T09 · Insecure Skill Coding Practices
- Location
scripts/sync-memory.sh:60- Finding
Sensitive memory sections, including API keys, are synchronized without filtering
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its memory-sync purpose, but it can copy private memories, daily logs, and an explicit API-keys section into CortexGraph without adequate scoping, filtering, or warnings.
Review and sanitize MEMORY.md and daily logs before using this skill. Do not sync secrets, API keys, credentials, regulated data, or client-private notes; prefer dry-run first, pin and verify cortexgraph/mcporter versions, and back up CortexGraph and MEMORY.md before running gc, consolidation, or promotion commands.
scripts/sync-memory.sh:60Sensitive memory sections, including API keys, are synchronized without filtering
scripts/sync-daily.sh:7Unvalidated date argument permits path traversal outside the daily-memory directory
SKILL.md:8Unpinned third-party executables are installed and trusted with private memory
The Chinese description explicitly advertises forgetting-curve support and intelligent retrieval, yet the visible content only documents saving/importing and external CortexGraph calls, not actual in-skill recall or decay logic. In a memory-management context, this can cause unsafe assumptions about retention, deletion timing, and what conversational data is being processed or surfaced.
The Chinese description explicitly advertises forgetting-curve support and intelligent retrieval, yet the visible content only documents saving/importing and external CortexGraph calls, not actual in-skill recall or decay logic. In a memory-management context, this can cause unsafe assumptions about retention, deletion timing, and what conversational data is being processed or surfaced.
The Chinese description explicitly advertises forgetting-curve support and intelligent retrieval, yet the visible content only documents saving/importing and external CortexGraph calls, not actual in-skill recall or decay logic. In a memory-management context, this can cause unsafe assumptions about retention, deletion timing, and what conversational data is being processed or surfaced.
The README advertises automatic bidirectional synchronization between MEMORY.md, CortexGraph, and daily logs, but does not warn users that potentially sensitive memory data may be imported, modified, persisted, or propagated across stores. In an agent skill context, unclear data-flow and write behavior can cause accidental disclosure or unintended modification of personal/project memory, especially when users run shell scripts directly from the documentation.
Suspicious Unicode normalization or mixed-script content
The skill documents automatic analysis, memory capture, and recall of user conversation content without any privacy warning, consent guidance, retention notice, or data-sensitivity limits. Because the content being processed is conversational memory, the context makes this more dangerous: users may inadvertently store sensitive personal, corporate, or credential-like information in a long-lived local memory system.
The documentation includes garbage-collection and consolidation commands that can delete or alter stored memories, but it does not clearly warn about irreversible effects, backups, or safe preview-first usage. In a memory store, destructive maintenance can cause permanent data loss or silent corruption of important user information if run casually.
The script automatically reads the entire daily log file and sends it to cortexgraph.save_memory, which is an external persistence boundary, without any explicit consent prompt, warning, redaction step, or data classification check. Because daily logs commonly contain sensitive personal notes, credentials, project details, or client data, this creates a real risk of unintended disclosure through normal use rather than an exploit in the classic sense.
The natural-language instructions in this file are exclusively in Chinese, and the document does not provide an alternative language or indicate that Chinese is an intentional, justified locale constraint. This can violate language/locale policy when users are not given an explicit language choice.
The skill’s natural-language description and operational guidance are entirely in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a skill effectively forces one language without opt-in or justification.
This manifest includes a Chinese-only natural-language description, which can indicate a fixed language/locale assumption without offering user opt-in or documenting why the locale is required. Under the policy rule for language/locale constraints, this is a natural-language policy concern because no alternative language choice or region-specific justification is provided in the file.
The script’s comments, prompts, and user-facing output are written entirely in Chinese, which imposes a specific language on users without opt-in. This matches the language/locale policy concern because no alternative language option or justification for a Chinese-only workflow is provided.
The inline comment on L12 says the script retrieves 'high-score memories' with 'score > 1.5', but the actual mcporter call sets min_score=0.5 on L17. This is an active contradiction between documentation and implemented behavior, which changes the effective scope of what gets considered for promotion.
The script's descriptive comments and runtime messages are written in Chinese, which imposes a specific language on users without any opt-in or explanation of a region-specific requirement. This can violate language/locale policy when the skill does not provide a choice or document why the locale is fixed.
No suspicious patterns detected.