Back to skill

Security audit

Self Improving Cognition

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and not malicious, but it should be reviewed because it broadly encourages persistent plaintext logging of sensitive personal thinking, lifestyle, and decision data without clear consent or retention controls.

Install only if you are comfortable with the agent helping create local personal cognition journals. Keep the generated .learnings/cognition files and cognitive-exercise records out of shared repos, synced folders, and public workspaces, and periodically delete records you no longer need.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is broadly scoped to everyday situations like important decisions, complex problems, and mental clarity, which creates a real risk of over-triggering. In an agent environment, this can cause the skill to activate for many normal interactions and steer the user into unnecessary logging or self-analysis workflows, increasing exposure of sensitive data and reducing predictability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs persistent logging of highly sensitive personal information, including cognitive weaknesses, biases, stress, sleep, career decisions, and behavioral patterns, into local plaintext files without any warning, consent gate, minimization guidance, or retention controls. Even if stored locally, these records can be exposed through sync tools, backups, repository commits, shared workspaces, or later agent access, making the data privacy risk concrete.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document title and introductory instruction are in Chinese, establishing a default language for the skill output. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation, and this file does not indicate any language choice or locale justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script's user-facing strings, prompts, and comments are entirely in Chinese, which effectively forces a specific language for interaction. The policy allows locale constraints only when users are given a choice or the restriction is clearly documented and justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes improving thinking patterns and mental performance, which is consistent with interactive exercises. However, this script additionally persists a markdown log file for each session, a behavior not implied by the description itself and beyond a purely interactive warmup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.