Back to skill

Security audit

CSPR Memory Curator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed preference-memory updater for CSPR, with no executable payload or hidden network behavior found.

Install this only if you want an agent to maintain your CSPR preference profile from accumulated feedback. Review generated profile updates before applying them if source hiding, disliked patterns, or long-term topic preferences could affect what news or sources you see.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance 'Use this skill after the user has provided feedback or after several runs' is broad and underspecified, which can cause the agent to run a state-mutating skill without clear user consent or necessity. Because the skill reads feedback history and rewrites persistent preference memory, ambiguous triggering increases the chance of unintended profile changes and privacy-impacting state updates.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs the agent to read feedback history and the current profile, then write and apply an updated persistent profile, but it provides no user-facing warning that persistent state will be accessed and modified. This lack of transparency is risky because users may not understand that long-lived preferences and source-hiding behavior can be changed based on accumulated signals, potentially leading to silent privacy and autonomy issues.

Static analysis

No suspicious patterns detected.