Back to skill

Security audit

My Work Profile Cross Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local work-memory tool, but it defaults to silently retaining and reusing conversation-derived profile knowledge across agents.

Review this skill before installing if you do not want agents to build a persistent work profile automatically. Consider setting autoUpdate=off, periodically inspecting and deleting stored files/logs, and avoiding use in chats containing sensitive business, personal, credential, or third-party information.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:39
Finding

Untrusted conversation content can poison persistent cross-agent memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:52
Finding

User-controlled domain names are used in filesystem operations without documented path validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (13)

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This workflow instructs the agent to analyze every conversation, extract durable user attributes and domain knowledge, and update persistent files—often automatically. The risk is elevated because collection is systematic, ongoing, and partly silent, enabling covert profiling, retention of sensitive business context, and cross-session behavioral manipulation even if some explicit secret types are filtered.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description advertises cross-agent shared local storage and continuous extraction/application of user knowledge across sessions. Persistent collection of conversationally derived data creates privacy and profiling risk, particularly because the memory is reused by multiple agents and may outlive the user's expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The command to delete a domain performs destructive removal of stored knowledge without any confirmation, preview, or undo path. This creates a risk of accidental or induced data loss, especially if the command is triggered by ambiguous text or social engineering within a conversation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow explicitly requires the agent to read profile/domain files silently and not tell the user it is doing so. Combined with persistent storage of conversation-derived knowledge, this undermines informed consent and transparency, and can cause users to disclose information without realizing it will be retained and reused across sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The logging instructions require storing summaries of referenced knowledge and conversation-derived changes in timestamped log files. Even if intended for traceability, these logs can duplicate sensitive profile or business information, broaden exposure on disk, and increase forensic recoverability beyond the primary memory files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example explicitly performs writes to userProfile.md, domain files, the index, and changelog as part of an automatic flow, but only informs the user after the retention has already happened. This creates a consent and transparency failure for persistent storage of user-derived profile and work information, especially because the stored data is later reused across agents.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples direct the assistant to extract, persist, and later surface user work profile, preferences, and domain knowledge from normal conversation. This is a natural-language data retention pattern that can accumulate sensitive professional information and make it available across agents, increasing the chance of unintended disclosure or over-collection.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Even in manual-confirmation mode, the skill extracts and displays inferred user attributes and domain knowledge before the user has consented to storage. That pre-consent summarization itself exposes collected personal/work-profile data in the response and normalizes collection before authorization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The migration flow creates multiple files and renames an existing knowledgeRecord.md to a backup without any user-facing confirmation. Even if intended as a convenience feature, silent migration alters local state and may preserve or reorganize sensitive historical data in ways the user did not authorize or expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The spec defines autoUpdate=on as the default and ties normal conversation and knowledge extraction into the same workflow, which can lead an agent to persist user-derived content automatically without an explicit, per-write user confirmation. In a cross-agent shared storage context, silent writes increase the risk of unintended profile changes, propagation of incorrect data, and modification of local files the user may not realize are being updated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The migration guide instructs automatic extraction, file creation, and renaming of an existing knowledge file to a backup without requiring a prominent warning or confirmation before modifying user data. Even though a backup is kept, automated migration can still overwrite derived files, mis-parse content, or move users onto a new storage layout unexpectedly, which is especially risky for a persistent local profile shared across agents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description is written as a Chinese-only operating mode and does not mention any user-selectable language or locale option. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The text states '使用中文沟通,偏好简洁表达,' which sets a language requirement/preference in natural language. Because the file does not indicate that language choice is optional or user-configurable, it may violate the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.