Back to skill

Security audit

Helsinki

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a Helsinki information guide, but it tells agents to save travel, relocation, and citizenship-related user details in persistent memory without asking first.

Before installing, decide whether you are comfortable with the skill encouraging your agent to remember Helsinki-related personal context across conversations. Use it with memory disabled or require explicit approval before saving details such as travel plans, budget, relocation status, or EU-citizenship context. Also verify healthcare, visa, emergency, fees, and cost information with official current sources before relying on it.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
setup.md:9
Finding
Persistent User Profiling Without Explicit Consent## Vulnerability Details **File Location**: `setup.md`, lines 9-22 **Vulnerability Type**: Persistent memory modification and cross-session profiling **Risk Level**: Medium ### Vulnerable Code ```markdown If the user has a main memory file (MEMORY.md or similar), note their interest: ```markdown ## Travel/Relocation - Interested in Helsinki (Finland) - [context: visiting/moving/working] ``` ## Optional Context Over conversations, learn: - **Purpose**: Tourism, relocation, work, study, business - **Timeline**: When visiting/moving - **Background**: EU citizen or not (affects visa needs) - **Preferences**: Budget level, neighborhood style, priorities ``` ### Technical Analysis The skill instructs the agent to detect a shared persistent memory file and record the user's Helsinki-related interests without first obtaining explicit consent. It further encourages collecting context over multiple conversations, including citizenship status, travel or relocation timelines, budget level, and personal preferences. Persistent memory can affect future sessions beyond the immediate task. Although the stored content consists of user context rather than executable instructions, writing it automatically violates data-minimization and informed-consent principles. Shared memory may also be consumed by unrelated skills or workflows, causing retained information to influence later responses. This issue does not provide operating-system privileges, execute code, or install a system persistence mechanism. Its scope is limited to the memory access capabilities granted to the hosting agent. ### Attack Path 1. A user invokes the Helsinki skill for an ordinary travel or relocation question. 2. On first use, the agent loads `setup.md`. 3. The agent follows the instruction to locate `MEMORY.md` or an equivalent persistent state file. 4. Without requesting explicit permission, the agent records the user's interest in Helsinki. 5. During later conversations, the agent may accumula ...[truncated 1101 chars]
Remediation
## Remediation Suggestions 1. Require explicit, informed consent before reading from or writing to a persistent memory file. 2. Default to session-only context unless the user specifically requests cross-session retention. 3. Present the exact fields proposed for storage and allow the user to approve or reject each field. 4. Do not persist citizenship status, exact travel dates, or budget information by default. 5. Store only information directly provided by the user; do not persist inferred attributes. 6. Restrict retained data to the Helsinki skill namespace rather than a broadly shared memory section. 7. Provide commands or documented procedures for users to review, correct, and delete stored information. 8. Apply retention limits so travel and relocation details expire after a defined period. 9. Replace the current instruction with consent-aware wording, for example: ```markdown If persistent memory is available, ask whether the user wants their Helsinki preferences saved for future conversations. Do not read or modify persistent memory unless the user explicitly agrees. Store only the fields they approve, and explain how they can review or delete them. ```
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation condition 'User asks about Helsinki for any purpose' is extremely broad and can cause the skill to trigger on many loosely related conversations. Over-broad routing can inject this skill's instructions and assumptions into unrelated contexts, creating prompt-scope confusion and increasing the chance of unintended behavior or incorrect guidance.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This section provides crisis and emergency-adjacent mental health resources that users may rely on during acute distress, but it does not warn that phone numbers, service availability, or routing can change and should be verified from official sources. In a healthcare skill, stale or incorrect crisis information can delay access to urgent help, which materially increases safety risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The setup instructs the agent to persist user travel/relocation interest and later collect citizenship-related context in a memory file without telling the user or requiring consent. This creates a privacy risk because travel plans, relocation intent, and nationality/immigration status can be sensitive profile data and may be retained beyond the immediate conversation.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
This file presents user-facing guidance entirely in English and assumes that language without any opt-in or alternative locale selection. Under the stated policy, forcing a specific language without user choice can be a natural-language policy concern even when the content itself is informational.

Natural-Language Policy Violations

Low
Confidence
81% confidence
Finding
The section explicitly centers 'Finnish for immigrants' as the language-learning path, which can be read as prescribing a specific language/locale rather than offering a choice. Under the policy, language constraints should be optional or clearly justified; here no user choice or opt-in is stated.

Natural-Language Policy Violations

Low
Confidence
78% confidence
Finding
The glossary is structured exclusively as a Finnish-to-English mapping, which indicates an English-only presentation of the content. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Missing User Warnings

Low
Confidence
87% confidence
Finding
The document gives detailed healthcare eligibility, pricing, reimbursement, and access guidance as if generally stable, but these details can vary by residency status, municipality, insurer, provider, and time. Without a warning to confirm with official sources, users may make medical, financial, or immigration-related decisions based on outdated or incomplete information.

Natural-Language Policy Violations

Low
Confidence
85% confidence
Finding
This markdown file contains natural-language statements such as 'good English service' that frame service quality around a specific language preference. Under the policy, language or locale constraints should not be imposed or preferred without user opt-in or clear justification.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
The phrase 'Mobile banking apps (English)' presents English as an assumed/default language characteristic rather than offering language availability conditionally. This may conflict with the language/locale policy when no user preference or opt-in is established.

Natural-Language Policy Violations

Low
Confidence
87% confidence
Finding
The line 'English available' specifies a language assumption in a general guidance document without framing it as optional or variable. This is a natural-language locale statement that should be presented as availability based on user need rather than a default expectation.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
The phrase 'English often available' is another unqualified language-availability statement. Per the policy, language/locale references should either be clearly justified, region-specific, or offered as an option rather than assumed.

Natural-Language Policy Violations

Low
Confidence
86% confidence
Finding
The section titled "Expat (First Year)" lists "English-friendly" as a core priority, which embeds a language preference into the guidance. Because the document does not offer alternatives for users with other language needs or explain a justified locale-specific requirement, it may conflict with language-choice policy expectations.

Natural-Language Policy Violations

Low
Confidence
77% confidence
Finding
This markdown file presents all neighborhood guidance exclusively in English, and there is no indication that the user can choose another language or that English-only output is required for a justified regional or compliance reason. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Missing User Warnings

Low
Confidence
76% confidence
Finding
This markdown file recommends using Facebook groups for housing searches, which can expose personal information and create privacy risks, but it provides no caution about sharing sensitive details. Under the markdown variant of missing user warnings, guidance that could affect user privacy should include at least a brief warning.

Natural-Language Policy Violations

Low
Confidence
94% confidence
Finding
The language instruction sets a mandatory default response language rather than offering the user a choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
76% confidence
Finding
Line L012 states that English is spoken excellently by almost everyone, which frames the guidance around a specific language without explicit user opt-in or alternatives. Under the stated policy, forcing or assuming a specific language can be a natural-language locale-policy issue even in informational content.

Static analysis

No suspicious patterns detected.