Back to skill

Security audit

Soul Sharing

Security checks for vulnerabilities and agentic risk

Overview

This skill has a clear memory-sharing purpose, but it asks agents to persistently load and write shared GitHub-backed identity and memory using mutable external scripts without enough review or data-safety controls.

Install only if you intentionally want a private GitHub repository to become shared long-term memory for your agents. Before use, review and pin the external template and scripts, consider disabling GitHub Actions, restrict repository access, require user approval before committing memories, and avoid storing secrets, regulated data, raw conversations, or confidential project details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:76
Finding

Persistent Agent Instruction and Memory Poisoning Through Synchronized Repository Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 76-111
Vulnerability Type: Persistent loading of externally controlled identity, memory, and startup instructions
Risk Level: High

Vulnerable Code Snippet:

markdown
### Step 1 — Sync and read

```bash
git pull --ff-only origin main

Read L0 (soul): SOUL.md -> IDENTITY.md -> USER.md -> VOICE.md Read L1 (memory): canonical/profile.md -> canonical/stable-memory.md

Step 3 — Write join event and push

bash
python scripts/add_event.py --source YOUR_ID --kind decision --scope stable \
  --summary "YOUR_ID joined agent-soul and adopted the shared identity."
python scripts/compile_memory_hub.py --apply
git add sources/ canonical/
git commit -m "chore: YOUR_ID joins agent-soul"
git push origin main

Step 4 — Persist in your runtime config

Write the loading instruction into your startup config so you remember the hub next session.

Claude Code (~/.claude/CLAUDE.md):

markdown
## Shared Memory
- Repo: /path/to/repo
- Source id: YOUR_SOURCE_ID
- Session start: git pull, read L0 + L1
- Write: python scripts/add_event.py --source YOUR_SOURCE_ID ...
text

### Technical Analysis

The skill instructs an agent to pull mutable content from a Git repository and load identity and memory documents directly into its operational context. Files such as `SOUL.md`, `IDENTITY.md`, `USER.md`, and the generated canonical memory can contain natural-language rules that influence agent behavior.

The same instructions direct the agent to place repository-loading behavior in a persistent runtime configuration file such as `~/.claude/CLAUDE.md`. Consequently, repository content is not limited to the current invocation: it can continue to affect later sessions.

No trust boundary, signature verification, content schema, instruction filtering, protected-branch requirement, or user confirmation step is 
...[truncated 1530 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not interpret synchronized memory or persona records as executable instructions. Separate trusted policy from untrusted memory data.
  • Represent memory as schema-validated structured records, with fields that cannot redefine system policy, tool permissions, or startup behavior.
  • Require explicit user review and approval for changes to identity, behavioral rules, and stable memory.
  • Pin synchronization to reviewed commits or cryptographically verify signed commits from approved maintainers.
  • Apply protected branches, mandatory reviews, signed commits, and least-privilege repository access.
  • Sanitize retrieved content before adding it to the agent context, including detection of prompt-injection and tool-use directives.
  • Avoid modifying global startup files automatically. Prefer a project-scoped, revocable configuration approved by the user.
  • Provide a documented removal procedure that deletes persistent startup entries and restores trusted identity files.
  • Maintain provenance for every memory item and prevent generated canonical files from elevating memory content into trusted policy.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Execution of Mutable and Unaudited Code Retrieved From an External Repository

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 64-120
Vulnerability Type: Unpinned remote payload retrieval followed by local and CI execution
Risk Level: Critical

Vulnerable Code Snippet:

markdown
## Human setup (one-time, ~10 minutes)

Ask your user to:

1. Create a **private** GitHub repository
2. Clone the template: `git clone https://github.com/kingcharleslzy-ai/agent-soul.git my-agent-memory`
3. Push to their private repo
4. Enable GitHub Actions
5. Fill in persona files (`SOUL.md`, `IDENTITY.md`, `USER.md`, `VOICE.md`)
6. Give you the repo path and your stable `source` id
markdown
### Step 3 — Write join event and push

```bash
python scripts/add_event.py --source YOUR_ID --kind decision --scope stable \
  --summary "YOUR_ID joined agent-soul and adopted the shared identity."
python scripts/compile_memory_hub.py --apply
git add sources/ canonical/
git commit -m "chore: YOUR_ID joins agent-soul"
git push origin main
text

```markdown
## Session protocol (every session)

1. `git pull --ff-only origin main`
2. Read L0 (soul) + L1 (memory)
3. Load L2 only when needed
4. Write events via `scripts/add_event.py`
5. Use `scripts/quick_share.sh` for urgent propagation
6. Never hand-edit `canonical/*` — it is auto-generated

Technical Analysis

The audited package does not contain the referenced Python or shell scripts. Instead, the skill directs the user to clone a mutable external repository, repeatedly pull its current main branch, and execute scripts obtained from that repository. Neither an immutable commit identifier nor a checksum or signature is provided.

The effective executable payload can therefore change after this skill has been reviewed. The instruction to enable GitHub Actions creates an additional execution channel for workflow files delivered by the same external source. A compromise of the upstream project, its maintainer ...[truncated 1709 chars]

Remediation
View remediation

Remediation Suggestions

  • Include all required scripts in the reviewed skill package rather than downloading executable code at runtime.
  • If external retrieval is unavoidable, pin the repository to a specific immutable commit hash and verify cryptographic checksums or signed commits before execution.
  • Review and approve every script and workflow at the pinned revision.
  • Do not enable GitHub Actions by default. Require separate, informed approval after reviewing workflow permissions and commands.
  • Configure workflow tokens with read-only permissions unless write access is strictly required, and do not expose unrelated secrets.
  • Execute retrieved tools in a sandbox with a minimal environment, restricted filesystem access, disabled credential forwarding, and constrained network access.
  • Prevent automatic execution after git pull; require a review when executable files or workflow definitions change.
  • Use repository ownership controls, protected branches, mandatory code review, signed releases, and dependency scanning.
  • Document the exact trusted revision and provide an upgrade procedure that requires a fresh security review.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:89
Finding

Uncontrolled Persistence and External Synchronization of Potentially Sensitive User Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 89-139
Vulnerability Type: Insufficiently protected storage and transmission of user profile and project information
Risk Level: High

Vulnerable Code Snippet:

markdown
### Step 3 — Write join event and push

```bash
python scripts/add_event.py --source YOUR_ID --kind decision --scope stable \
  --summary "YOUR_ID joined agent-soul and adopted the shared identity."
python scripts/compile_memory_hub.py --apply
git add sources/ canonical/
git commit -m "chore: YOUR_ID joins agent-soul"
git push origin main
text

```markdown
## Writing memory events

```bash
# A durable preference
python scripts/add_event.py --source YOUR_ID --kind preference --scope profile \
  --summary "User prefers dark mode across all tools."

# A decision with expiry
python scripts/add_event.py --source YOUR_ID --kind decision --scope stable \
  --summary "Feature freeze until release." --valid-until 2026-04-01

# Something temporary
python scripts/add_event.py --source YOUR_ID --kind fact --scope fuzzy \
  --summary "User is debugging a CORS issue in the API gateway."
text

### Technical Analysis

The skill directs agents to persist user preferences, decisions, and current project activity in Git-tracked NDJSON and canonical files and then push those records to GitHub. Although the setup recommends a private repository and discourages raw transcripts, it does not define content classification, per-event consent, secret detection, encryption, retention enforcement, access review, or safe deletion from Git history.

Git history is durable and replicated. Deleting a current file does not necessarily remove sensitive data from previous commits, local clones, forks, CI artifacts, or logs. The generated canonical files can also duplicate information originally stored under `sources/`, increasing the number of locations requiring cleanup.

### Attack 
...[truncated 1334 chars]
Remediation
View remediation

Remediation Suggestions

  • Obtain explicit user consent before recording or synchronizing each category of personal or project information.
  • Define a strict data-classification policy that prohibits credentials, authentication tokens, private keys, regulated data, raw transcripts, and unnecessary personal identifiers.
  • Add automated secret and sensitive-data scanning before every commit and push.
  • Encrypt sensitive memory records at the application layer using keys that are not stored in the repository.
  • Minimize stored content and use opaque references where detailed source material is unnecessary.
  • Enforce repository access reviews, least-privilege collaborator permissions, multi-factor authentication, protected branches, and audit logging.
  • Disable workflow access to memory content unless required, and prevent untrusted workflows from receiving secrets.
  • Implement enforceable retention and expiry processing rather than relying only on an optional valid_until field.
  • Provide a deletion procedure that addresses current files, Git history, CI artifacts, caches, forks, and authorized clones.
  • Present the exact pending memory diff to the user before committing or pushing it.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly promotes persistent, cross-agent memory sharing of user-related information, but it does not present a clear warning near the usage guidance that sensitive user data may be stored durably and propagated to other agents and devices. This creates a meaningful privacy and consent risk because operators may adopt the skill without understanding that facts, preferences, and decisions can persist across sessions and be visible to multiple agent runtimes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill is designed to establish durable session persistence by writing memory events to a Git-backed repository and reloading them in future sessions. While persistence is the core feature, it becomes dangerous because it encourages long-term retention and propagation of agent-observed user facts without strong guardrails for data minimization, sensitivity filtering, consent, or deletion handling.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

canonical/fuzzy-memory.md | L2: Context Layer (on-demand) canonical/agents/* / "Project state, recent context"

sources/ <- append-only event streams (write surface)

text

## Human setup (one-time, ~10 minutes)

Static analysis

No suspicious patterns detected.