Back to skill

Security audit

AI Daily Briefing

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only daily briefing skill, but it directs the agent to read persistent memory/profile files and calendar/task context with broad trigger phrases and limited user control.

Install only if you are comfortable with the agent using your to-do list, recent meeting notes, calendar, and ai-persona-os memory/profile files in briefings. Keep sensitive details out of MEMORY.md, memory/, and USER.md or disable those sources if your agent supports it, and prefer explicit requests like 'daily briefing' when invoking it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:100
Finding

Overbroad Access to Persistent Memory and User Profile Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 100–104 and 151–156
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable Code

markdown
### 4. Memory/Context Files (if using ai-persona-os)

**Locations:**
- `MEMORY.md` — Permanent facts
- `memory/[today].md` — Session notes
- `USER.md` — User preferences

The mandatory data-gathering workflow subsequently directs the Agent to inspect these sources:

markdown
Check for these files in order:

1. todo.md (to-do list from ai-meeting-notes)
2. meeting-notes/ folder (recent meeting notes)
3. MEMORY.md (if using ai-persona-os)
4. memory/[today].md (session notes)
5. Calendar integration (if available)

Technical Analysis

A daily briefing legitimately requires task, meeting, and calendar information. However, the Skill also instructs the Agent to read permanent memory, session notes, and the general user-profile file. These sources may contain personal facts, historical conversation context, preferences, or other sensitive information unrelated to the requested briefing.

The instructions do not define field-level restrictions, sensitivity filtering, purpose limitations, or an explicit consent step before these persistent files are accessed. Consequently, the workflow violates the principle of least privilege: it permits access to broader persistent context than is necessarily required to summarize the user's current schedule and tasks.

This issue does not grant new operating-system permissions and no external exfiltration mechanism was found. The risk arises when the host Agent already has workspace-reading capabilities and follows the Skill's broad collection instructions.

Attack Path

  1. The Skill is installed in an Agent that can read files in the user's workspace.
  2. The workspace contains MEMORY.md, memory/[today].md, or USER.md with persistent personal or s ...[truncated 1029 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make persistent-memory access disabled by default and require explicit user opt-in before reading MEMORY.md, memory/, or USER.md.
  2. Use task-specific sources such as todo.md, recent meeting notes, and the calendar as the default briefing inputs.
  3. Allow users to select individual memory files or approved fields rather than authorizing an unrestricted scan.
  4. Define an allowlist of briefing-relevant data categories, such as working hours, scheduling preferences, and explicitly marked reminders.
  5. Exclude sensitive categories by default, including credentials, financial information, health information, private relationship details, and unrelated historical conversations.
  6. Add a relevance and sensitivity review before memory-derived information is reproduced in a briefing.
  7. Clearly identify which sources were used and provide a setting that permanently disables persistent-memory integration.
  8. Limit file reads to the minimum necessary portions and avoid copying complete memory-file contents into model context.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill markets itself as a simple morning briefing without clearly warning that it may read sensitive sources including meeting notes, memory files, and calendar data. This undermines informed consent and can lead users to disclose or surface private business and personal information unintentionally when invoking the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad, conversational, and likely to appear in ordinary chat, which can cause the skill to activate without clear user intent. Because activation leads the agent to gather data from todo files, meeting notes, memory files, and possibly calendar sources, accidental invocation can expose sensitive workspace context that the user did not explicitly request in that moment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "briefing" is very generic and can easily appear in normal conversation, making unintended activation plausible. In a skill that aggregates calendar, tasks, and meeting-note context, accidental invocation could expose sensitive productivity data or steer the assistant away from the user's actual intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example phrase "what's today look like?" is a common conversational utterance that could be used in many contexts unrelated to this skill. Because this skill returns synthesized personal schedule and meeting context, broad matching increases the risk of accidental activation and unintended disclosure of sensitive information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrase "what's overdue?" is broad and may naturally occur in unrelated discussions about projects, billing, or deadlines. Since the skill responds with potentially sensitive to-do and deadline data, an overly permissive trigger can cause unintended workflow disclosure or context switching.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The listed trigger phrases include very common conversational language such as 'start my day' and 'what's on my plate?', which can overlap with normal user dialogue and cause unintentional invocation. In a skill that aggregates personal productivity, calendar, and meeting-derived task context, accidental triggering can expose sensitive scheduling and work information in the wrong context or to the wrong audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The quick-start text says meeting action items 'automatically populate your to-do list' and that calendar data appears automatically, but it does not disclose what data is accessed, when access occurs, or the privacy implications. Because this skill surfaces work tasks, meetings, and contextual background, silent or poorly explained data use can lead to oversharing of sensitive personal or business information and undermine informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a no-setup briefing skill that provides a daily overview from existing task, meeting, and calendar context. However, the documented behavior explicitly offers to create a to-do list, process meeting notes, or set up a priority list when no data exists, which goes beyond merely delivering a briefing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest centers the skill on a morning briefing with today's tasks, calendar, and meeting context. The file's documented behavior additionally includes 'weekly preview,' weekend briefings, and end-of-day requests, which are adjacent but materially broader than the stated morning-only scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes a productivity-focused briefing based on tasks, calendar, and recent meetings. The customization section suggests adding weather and motivational quotes, which are outside the declared purpose and data sources of the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

"Weekly preview" is less generic than the other phrases but is still underspecified and may overlap with ordinary planning conversation. The risk is lower because the phrase is more domain-specific, yet it could still trigger disclosure of upcoming schedule and task context without clear user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.