Back to skill

Security audit

Memory Manager Pro (记忆索引管理)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent task-memory manager, but it allows broad automatic workspace updates from generic triggers and other skills without enough scoping or confirmation.

Install only if you are comfortable with the agent creating and updating persistent memory/project files. Use it in a dedicated workspace, review proposed file paths before writes, and avoid allowing other skills to call its update interface unless you trust them and can verify the resolved paths stay inside the intended memory/projects folders.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:327
Finding

Path Traversal Through Unvalidated Task IDs and Project Names

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 327-370
Vulnerability Type: Unvalidated path construction and path traversal
Risk Level: Medium

Vulnerable Code

The following is an English rendering of the relevant path-derivation and file-update instructions:

text
Project name -> Automatically locate project directory through keyword mapping
  1. Search the "Project Keywords" table in memory/quick-search/keyword-mapping.md
  2. If present: use the mapped path directly
  3. If absent: generate it using the default path rules
    novel/project-name/ -> novel project
    code/project-name/ -> code project
    design/project-name/ -> design project
    research/project-name/ -> research project

Derived file paths:
  Project index: memory/project-index/{project-type}-project-index.md
  Type index:    memory/type-index/{task-type}.md
  Task details:  memory/task-flow/task-details/{task-ID}.md
  Content dir:   {project-directory}/content/
  Plan dir:      {project-directory}/plans/
  Title library: {project-directory}/plans/used-title-library.md

Step 2: Update task details
  Construct path: memory/task-flow/task-details/{task-ID}.md
  Check whether the file exists
  Exists -> mark completed and append an execution record
  Missing -> create a new file containing basic information and an execution record

The original instructions directly interpolate externally supplied values into paths, including:

text
memory/任务流/任务详情/{任务ID}.md
{项目目录}正文/
{项目目录}规划/

Technical Analysis

The documented external interface accepts a task ID and project name, then derives writable file paths from those values. The Skill does not require:

  • Strict validation of the task-ID format.
  • Rejection of .., /, \, absolute paths, control characters, or encoded separators.
  • Canonicalization of keyword-map destinations.
  • Verification that the resolved path remains in ...[truncated 1921 chars]
Remediation
View remediation

Remediation Suggestions

  1. Enforce a strict task-ID allowlist before constructing any path:

    regex
    ^TASK_(NOVEL|CODE|DESIGN|RESEARCH|SYSTEM)_[0-9]{8}_[0-9]{3}$
    
  2. Reject project names and identifiers containing:

    • ..
    • / or \
    • Absolute-path prefixes
    • Null bytes or control characters
    • Encoded path separators
    • Platform-specific reserved path components
  3. Resolve every generated path to its canonical absolute form and verify that it is contained under an explicitly approved root, such as the canonical task-details or projects directory.

  4. Apply the same validation and containment checks to paths loaded from the keyword-mapping file. Mapping entries must be treated as untrusted data rather than trusted configuration.

  5. Reject symbolic links or verify the final resolved target immediately before each write to prevent redirection outside the permitted root.

  6. Use fixed path-joining APIs rather than string concatenation, and fail closed when path validation is inconclusive.

  7. Require user confirmation before overwriting an existing file that is not the exact expected task record.

  8. Add negative tests covering traversal sequences, absolute paths, mixed separators, encoded traversal, malicious keyword mappings, and symbolic-link targets.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented external skill update interface allows cross-skill index update requests but does not describe trust boundaries, validation, or user approval for data flowing between skills. That makes it possible for another skill to cause unexpected memory/index modifications, propagate incorrect metadata, or expand the blast radius of a compromised or buggy integration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are generic enough to match ordinary planning or project-organization requests, which can cause the skill to activate in situations where the user did not explicitly intend memory-management behavior. In this skill, unintended activation is more dangerous because the documented behavior includes creating directories, files, indexes, and task records, so an accidental trigger can lead to unsolicited filesystem and state changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs the system to create directories, initialize files, and update task/index state without any warning, consent checkpoint, or indication that persistent workspace data will be modified. In the context of an agent skill, silent write operations can overwrite organization structures, create unwanted artifacts, or pollute user projects if the skill is triggered accidentally or on ambiguous input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases such as 'task planning' and 'memory management' that can naturally appear in ordinary conversations, increasing the chance of unintended skill activation. Because this skill performs filesystem-oriented project and memory operations, accidental invocation could lead to unexpected reads, file creation, or edits across the workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section instructs the agent to create directories and files and edit multiple memory indexes, but it does not require explicit user consent or warn that workspace state will be modified. In practice, a user asking for organization help could trigger non-obvious persistent changes, causing unwanted file creation, clutter, or overwriting of existing project structure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The external update interface describes automatic, semantic path derivation and a workflow that can update many files in sequence, including task indexes, project indexes, type indexes, and top-level memory files. This increases risk because a single request can fan out into broad workspace mutations without a user-facing approval gate, and the automatic path inference may touch unintended targets if mappings or project names are ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The README begins with Chinese-language product description and most operational examples are written in Chinese, while some trigger phrases are in English. This creates an implicit language preference without documenting a user-selectable language or locale option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file mixes English metadata with predominantly Chinese operational instructions and examples, effectively constraining normal use to Chinese for many users. There is no statement that the user may choose their preferred language or that Chinese is a justified locale requirement for a region-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file uses Chinese throughout for headings, instructions, and template fields, which effectively imposes a specific language on users. The file does not indicate that Chinese is optional, selectable, or required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file defines a retrieval example where the input phrase "查看当前任务" maps directly to a specific file. The phrase is broad and common in everyday task-management contexts, and the document does not provide constraints or negative examples clarifying when this mapping should or should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The example uses a natural, generic request that could match many ordinary browsing intents, but the file presents it as mapping to a specific internal index path. There are no stated scope limits, activation boundaries, or negative examples to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The naming rules state '使用英文或中文' and recommend a specific casing convention, which functions as a language/locale constraint in the documentation. The file does not indicate that users may choose another language or that the restriction is justified by a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file presents all headings, examples, and instructions exclusively in Chinese, with no note that the language is optional or intended for a Chinese-only audience. The policy requires flagging cases where a skill forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.