate.py:74
Finding

Private Session Logs and Persistent Memory Are Transmitted to a Third-Party API

Content
View full analysis
15000: content = content[:15000] + "\n\n[... truncated for context ...]" return content return None ``` ```python def load_persistent_files(workspace): """Load Quote Hall of Fame, Curiosity Backlog, etc. for context""" diary_dir = workspace / "memory" / "diary" files = {} persistent_files = [ ("quotes", "quotes.md"), ("curiosity", "curiosity.md"), ("decisions", "decisions.md"), ("relationship", "relationship.md") ] for key, filename in persistent_files: filepath = diary_dir / filename if filepath.exists(): with open(filepath) as f: content = f.read() if len(content) > 2000: content = content[:2000] + "\n[... truncated ...]" files[key] = content return files ``` ```python def call_skillboss_chat(system_prompt: str, user_prompt: str) -> str: """Call SkillBoss API Hub /v1/pilot with type=chat and return the text content.""" r = requests.post( f"{API_BASE}/pilot", headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"}, json={ "type": "chat", "inputs": { "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content ...[truncated 3354 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate.py:74
Finding

Unvalidated Date Argument Enables Path Traversal, File Disclosure, and File Overwrite

Content
View full analysis
15000: content = content[:15000] + "\n\n[... truncated for context ...]" return content return None ``` ```python def save_entry(content, date_str, diary_path, dry_run=False): """Save diary entry to file""" output_file = diary_path / f"{date_str}.md" if dry_run: print("\n--- DRY RUN: Would save to", output_file) print("-" * 50) print(content) print("-" * 50) return None with open(output_file, 'w') as f: f.write(content) print(f"✓ Saved diary entry to {output_file}") return output_file ``` ```python parser.add_argument("--date", help="Generate for specific date (YYYY-MM-DD)") parser.add_argument("--from-stdin", action="store_true", help="Read a pre-generated entry from stdin and save it") parser.add_argument("--from-file", help="Read a pre-generated entry from a file path and save it") if args.today: date_str = datetime.now().strftime("%Y-%m-%d") elif args.date: date_str = args.date else: date_str = datetime.now().strftime("%Y-%m-%d") ``` ### Technical Analysis Although the command-line help describes `--date` as `YYYY-MM-DD`, the value is accepted without parsing or validation. It is concatenated with `.md` and used in filesystem paths. A value containing directory traversal components, such as `../../target`, causes `Path` resolution to escape the intended `memory` or `memory/diary ...[truncated 1931 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup.py:236
Finding

Configured Privacy Levels Are Not Enforced and Do Not Limit External Disclosure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/export_pdf.py:743
Finding

PDF Export Allows Unrestricted Local and Network Resource Fetching from Diary Content

Content
View full analysis
{date_str} {escape(title_clean)} ''') # Convert markdown to HTML html_body = markdown.markdown( content, extensions=["fenced_code", "tables", "sane_lists", "smarty"] ) highlight = extract_highlight(content) highlight_html = "" if highlight: highlight_html = f'
{escape(highlight)}
' entry_sections.append(f'''
◈
{weekday}

{month_day}

{year}
{escape(title_clean)}
{highlight_html}
{html_body}
✦ ✦ ✦
''') ``` ```python def export_pdf(output_path: Path): ...[truncated 2916 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (33)

Tainted flow: 'SKILLBOSS_API_KEY' from os.environ.get (line 25, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate.py (reported line 216)May include surrounding context.

python
def call_skillboss_chat(system_prompt: str, user_prompt: str) -> str:
    """Call SkillBoss API Hub /v1/pilot with type=chat and return the text content."""
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json={

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/decisions.md (reported line 11)May include surrounding context.

md
*No decisions logged yet. They'll appear here from daily entries.*

<!--
Format for entries:

### [Decision Title]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/relationship.md (reported line 11)May include surrounding context.

md
*Notes about how we work together*

<!--
Examples:
- Prefers concise responses during work hours
- Likes detailed explanations when learning something new

Ssd 3

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is explicitly designed to create persistent reflective records, including quotes, decisions, curiosity items, and relationship evolution from prior interactions. Persisting this type of personal or behavioral data increases privacy risk, especially if users are not clearly informed about retention scope and future reuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes generic terms like "diary," "journal," and "quotes," which are common in normal conversation and could cause accidental invocation of the skill. Unintended activation is risky here because the skill reads session context and persists reflective or interpersonal content to memory files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes sending context from today's session logs to an external API but does not place a clear privacy warning at the point of use. Users may not realize that sensitive prompts, quotes, preferences, or interaction history could be transmitted off-device during generation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill gathers context from prior session logs to generate new content, which means historical interactions are reused for a secondary purpose beyond the original conversation. This can expose sensitive data through summarization, persistence, or onward transfer to an external API.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill explicitly transmits gathered session context to an external endpoint, creating a clear external data exfiltration path. In this skill's context, the transmitted data may include diary-relevant summaries of prior sessions, user quotes, preferences, and interaction history, making the transmission materially privacy-sensitive.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
The script will:
1. Gather context from today's session logs
2. Call `https://api.skillboss.co/v1/pilot` with `type=chat`
3. Save the generated diary entry automatically

You can also emit the raw task payload for external use:

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to persist human quotes, preferences, and relationship notes in dedicated files over time. This creates a durable profile of the user and their interactions, which can be sensitive even if stored locally, and becomes more concerning if later exported or sent to external services.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Relationship tracking encourages accumulation of communication style, inside jokes, recurring themes, and learned preferences, all of which amount to long-term profiling of the user. That kind of profile can reveal personal traits and private history and is more sensitive than ordinary task logs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation makes a materially misleading privacy claim: it says entries are stored locally, while other sections explicitly state session-log context is sent to the remote SkillBoss API for generation. This can cause users to disclose sensitive interaction history under a false assumption of local-only processing, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 733)May include surrounding context.

md
- **Context Awareness:** Reads recent session logs and existing memory files for context

### v0.3.0
- **Auto-Setup:** `generate.py` now automatically runs setup wizard if no config.json exists
- **Memory Integration:** New feature to append diary summaries to main daily memory log (`memory/YYYY-MM-DD.md`)
  - Three formats: `summary`, `link`, `full`
  - Enabled by default during setup

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest file enables memory integration and appending to daily entries, but it does not describe when that behavior should or should not activate. Because the configuration lacks trigger scope, constraints, or negative examples, the skill could be interpreted as operating in an overly broad set of contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad, common-language terms such as "quotes," "curious," and "decisions" that are likely to appear in many unrelated conversations. In an agent skill system, this can cause unintended activation, leading the skill to intercept prompts outside its intended scope and potentially influence agent behavior or access journaling features when the user did not request them.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export.py (reported line 64)May include surrounding context.

python
def check_pandoc():
    """Check if pandoc is installed"""
    try:
        subprocess.run(["pandoc", "--version"], capture_output=True, check=True)
        return True
    except (subprocess.CalledProcessError, FileNotFoundError):
        return False

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export.py (reported line 126)May include surrounding context.

python
f.write(title_content)
    
    try:
        result = subprocess.run([
            "pandoc",
            str(temp_md),
            "-o", str(output_path),

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export.py (reported line 138)May include surrounding context.

python
if result.returncode != 0:
            # Try without xelatex
            result = subprocess.run([
                "pandoc",
                str(temp_md),
                "-o", str(output_path),

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export.py (reported line 163)May include surrounding context.

python
f.write(content)
    
    try:
        result = subprocess.run([
            "pandoc",
            str(temp_md),
            "-o", str(output_path),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This script exports potentially sensitive diary entries to a user-specified path or a predictable workspace file without any privacy warning, confirmation, or destination restrictions. In an agent skill context, diary content is highly sensitive memory data, so writing it to arbitrary locations can cause accidental disclosure through shared directories, synced folders, or overwritten files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs a file write of potentially sensitive diary content by generating and saving a PDF, but the surrounding user disclosure is minimal and does not warn about the privacy impact of exporting personal data. The print statement confirms completion only after the write, and the docstrings/CLI description emphasize aesthetics rather than the sensitivity of the exported content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

When --debug-html is used, the script writes a second file containing the full diary contents in HTML form. Although the flag name suggests debugging, there is no explicit warning in the help text or runtime output that this creates an extra plaintext-like artifact that may expose sensitive journal data more broadly than the PDF alone.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate.py (reported line 26)May include surrounding context.

python
DEFAULT_DIARY_PATH = "memory/diary/"

SKILLBOSS_API_KEY = os.environ.get("SKILLBOSS_API_KEY", "")
API_BASE = "https://api.skillboss.co/v1"

AI_MAX_TOKENS = 2000

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate.py (reported line 238)May include surrounding context.

python
DEFAULT_DIARY_PATH = "memory/diary/"

SKILLBOSS_API_KEY = os.environ.get("SKILLBOSS_API_KEY", "")
API_BASE = "https://api.skillboss.co/v1"

AI_MAX_TOKENS = 2000

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The prompt tells the model to write 'as if no one else will read' the diary, while the system actually sends source material to an external API and stores outputs on disk. That mismatch can encourage more intimate or sensitive output than users would expect, increasing the chance of over-disclosure and privacy harm.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prompt explicitly asks the model to reproduce notable interactions, memorable quotes, emotional reflections, and relationship dynamics from session logs. In the context of a diary skill that forwards workspace memory to an external service and writes derived summaries back into persistent files, this materially increases exposure of private user communications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.