Back to skill

Security audit

Morty's Mind Blowers

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly designed to search prior memories and session logs, but it gives the agent broad access to potentially private history without clear confirmation or source limits.

Review before installing. Use it only if you are comfortable with an agent searching prior memory files or session logs for entertaining recaps. Prefer adding explicit confirmation and source limits before allowing it to inspect transcripts, long-term memory, or broad local history.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:28
Finding

Unscoped Access to Private Memory Files and Session Transcripts

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to activate on ordinary requests like 'random memory' or 'tell me a weird thing from memory,' which can cause the skill to run in contexts where the user did not clearly consent to rummaging through archived memories or logs. In this skill, that ambiguity is more dangerous because activation leads directly to reviewing memory stores and surfacing potentially sensitive historical content.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill's core description is to dig through memory logs and retell surprising archived notes, which is functionally a mechanism for extracting and repackaging stored user history. In context, the playful narrative framing makes this more dangerous, not less, because it encourages broad retrieval and dramatic retelling of sensitive content that users may not expect to be resurfaced.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The usage guidance says to use the skill whenever the user wants a random or deep-cut memory or a weird recap instead of a plain summary, but those conditions are subjective and open-ended. Because the skill then searches memory files and session logs, vague routing criteria increase the chance of unintended disclosure from overbroad skill activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill tells the agent to surface memorable or revealing content from memory sources but does not require warning the user that daily memory files, long-term memory, or session transcripts may be scanned. That missing notice undermines informed consent and can expose users to unexpected retrieval of sensitive prior interactions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly prefers daily memory files and session transcripts/logs, then instructs the agent to surface unusual or revealing entries as entertainment-style output. This creates a direct privacy risk: historical logs often contain sensitive data, and retelling 'surprising' or 'revealing' content incentivizes disclosure of exactly the material that should be handled conservatively.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.