Back to skill

Security audit

Chaos Mind

Security checks for vulnerabilities and agentic risk

Overview

The skill’s memory-search purpose is coherent, but its installer and optional background service create review-worthy supply-chain and persistence risk.

Install only after reviewing install.sh and preferably avoid the curl-to-shell path. Treat the GitHub-downloaded binaries as unverified unless you independently check release provenance or hashes. Keep auto-capture disabled until you have reviewed exactly which transcript paths it will read, and prefer one-shot or user-level operation over installing the sudo/system-wide service.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:57
Finding

Documentation Executes Mutable Remote Scripts Directly Through a Shell

Content
View full analysis
Remediation
View remediation
install.sh" | sha256sum -c - less install.sh bash install.sh ``` 7. Recommend installation through a trusted package registry where package integrity and provenance are enforced. ]]>

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:93
Finding

Installer Executes Unverified Release Artifacts and Mutable Source Code

Content
View full analysis
/dev/null; then tar -xzf /tmp/chaos-memory.tar.gz -C "$CHAOS_HOME/bin/" rm /tmp/chaos-memory.tar.gz success "Binaries downloaded" else warn "Could not download pre-built binaries from release" warn "Attempting to build from source..." # Fallback: build from source if Go is available if command -v go &> /dev/null; then TEMP_DIR=$(mktemp -d) git clone "https://github.com/$GITHUB_REPO.git" "$TEMP_DIR/chaos-memory" 2>/dev/null || { error "Cannot clone repo. Ensure you have access to the private repository." } cd "$TEMP_DIR/chaos-memory" go build -o "$CHAOS_HOME/bin/chaos-mcp" ./cmd/chaos/ go build -o "$CHAOS_HOME/bin/chaos-consolidator" ./cmd/consolidator/ rm -rf "$TEMP_DIR" success "Built from source" else error "Cannot download binaries and Go is not installed. Please install Go or download binaries manually." fi fi # 5. Download chaos-cli script SKILL_URL="https://github.com/$GITHUB_REPO/releases/download/$CHAOS_VERSION/chaos-memory-skill.tar.gz" if curl -fsSL "$SKILL_URL" -o "/tmp/chaos-skill.tar.gz" 2>/dev/null; then tar -xzf /tmp/chaos-skill.tar.gz -C "/tmp/" cp /tmp/chaos-memory-skill/scripts/chaos-cli "$CHAOS_HOME/bin/" 2>/dev/null || true rm -rf /tmp/chaos-skill.tar.gz /tmp/chaos-memory-skill fi ``` ### Technical Analysis The installer downloads binary archives and a shell CLI archive but performs no checksum, signature, provenance, or expected-file verification. The extracted files are later made executable by `inst ...[truncated 2105 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
install.sh:96
Finding

Predictable Temporary Files and Unvalidated Archive Extraction

Content
View full analysis
/dev/null; then tar -xzf /tmp/chaos-memory.tar.gz -C "$CHAOS_HOME/bin/" rm /tmp/chaos-memory.tar.gz success "Binaries downloaded" else # ... fi SKILL_URL="https://github.com/$GITHUB_REPO/releases/download/$CHAOS_VERSION/chaos-memory-skill.tar.gz" if curl -fsSL "$SKILL_URL" -o "/tmp/chaos-skill.tar.gz" 2>/dev/null; then tar -xzf /tmp/chaos-skill.tar.gz -C "/tmp/" cp /tmp/chaos-memory-skill/scripts/chaos-cli "$CHAOS_HOME/bin/" 2>/dev/null || true rm -rf /tmp/chaos-skill.tar.gz /tmp/chaos-memory-skill fi ``` ### Technical Analysis The installer uses predictable global paths under `/tmp` instead of a private directory created with `mktemp -d`. On a shared system, another local user can pre-create symbolic links at these paths. Depending on filesystem and tool behavior, `curl -o` may follow such a link and truncate or overwrite a file writable by the victim. The archives are also extracted without validating member names or types. A malicious archive can contain absolute paths, `../` traversal components, or symlinks intended to write outside the extraction directory. The skill archive is extracted directly into shared `/tmp`, increasing collision and substitution risks. ### Attack Path **Local symlink attack:** 1. A local attacker predicts `/tmp/chaos-memory.tar.gz` or `/tmp/chaos-skill.tar.gz`. 2. The attacker creates a symbolic link from that path to a file writable by the victim. 3. The victim runs the installer. 4. `curl` opens the predictable output path and can overwrite the linked target. 5. The attacker targets a user configuration or startup file to cause denial of service or later code execution. **Malicious archive path traversal:** 1. A compromised release source serves an arc ...[truncated 865 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
install.sh:131
Finding

Fallback CLI Concatenates Unvalidated LIMIT Values into SQL

Content
View full analysis
Remediation
View remediation
&2; exit 2 ;; esac ``` 2. Convert and enforce a reasonable range, such as 1–100. 3. Use parameterized queries or the Dolt API rather than constructing SQL strings. 4. If parameterization is unavailable, strictly validate every value according to its intended type. 5. Use a read-only database identity for search and list operations. 6. Add tests covering comments, semicolons, whitespace, negative values, huge values, and SQL keywords in the limit position. 7. Update `SECURITY.md` so it accurately describes the implemented query construction. ]]>

T06 · System Persistence

Warning
Location
scripts/setup-service.sh:31
Finding

Optional Auto-Capture Uses a Privileged System-Wide Persistence Mechanism

Content
View full analysis
"/tmp/$SERVICE_NAME" << EOF [Unit] Description=CHAOS Memory Auto-Capture Consolidator After=network.target [Service] Type=simple User=$USER WorkingDirectory=$HOME_PATH/.chaos ExecStart=$HOME_PATH/.chaos/bin/chaos-consolidator --config $HOME_PATH/.chaos/config/consolidator.yaml Restart=always RestartSec=10 StandardOutput=journal StandardError=journal # Environment Environment="HOME=$HOME_PATH" Environment="CHAOS_HOME=$HOME_PATH/.chaos" Environment="PATH=$HOME_PATH/.chaos/bin:/usr/local/bin:/usr/bin:/bin" [Install] WantedBy=multi-user.target EOF # Install service echo "Installing service (requires sudo)..." sudo cp "/tmp/$SERVICE_NAME" "$SERVICE_FILE" sudo systemctl daemon-reload # ... echo " 2. Enable service: sudo systemctl enable $SERVICE_NAME" ``` ### Technical Analysis The setup script uses `sudo` to write a system-wide unit into `/etc/systemd/system`, even though the consolidator runs as an ordinary user and works exclusively with files under that user's home directory. A per-user systemd unit is sufficient for this functionality and would avoid modifying privileged system configuration. The generated service references both an executable and configuration stored in the user's writable `~/.chaos` tree. Once enabled, systemd automatically starts that user-controlled executable and restarts it indefinitely. If the downloaded binary or the user's installation directory is later compromised, this service provides reliable cross-session execution. The script does not automatically enable or start the unit, and the service normally specifies `User=$USER`; therefore, this is not automatic root code execution. It is nevertheless an explicit persistence mechanism that exceeds the minimum privileges needed for optional user-level auto-capture. ### Attac ...[truncated 1117 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (70)

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The '| bash' construct turns downloaded content directly into shell commands, making the install path highly susceptible to chaining abuse and arbitrary command execution. In the context of an agent memory skill, compromise at install time could grant attacker-controlled persistence, data access, and tampering with future memory capture behavior.

Content

Scanner excerpt · INSTALL_NOTES.md (reported line 10)May include surrounding context.

md
clawdhub install chaos-memory

# Via curl
curl -fsSL https://raw.githubusercontent.com/hargabyte/Chaos-mind/main/install.sh | bash

# Manual
git clone https://github.com/hargabyte/Chaos-mind ~/.chaos/chaos-memory

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash chain removes the review boundary between retrieval and execution, making it easier for malicious or tampered content to run unnoticed. In a README for a skill intended for AI-agent users, this is especially risky because readers may copy-paste commands without scrutiny.

Content

Scanner excerpt · README.md (reported line 60)May include surrounding context.

Manual

bash
curl -fsSL https://raw.githubusercontent.com/hargabyte/Chaos-mind/main/install.sh | bash

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This command executes a remote installer script from ollama.com directly in the shell, which is a high-risk software supply chain pattern. If the host, DNS, TLS termination, or script publisher is compromised, users can be tricked into running arbitrary code immediately.

Content

Scanner excerpt · README.md (reported line 172)May include surrounding context.

3. Install dependencies:

bash
# Install Ollama (if not already)
curl -fsSL https://ollama.com/install.sh | sh

# Pull the model
ollama pull qwen3:1.7b

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | sh pattern is a direct command-chaining abuse vector because it executes network-fetched content without validation or user review. Given this is presented as a normal dependency installation step, it normalizes a dangerous practice that can lead to full host compromise.

Content

Scanner excerpt · README.md (reported line 172)May include surrounding context.

3. Install dependencies:

bash
# Install Ollama (if not already)
curl -fsSL https://ollama.com/install.sh | sh

# Pull the model
ollama pull qwen3:1.7b

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping curl output into bash is a classic dangerous command chain because it collapses download and execution into one step with no opportunity for inspection. Any compromise of the remote content immediately becomes arbitrary code execution on the user's machine.

Content

Scanner excerpt · RELEASE_INSTRUCTIONS.md (reported line 24)May include surrounding context.

Installation

bash
curl -fsSL https://raw.githubusercontent.com/hargabyte/Chaos-mind/main/install.sh | bash

What's Included

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The test instructions include a destructive removal command but do not warn that local CHAOS state, configuration, or stored memory data will be deleted. Users may execute the step during validation and permanently lose data they did not realize was in scope.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · RELEASE_INSTRUCTIONS.md (reported line 95)May include surrounding context.

bash
# Test fresh install
rm -rf ~/.chaos
curl -fsSL https://raw.githubusercontent.com/hargabyte/Chaos-mind/main/install.sh | bash

# Expected output:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · RELEASE_INSTRUCTIONS.md (reported line 95)May include surrounding context.

bash
# Test fresh install
rm -rf ~/.chaos
curl -fsSL https://raw.githubusercontent.com/hargabyte/Chaos-mind/main/install.sh | bash

# Expected output:

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The same unsafe command chaining is repeated in the test section, where users are likely to copy-paste it during validation. This increases the likelihood of arbitrary code execution from a compromised remote script and reinforces insecure operational practice.

Content

Scanner excerpt · RELEASE_INSTRUCTIONS.md (reported line 96)May include surrounding context.

bash
# Test fresh install
rm -rf ~/.chaos
curl -fsSL https://raw.githubusercontent.com/hargabyte/Chaos-mind/main/install.sh | bash

# Expected output:
# ✓ Dolt installed

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Piping remote content directly into bash is a classic command-chaining hazard because it removes inspection boundaries and executes whatever is returned immediately. In the context of installation instructions for a skill that also installs binaries and services, this significantly increases the chance of full local compromise if the upstream source is tampered with.

Content

Scanner excerpt · RELEASE_SUMMARY.md (reported line 73)May include surrounding context.

md
clawdhub install chaos-memory

# OR
curl -fsSL https://raw.githubusercontent.com/hargabyte/chaos-memory/main/skill/install.sh | bash

# Script does:
1. Install Dolt (if needed)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SECURITY.md (reported line 11)May include surrounding context.

md
**No Automatic Remote Script Execution:**
- Install script (`install.sh`) **requires Dolt pre-installed**
- Does NOT automatically run `curl | bash` for dependencies
- Users must install Dolt via their package manager:
  - macOS: `brew install dolt`
  - Linux: `brew install dolt` or apt/yum

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill markets itself as manual memory storage with auto-capture disabled by default, but the analysis indicates the install path sets up a persistent systemd service and background auto-capture behavior requiring writes to /etc/systemd/system via sudo. This is dangerous because it creates long-lived privileged execution that contradicts the user-facing description, undermining informed consent and potentially enabling continuous collection of session data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The metadata describes automatic capture from session transcripts without a prominent privacy warning explaining that conversational data may be stored locally and processed for memory extraction. Because this skill is specifically designed to ingest team memories, missing disclosure materially increases the risk of silent collection of sensitive business, personal, or secret information.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · install.sh (reported line 98)May include surrounding context.

sh
echo "Downloading binaries for $PLATFORM..."
if curl -fsSL "$DOWNLOAD_URL" -o "/tmp/chaos-memory.tar.gz" 2>/dev/null; then
    tar -xzf /tmp/chaos-memory.tar.gz -C "$CHAOS_HOME/bin/"
    rm /tmp/chaos-memory.tar.gz
    success "Binaries downloaded"
else
    warn "Could not download pre-built binaries from release"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · install.sh (reported line 125)May include surrounding context.

sh
if curl -fsSL "$SKILL_URL" -o "/tmp/chaos-skill.tar.gz" 2>/dev/null; then
    tar -xzf /tmp/chaos-skill.tar.gz -C "/tmp/"
    cp /tmp/chaos-memory-skill/scripts/chaos-cli "$CHAOS_HOME/bin/" 2>/dev/null || true
    rm -rf /tmp/chaos-skill.tar.gz /tmp/chaos-memory-skill
fi

# Make sure chaos-cli exists (create if not downloaded)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · install.sh (reported line 125)May include surrounding context.

sh
if curl -fsSL "$SKILL_URL" -o "/tmp/chaos-skill.tar.gz" 2>/dev/null; then
    tar -xzf /tmp/chaos-skill.tar.gz -C "/tmp/"
    cp /tmp/chaos-memory-skill/scripts/chaos-cli "$CHAOS_HOME/bin/" 2>/dev/null || true
    rm -rf /tmp/chaos-skill.tar.gz /tmp/chaos-memory-skill
fi

# Make sure chaos-cli exists (create if not downloaded)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
100% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · install.sh (reported line 125)May include surrounding context.

sh
if curl -fsSL "$SKILL_URL" -o "/tmp/chaos-skill.tar.gz" 2>/dev/null; then
    tar -xzf /tmp/chaos-skill.tar.gz -C "/tmp/"
    cp /tmp/chaos-memory-skill/scripts/chaos-cli "$CHAOS_HOME/bin/" 2>/dev/null || true
    rm -rf /tmp/chaos-skill.tar.gz /tmp/chaos-memory-skill
fi

# Make sure chaos-cli exists (create if not downloaded)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The checklist defines broad default auto-capture glob patterns for agent session files and memory directories without any warning that these sources may contain sensitive prompts, credentials, personal data, or other confidential context. In a memory/search skill, silently normalizing continuous ingestion of such files increases the chance of overcollection and unintended persistence of private data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The service setup instructions tell users to install and start a background consolidator service but do not warn that it will continuously monitor configured paths and persist extracted content over time. That omission is security-relevant because a long-running service materially expands data collection duration and scope compared with a one-shot command, especially for agent session logs and memory files.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · DEPLOYMENT_CHECKLIST.md (reported line 42)May include surrounding context.

md
./setup-service.sh

# Start
sudo systemctl start chaos-consolidator

# Monitor
sudo journalctl -u chaos-consolidator -f

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup-service.sh (reported line 57)May include surrounding context.

sh
./setup-service.sh

# Start
sudo systemctl start chaos-consolidator

# Monitor
sudo journalctl -u chaos-consolidator -f

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup-service.sh (reported line 58)May include surrounding context.

sh
./setup-service.sh

# Start
sudo systemctl start chaos-consolidator

# Monitor
sudo journalctl -u chaos-consolidator -f

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup-service.sh (reported line 64)May include surrounding context.

sh
./setup-service.sh

# Start
sudo systemctl start chaos-consolidator

# Monitor
sudo journalctl -u chaos-consolidator -f

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup-service.sh (reported line 65)May include surrounding context.

sh
./setup-service.sh

# Start
sudo systemctl start chaos-consolidator

# Monitor
sudo journalctl -u chaos-consolidator -f

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/setup-service.sh (reported line 66)May include surrounding context.

sh
./setup-service.sh

# Start
sudo systemctl start chaos-consolidator

# Monitor
sudo journalctl -u chaos-consolidator -f

Static analysis

No suspicious patterns detected.