Back to skill

Security audit

Context Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed long-term context manager, but it depends on unaudited code loaded from a user-writable external directory and stores/searches persistent user content.

Review before installing. Use only if you trust the external context-manager directory and its Python files, install dependencies in an isolated environment with pinned versions, and avoid storing secrets or sensitive private files unless you accept that they may be indexed, cached, logged, and optionally sent to configured model services.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
skill.py:14
Finding

Untrusted Python Module Loading from a Mutable External Directory

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skill_demo.py:63
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions, examples, and warnings exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The test invokes the skill exclusively with Chinese-language prompts such as creating, listing, and searching agents/files. This reflects a language-specific usage assumption without any visible opt-in, fallback, or documented justification, which can violate language/locale policy requirements for user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill returns user-facing output in Chinese and relies on Chinese trigger phrases throughout the command handling logic. This creates a language policy concern because the file does not offer user opt-in, fallback language support, or any documented justification that the skill is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation logic depends on Chinese words like '创建', '删除', '搜索', and '帮助', while only partially supporting English via 'agent' and 'help'. This effectively enforces a specific language for core functionality, which is a policy violation unless the locale restriction is explicitly justified or made optional.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

The skill enables creation of persistent agents and associated long-term context without any visible authorization, approval, ownership checks, retention limits, or user confirmation. In an agent environment, this can be abused to store sensitive data indefinitely, create unauthorized persistent state, or poison future retrievals across sessions if the underlying context manager is shared.

Content

Scanner excerpt · skill.py (reported line 111)May include surrounding context.

python
# Generate agent ID
            agent_id = agent_name.lower().replace(" ", "_").replace("-", "_")

            # Create agent
            response = await self.context_manager.create_agent(
                agent_id=agent_id,
                name=agent_name,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger logic only recognizes Chinese command words such as "创建", "列出", "删除", "保存", "搜索", and most responses/help text are written exclusively in Chinese. This creates a language-policy issue because users are not given an opt-in or alternative locale, and no region-specific justification is provided.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill_demo.py (reported line 66)May include surrounding context.

python
pip install chromadb sentence-transformers fastapi uvicorn redis aiofiles openai"""

    def _create_agent(self, message: str) -> str:
        """Create an agent."""
        import re
        match = re.search(r"为\s+['\"]?([^'\"]+)['\"]?\s+创建", message)
        if match:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The test inputs are written only in Chinese string literals, which reflects a language-specific usage pattern without any visible opt-in or alternative locale handling. Under the policy rule, forcing a specific language without user choice can be a natural-language policy concern even in code examples.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script sends only Chinese natural-language prompts to the skill, such as help, create, list, and search requests. This imposes a specific language/locale in the interaction flow without documenting user choice or indicating that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.