Back to skill

Security audit

mia

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned as a memory and planning helper, but it persists user/task history and can send prompts, historical plans, and API credentials to configurable external endpoints without enough safeguards.

Install only if you are comfortable with local persistence of task history and feedback. Prefer local planner mode for sensitive work, set memory and feedback files to protected locations, review or delete stored JSONL files regularly, and use API mode only with trusted HTTPS endpoints and narrowly scoped API keys.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
memory/mia-memory.mjs:329
Finding

Untrusted Persistent Memory Can Influence Future Agent Plans

Content
View full analysis

Vulnerability Details

File Location: memory/mia-memory.mjs:329-343, mia-memory/mia-memory.mjs:329-343, planner/mia-planner.mjs:58-77, and mia-planner/mia-planner.mjs:58-77
Vulnerability Type: Persistent memory poisoning through unsanitized historical plans
Risk Level: Medium

Vulnerable Code

Memory records are accepted and persisted without schema validation, provenance checks, or content sanitization:

js
function storeRecord(entry) {
  const record = {
    timestamp: new Date().toISOString(),
    ...entry
  };

  // If efficiency metrics are absent, add default values
  if (!record.efficiency && record.execution) {
    record.efficiency = {
      search_count: record.execution.length,
      step_count: (record.steps || []).length,
      success: true
    };
  }

  return storeWithOptimization(record);
}

Historical plan content is subsequently inserted directly into the model prompt:

js
async function generatePlan(question, referencePlan = null) {
  const prompt = referencePlan !== null
    ? REFERENCE_PROMPT.replace('{historicalPlan}', referencePlan).replace('{question}', question)
    : BASE_PROMPT.replace('{question}', question);

  try {
    // Request generation continues using the constructed prompt

The actual source uses equivalent non-English template placeholder names; the security-relevant behavior is direct substitution of referencePlan and question into the prompt.

Technical Analysis

The store command accepts arbitrary JSON and spreads every supplied property into a persistent record. It does not enforce a schema, constrain plan content, record provenance, distinguish trusted instructions from untrusted data, or reject instruction-like text.

The documented workflow allows a retrieved historical plan to be passed to the planner through the --reference argument. The planner inserts that text directly into the model ...[truncated 1985 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define and enforce a strict schema for stored records, including expected types, maximum lengths, and permitted fields.
  2. Reject unknown fields rather than spreading arbitrary input into the persistent record.
  3. Record provenance, trust level, creator identity, and validation status for every memory.
  4. Treat all historical plans as untrusted data and clearly delimit them in the model prompt.
  5. Add explicit planner instructions that content inside the historical-plan section must never override planner policies or request unrelated actions.
  6. Normalize stored plans into structured, allowlisted action metadata instead of retaining unrestricted instruction text where possible.
  7. Validate generated steps against an action and tool allowlist before sending them to an executor.
  8. Require user confirmation for sensitive or privileged actions derived from historical memory.
  9. Add retention, review, quarantine, and deletion controls for suspicious memories.
  10. Apply the same changes to both duplicate implementations under memory/ and mia-memory/.

T09 · Insecure Skill Coding Practices

Warning
Location
planner/mia-planner.mjs:11
Finding

Custom Planner Endpoint Can Receive API Credentials and Sensitive Task Content Without Destination Validation

Content
View full analysis

Vulnerability Details

File Location: planner/mia-planner.mjs:11-35,73-105 and mia-planner/mia-planner.mjs:11-35,73-105
Vulnerability Type: Unrestricted credential and prompt transmission to a configurable endpoint
Risk Level: Medium

Vulnerable Code

The destination URL and API credential are taken from environment variables, and any custom URL is accepted:

js
const MODE = process.env.MIA_PLANNER_MODE || 'local';
const CUSTOM_URL = process.env.MIA_PLANNER_URL;
const MODEL = process.env.MIA_PLANNER_MODEL;
const API_KEY = process.env.MIA_PLANNER_API_KEY;

if (!['local', 'api'].includes(MODE)) {
  console.error(`Error: Invalid MIA_PLANNER_MODE="${MODE}". Must be "local" or "api"`);
  process.exit(1);
}

if (MODE === 'api' && !API_KEY) {
  console.error('Error: MIA_PLANNER_API_KEY is required when MIA_PLANNER_MODE=api');
  process.exit(1);
}

let PLANNER_URL;
if (CUSTOM_URL) {
  PLANNER_URL = CUSTOM_URL;
} else if (MODE === 'api') {
  PLANNER_URL = 'https://api.openai.com/v1/chat/completions';
} else {
  PLANNER_URL = 'http://localhost:8000/v1/chat/completions';
}

API mode then sends the bearer credential and complete prompt to the selected URL:

js
async function generatePlan(question, referencePlan = null) {
  const prompt = referencePlan !== null
    ? REFERENCE_PROMPT.replace('{historicalPlan}', referencePlan).replace('{question}', question)
    : BASE_PROMPT.replace('{question}', question);

  try {
    const headers = { 'Content-Type': 'application/json' };
    if (MODE === 'api') {
      headers['Authorization'] = `Bearer ${API_KEY}`;
    }

    const body = {
      model: PLANNER_MODEL,
      messages: [{ role: 'user', content: prompt }],
      temperature: 0.7,
      max_tokens: 2048
    };

    if (MODE === 'local') {
      body.chat_template_kwargs = { enable_thinking: false };
    }

    const controller = new AbortCo
...[truncated 3026 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require https: for every API-mode endpoint and reject plaintext HTTP.
  2. Parse destinations with the standard URL parser and reject malformed URLs, embedded credentials, unsupported protocols, and unexpected ports.
  3. Maintain an allowlist of approved provider hosts or require explicit administrator approval for each custom host.
  4. Bind each API credential to a configured provider and never forward one provider's credential to an unrelated custom host.
  5. Use separate, narrowly scoped credentials for different custom endpoints.
  6. Display or log the destination hostname without logging the credential, and require confirmation when a new custom host is first used.
  7. Clearly disclose that user questions and historical plans leave the local system in API mode.
  8. Add optional redaction or data-loss-prevention processing before constructing outbound prompts.
  9. Minimize submitted context and avoid sending historical content unless it is necessary for the current request.
  10. Add automated tests confirming that API mode rejects HTTP, unapproved hosts, embedded URL credentials, and malformed destinations.
  11. Apply identical hardening to both duplicate planner files under planner/ and mia-planner/.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (30)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
node memory/mia-memory.mjs search "你的问题"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
node memory/mia-memory.mjs search "你的问题"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
node memory/mia-memory.mjs search "你的问题"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill declares capabilities implying environment variable access and network use, but it does not define an explicit tool scope such as permissions or allowed-tools. This creates an authorization ambiguity where operators or users may not understand that the skill can reach external endpoints and consume sensitive configuration like API keys, increasing the risk of unintended data exposure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Planner section documents external API usage but does not warn that user questions and historical plan content may be transmitted to third-party endpoints. Because those inputs can contain sensitive user data or prior internal reasoning artifacts, omission of this disclosure can lead to unintentional privacy and confidentiality leaks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Memory and Feedback sections explicitly support storing questions, plans, execution traces, answers, and feedback in local JSONL files, but the skill does not warn users that this data will be persisted. Persisting potentially sensitive interaction content without clear disclosure or retention guidance can expose private information to other local users, backups, logs, or later compromise of the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code persistently stores user-provided records to MEMORY_FILE and may overwrite existing records via the optimization logic, but there is no confirmation prompt or explicit user-facing warning that data will be retained and older entries may be replaced. Because the skill handles memory content that may include user data, persistence and replacement behavior should be clearly disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly describes collecting and storing user feedback records, including the user's question and answer content, but provides no privacy notice, retention policy, access controls, or data-handling guidance. Because these fields can contain sensitive or personal information, the omission creates a real privacy and compliance risk even if the feature is intended to be benign.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's natural-language instructions and descriptions are presented exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy requirements when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file header and command descriptions present the skill as Chinese-only, and the CLI usage/help text also uses Chinese labels for commands and behavior. This creates a language-policy issue because the skill appears to force a specific language/locale without any user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file presents the skill entirely in Chinese, and the embedded prompt templates instruct the model in Chinese, implying a fixed language behavior. There is no indication that users can choose another language or that the Chinese-only constraint is intentional for a region-specific use case.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documented default API endpoint is an external service, which means user prompts and referenced historical plan content may be transmitted off-host in API mode. External transmission is not inherently malicious, but in this skill's context it is security-relevant because the planner can include memory-derived data and the documentation does not pair this with an explicit privacy warning or data-handling guidance.

Content

Scanner excerpt · mia-planner/SKILL.md (reported line 65)May include surrounding context.

md
**默认配置:**
- local模式:`http://localhost:8000/v1/chat/completions`
- api模式:`https://api.openai.com/v1/chat/completions`

**默认模型:**
- local模式:`Qwen3-8B`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly supports API mode and allows sending both the user's question and referenced historical plans to third-party OpenAI-compatible endpoints, but it does not warn users that their prompts and memory-derived content may leave the local environment. This creates a real privacy and data-governance risk, especially because historical plans may contain sensitive prior task context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This section reiterates that API mode connects to OpenAI-compatible external providers, again implying outbound transfer of user and memory-related content. In the planner context, this is more sensitive than generic outbound traffic because the referenced historical plans may contain accumulated operational context that users may not expect to be shared externally.

Content

Scanner excerpt · mia-planner/SKILL.md (reported line 120)May include surrounding context.

md
- 连接到 OpenAI 协议兼容的 API 服务
- 需要 `MIA_PLANNER_API_KEY`
- 支持:OpenAI、阿里云 DashScope、Azure 等
- 默认端点:`https://api.openai.com/v1/chat/completions`
- 默认模型:`gpt-4`

## Prompt 模板

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill is designed to send prompt content to an external service endpoint, including the default OpenAI API URL or an arbitrary custom URL. External transmission is not inherently malicious, but in this context it is security-relevant because user questions and historical plans may contain sensitive information and the custom endpoint support increases exfiltration and trust-boundary risk.

Content

Scanner excerpt · mia-planner/mia-planner.mjs (reported line 33)May include surrounding context.

js
if (CUSTOM_URL) {
  PLANNER_URL = CUSTOM_URL;
} else if (MODE === 'api') {
  PLANNER_URL = 'https://api.openai.com/v1/chat/completions';
} else {
  PLANNER_URL = 'http://localhost:8000/v1/chat/completions';
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language prompts are written to require planning behavior in Chinese, and the file does not offer any mechanism for the user to select a preferred language or opt in to this locale constraint. This creates a language policy concern because the skill appears to enforce a specific language by default rather than adapting to user preference.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code sends the user question and optional historical plan to a configurable remote endpoint without any built-in disclosure, consent flow, or minimization. Because those fields may contain sensitive user content, prior agent traces, or proprietary data, this creates a real privacy and data-governance risk, especially when MODE=api or when a custom URL is supplied.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The planner can send the user's question and any historical plan to either OpenAI or an arbitrary URL supplied through MIA_PLANNER_URL. Because historical plans may contain prior user data, internal reasoning artifacts, or sensitive context, this creates a real exfiltration path outside the local system without any allowlist, consent flow, or data minimization.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The code contains a built-in path to send prompt data to https://api.openai.com/v1/chat/completions when api mode is enabled. External transmission is not inherently malicious, but in this skill it becomes a genuine security/privacy issue because sensitive questions and reference plans are exported to a third party without strong controls or disclosure.

Content

Scanner excerpt · planner/mia-planner.mjs (reported line 33)May include surrounding context.

js
if (CUSTOM_URL) {
  PLANNER_URL = CUSTOM_URL;
} else if (MODE === 'api') {
  PLANNER_URL = 'https://api.openai.com/v1/chat/completions';
} else {
  PLANNER_URL = 'http://localhost:8000/v1/chat/completions';
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The base and reference prompts are written entirely in Chinese and instruct the planner's behavior in that locale, with no indication that the user can choose another language. This can violate language/locale policy where skills must not force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

generatePlan(question, refPlan) forwards the current question and optional historical plan to the configured remote model endpoint, but the script provides no user-facing disclosure at the point of use. This is dangerous because users may reasonably assume planning is local while their prompt content is actually transmitted to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions and usage guidance are presented in Chinese throughout the file, but the skill does not indicate that Chinese is optional or that the skill is intentionally restricted to a Chinese-speaking context. This can conflict with language-choice expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module comment states the collector's responsibility is to gather feedback '仅针对全新问题' (only for brand-new questions). However, the store path accepts arbitrary question text from argv and appends it directly to storage, with no check for whether the question is new or previously seen.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language descriptions and command help text are presented only in Chinese, with no indication that other languages are supported or that the user can opt into this locale. That can violate language/locale policy when a skill imposes a specific language without user choice or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI help and operational descriptions are written in Chinese for core commands, which constrains interaction to a single language without presenting an alternative or opt-in mechanism. This is a natural-language locale restriction rather than a code defect, but it still falls under policy review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.