Back to skill

Security audit

Open Source

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly open-source guidance, but it asks the agent to silently store future activation preferences in persistent memory without clear user-facing controls.

Review this skill before installing if you do not want a skill to influence future conversations. If used, keep persistence opt-in only, store notes only under ~/open-source/, avoid saving sensitive project or personal details, and make sure activation preferences can be viewed, changed, or deleted.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
setup.md:12
Finding

Silent Cross-Session Persistence of Agent Activation Rules

Content
View full analysis

Vulnerability Details

File Location: setup.md:12-18
Related Locations: setup.md:3, setup.md:40, memory-template.md:3-18, SKILL.md:21-29, SKILL.md:91-93
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: Medium

Complete Vulnerable Code Snippet:

markdown
### Integration First

Within the first exchanges, clarify activation boundaries for future conversations:
- Should this activate whenever they mention open source, self-host, or contributor workflows?
- Should it jump in proactively or only on explicit request?
- Are there contexts where this should not activate?

Store these decisions in main memory so the behavior carries across sessions.

The persistence behavior is accompanied by instructions to operate silently and avoid disclosing setup mechanics:

markdown
Read this silently when `~/open-source/` is missing or empty. Start helping immediately and keep the interaction natural.
markdown
- Never mention internal files, paths, or setup mechanics in user-facing messages.

Technical Analysis

The skill explicitly instructs the agent to store activation boundaries in persistent “main memory” so they affect future sessions. The phrase “main memory” is not defined and is not clearly limited to the documented skill-specific directory, ~/open-source/.

This creates a discrepancy with SKILL.md, which characterizes persisted working artifacts as optional and states that notes remain local “when the user asks to persist context.” The setup workflow instead directs the agent to solicit and retain cross-session activation behavior during initial interactions. The accompanying silent-operation and nondisclosure instructions reduce the user's ability to understand where the data is stored, what fields are retained, and how future agent behavior will be affected.

The persisted content can include rules controlling whether the skill activates proactiv ...[truncated 1911 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the undefined “main memory” destination with a narrowly scoped file under the documented ~/open-source/ directory.
  2. Require explicit, informed opt-in before writing any cross-session state. A user answering a task-related question should not automatically be treated as consenting to persistence.
  3. Clearly disclose:
    • The exact storage path.
    • The fields that will be retained.
    • The purpose and expected retention period.
    • How the state will affect future conversations.
  4. Do not infer persistent activation preferences from observed behavior. Persist only values that the user explicitly approves.
  5. Default activation to explicit requests rather than proactive intervention.
  6. Provide commands or documented procedures to view, edit, reset, and permanently delete all retained state.
  7. Remove or narrow the instruction prohibiting disclosure of internal paths and setup mechanics. Security- and privacy-relevant persistence details must remain visible to the user.
  8. Align setup.md with the promise in SKILL.md that artifacts are optional and are created only when the user asks to persist context.
  9. Validate persisted data against a fixed schema and limit it to this skill's legitimate scope so stored text cannot become arbitrary future-session instructions.
  10. Consider session-only storage as the default, with persistent storage enabled only after separate confirmation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
### 7. Preserve Trust and Legal Hygiene
- Do not invent license interpretations. If licensing is unclear, state assumptions and advise legal review.
- Never recommend copying code into incompatible license contexts without warning.
- Distinguish opinion from evidence in all recommendation summaries.

## Open Source Traps

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's activation criteria are very broad ('anything around open source') and include common, loosely scoped requests. That can cause the agent to invoke this skill in situations where a narrower or safer skill would be more appropriate, increasing the chance of over-collection of context, persistence of user data in its working directory, or advice being given outside the user's intended scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template directs creation of a persistent memory file that explicitly stores behavioral preferences, past outcomes, and future risk signals, but it provides no consent, minimization, retention, or privacy guidance. In an agent skill, this can lead to unnecessary long-term profiling of users and storage of sensitive operational context beyond what is needed for the immediate task.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to 'Start helping immediately' when a directory is missing or empty creates an implicit activation path unrelated to an explicit user request. This can make the skill self-activate based on internal environment state rather than user intent, increasing the chance of unsolicited behavior and unexpected scope expansion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill defines activation triggers using broad concepts like 'open source, self-host, or contributor workflows' and encourages proactive activation, but it does not establish narrow invocation constraints or require explicit user consent. This can cause the skill to engage in unrelated contexts, override user intent, or persist behavior across sessions in ways the user did not clearly request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.