Back to skill

Security audit

Neat Freak

Security checks for vulnerabilities and agentic risk

Overview

This skill is a legitimate documentation and memory cleanup workflow, but it reaches into global agent state and can modify or delete persistent files without sufficiently clear opt-in boundaries.

Install only if you want an aggressive knowledge-base cleanup assistant. Before running it, explicitly limit scope to the current project unless you want it to inspect global agent memory/configuration, and require a path-by-path diff plus confirmation before it edits AGENTS.md/CLAUDE.md, memory files, or deletes any skill directory.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Warning
Location
references/agent-paths.md:21
Finding

Untrusted Project Content Can Be Promoted into Persistent Agent Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:113-122, SKILL.md:154; references/agent-paths.md:21-33
Vulnerability Type: Persistent agent-memory and instruction poisoning
Risk Level: Medium

Vulnerable Snippet

The following is an English translation of the relevant source instructions:

markdown
3. Collect rule files upward: walk from the project root to the workspace root,
read CLAUDE.md / AGENTS.md at every level, and then read global configuration
files such as ~/.claude/CLAUDE.md and ~/.codex/AGENTS.md when they exist.

Manually maintained, authoritative cross-session facts:
write them to ~/.codex/AGENTS.md for global facts or to the project-level
AGENTS.md for project-specific facts.

Technical Analysis

The Skill treats project documents, parent rule files, conversation content, and persistent Agent configuration as parts of one reconciliation workflow. It expressly identifies ~/.codex/AGENTS.md as an authoritative, manually editable cross-session store.

No mandatory trust-boundary control prevents repository-controlled text from being promoted into this persistent global instruction file. In particular, the workflow does not require:

  • Validation of the provenance of a proposed rule.
  • Separation of repository data from trusted user instructions.
  • An exact preview of global changes.
  • Explicit user authorization before a global write.
  • Restrictions preventing project-specific instructions from affecting unrelated projects.

A repository document can therefore present malicious instructions as project conventions or stable facts. If the Skill accepts and promotes those instructions, they can influence future Agent sessions after the original project is no longer active.

Attack Path

  1. An attacker adds a crafted CLAUDE.md, AGENTS.md, README entry, or documentation statement to a repository.
  2. The content describes an attacker-selected instruction as a req ...[truncated 1095 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make all writes outside the current project opt-in.
  2. Never automatically promote repository-controlled text into user-global Agent instructions.
  3. Require an exact path-by-path and line-by-line diff before modifying persistent state.
  4. Require explicit user approval for each global or cross-session write.
  5. Record the source project and source file for every retained fact.
  6. Reject proposed persistent rules that alter security policy, tool permissions, instruction precedence, or unrelated projects.
  7. Store project-specific facts only in project-local files.
  8. Use a structured data format for retained facts rather than executable natural-language instructions.
  9. Back up persistent configuration and support atomic rollback.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:113
Finding

Project Cleanup Automatically Inspects Unrelated Global Agent State

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:113-122; references/agent-paths.md:5-57
Vulnerability Type: Excessive access to home-directory Agent configuration and memory
Risk Level: Medium

Vulnerable Snippet

sh
ls -d ~/.claude ~/.codex ~/.config/opencode ~/.openclaw 2>/dev/null

The following is an English translation of the associated source instructions:

markdown
List the Agent memory files and read MEMORY.md and every referenced Markdown file.

Read every CLAUDE.md / AGENTS.md file from the project root up to the workspace
root, and then read global configuration files such as ~/.claude/CLAUDE.md and
~/.codex/AGENTS.md when present.

Technical Analysis

A project documentation-cleanup request triggers discovery and reading of home-directory Agent stores, including global instructions and cross-session memories. Those stores can contain information about unrelated repositories, personal preferences, infrastructure, operational procedures, or sensitive paths.

This access is broader than the minimum authority required to reconcile documentation inside the supplied project. The workflow does not require the user to opt in to home-directory inspection, enumerate approved paths, or redact sensitive values before the files enter the model context.

The audit found no instruction to transmit this information to an external service. Nevertheless, placing unrelated persistent state into the active context creates an avoidable confidentiality boundary violation and increases the damage possible from malicious repository instructions.

Attack Path

  1. An attacker supplies or modifies a repository containing instructions designed to elicit global configuration or memory details.
  2. The user invokes the Skill for ordinary project cleanup.
  3. The Skill enumerates ~/.claude, ~/.codex, ~/.config/opencode, and ~/.openclaw.
  4. It reads global configuration and memory files u ...[truncated 821 chars]
Remediation
View remediation

Remediation Suggestions

  1. Limit the default audit to the supplied project directory.
  2. Require explicit opt-in before reading any home-directory Agent state.
  3. Display the exact paths that will be accessed and request approval first.
  4. Use canonical-path allowlists and reject paths outside approved roots.
  5. Read only the minimum metadata needed before loading complete file contents.
  6. Redact tokens, credentials, private URLs, and secret-like values before content enters the working context.
  7. Keep unrelated projects and global memories out of project-generated files.
  8. Add a project-only mode and make it the default.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:166
Finding

Semantic Cleanup Rules Permit Unconfirmed Deletion of Persistent Skill Directories

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:166, SKILL.md:174-176, SKILL.md:225; references/agent-paths.md:31-33
Vulnerability Type: Unsafe destructive file operations
Risk Level: Medium

Vulnerable Snippet

The following is an English translation of the relevant source instructions:

markdown
For retired, renamed, or removed functionality, remove non-payload references
during the same synchronization operation. Delete the entire dead Skill directory.

You must actually use editing tools to modify existing files, writing tools to
create new files, and deletion commands to clean obsolete files.

The only content that should be manually cleaned includes dead Skills under:
~/.codex/memories/skills/<feature>/
~/.codex/skills/<feature>/

Technical Analysis

The Skill expressly authorizes deletion of complete Skill directories in persistent, user-global locations. Whether a Skill is “dead” is determined semantically from repository state, documentation, history, and the current conversation.

The deletion workflow lacks mandatory safeguards such as:

  • Explicit user confirmation for each deletion.
  • A dry-run mode and exact deletion manifest.
  • Canonical-path validation.
  • Protection against symbolic-link traversal.
  • Verification that the target belongs exclusively to the retired feature.
  • Backup or trash-based recovery.
  • Atomic rollback if later validation fails.

The instructions also create an internal policy inconsistency: general governance guidance treats deletion as destructive and subject to user approval, while the Skill-specific retirement process directly mandates deleting dead Skill directories. This ambiguity can cause an Agent to choose the more destructive interpretation.

Attack Path

  1. An attacker modifies project documentation, memory, or history to make an active feature appear retired.
  2. The user invokes the synchronization Skill.

...[truncated 971 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit user approval for every file or directory deletion.
  2. Generate and display an exact deletion manifest before taking action.
  3. Resolve and validate canonical paths against narrowly allowlisted roots.
  4. Reject symbolic links and refuse deletion when any path component is a link.
  5. Verify that the directory is uniquely associated with the retired feature.
  6. Move targets to a recoverable trash or quarantine location instead of deleting them immediately.
  7. Create a backup and provide a tested rollback command.
  8. Make dry-run behavior the default.
  9. Resolve the policy inconsistency by making all destructive actions subject to the governance approval rule.
  10. Never delete user-global Skills solely on the basis of repository-controlled documentation or conversation claims.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list is excessively broad and includes common phrases such as '整理一下', '收尾', 'tidy', and milestone-like language that can occur in ordinary conversation. Because this skill performs wide-ranging filesystem inspection and direct edits/deletions, accidental invocation could cause unintended documentation, memory, or rule changes without the user explicitly requesting a destructive sync operation.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

This duplicated finding points to the same risky behavior: cross-project scanning and cleanup of agent config/memory directories under the user's home directory. In context, the danger is heightened because the skill also instructs deletion of 'dead' skill directories, which could remove persistent assets unrelated to the current task.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
- 新增数据库表 → CLAUDE.md + architecture 的 Data Model
- 新增大特性(跨多文件) → 以上全部 + architecture 新章节 + handoff 已完成清单
- 跨项目改动 → 上下游两边的 docs **都要对齐**(最常见的漏改场景)
- **退役 / 改名 / 下线** → `git show <删除 commit> --stat` 取被删的路由/导出符号/字段/枚举名,对每个跑 `grep -rn '<symbol>' docs/ <本 agent 记忆目录>`(Codex 还要 grep `~/.codex/AGENTS.md` + `~/.codex/memories/skills/`),**在同一次同步里清掉非载荷引用(示例代码/历史案例/枚举列举)**,别留到事后的「补漏」commit。死 skill 目录整个删。
- 记忆层面:相对时间→绝对日期、过期事实→改、重复→合并、已完成待办→删
- **过期开放项扫描**:grep 记忆里同时带「开放项标记(待办/未决/暂缓/搁置/待评估/仍未/观察期再评估/TODO)」**且**「绝对日期早于今天」的行(别裸扫日期——绝对日期满天飞、大多是正确历史;marker 同行才是信号)。每条强制处置:① 已落地→链接 commit 并删;② 没落地→从「计划」降级为「未决,未排期,触发条件=X」,别让它再冒充已排期承诺;③ 已放弃→删。**写「已完成」前先对照真实代码与产物核实**,别假设已上线。

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

This duplicated finding points to the same risky behavior: cross-project scanning and cleanup of agent config/memory directories under the user's home directory. In context, the danger is heightened because the skill also instructs deletion of 'dead' skill directories, which could remove persistent assets unrelated to the current task.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
- 新增数据库表 → CLAUDE.md + architecture 的 Data Model
- 新增大特性(跨多文件) → 以上全部 + architecture 新章节 + handoff 已完成清单
- 跨项目改动 → 上下游两边的 docs **都要对齐**(最常见的漏改场景)
- **退役 / 改名 / 下线** → `git show <删除 commit> --stat` 取被删的路由/导出符号/字段/枚举名,对每个跑 `grep -rn '<symbol>' docs/ <本 agent 记忆目录>`(Codex 还要 grep `~/.codex/AGENTS.md` + `~/.codex/memories/skills/`),**在同一次同步里清掉非载荷引用(示例代码/历史案例/枚举列举)**,别留到事后的「补漏」commit。死 skill 目录整个删。
- 记忆层面:相对时间→绝对日期、过期事实→改、重复→合并、已完成待办→删
- **过期开放项扫描**:grep 记忆里同时带「开放项标记(待办/未决/暂缓/搁置/待评估/仍未/观察期再评估/TODO)」**且**「绝对日期早于今天」的行(别裸扫日期——绝对日期满天飞、大多是正确历史;marker 同行才是信号)。每条强制处置:1 已落地→链接 commit 并删;2 没落地→从「计划」降级为「未决,未排期,触发条件=X」,别让它再冒充已排期承诺;3 已放弃→删。**写「已完成」前先对照真实代码与产物核实**,别假设已上线。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/sync-matrix.md (reported line 57)May include surrounding context.

md
| CLAUDE.md 与 AGENTS.md 两份独立且内容不一致 | 待用户拍板——合并需要确认哪边权威 |
| 有可运行代码但缺 CLAUDE.md | 按工作空间模板建脚手架 |
| 目录命名违反工作空间约定 | 待用户拍板——重命名有外部影响(Syncthing / 脚本 / 引用) |
| .gitignore 缺红线条目(.env 等) | 直接补 |
| 规则文件引用了已删除的项目/路径 | `ls` 核实确已删除 → 清引用;拿不准(可能在别的设备) → 待用户拍板 |
| 上下级规则矛盾 | 能从现状判断现行版本的直接改,不能的待用户拍板 |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to delete files, merge content, and rewrite documentation/memory, but it does not require a prominent user-facing warning or confirmation before destructive actions. This creates risk of silent data loss or irreversible edits to project knowledge artifacts during what may be perceived as routine cleanup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates scanning and potentially modifying filesystem locations outside the current project, including home-directory agent memory/config paths. Without an upfront warning and scoped consent, this broadens the blast radius from project-local cleanup to system-wide agent state, increasing the chance of unintended cross-project changes or privacy exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

This duplicate finding identifies the same mandatory persistence behavior. In this skill's context, persistence is more dangerous because it targets high-trust artifacts like CLAUDE.md, AGENTS.md, docs, and memory, which can influence future agent behavior across sessions.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
### 第四步:实际修改(用工具,不只是描述)

你必须**真的用 Edit 修改现有文件、用 Write 创建新文件、用删除命令清理废弃文件**。"我会怎么改"的描述不算完成。

**顺序建议**:先改 docs/(改错影响外部)→ 再改 CLAUDE.md/AGENTS.md → 最后理记忆。先动外部优先级最高的,即使中途被打断,读者看到的也是对齐的最新状态。

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

This duplicate finding identifies the same mandatory persistence behavior. In this skill's context, persistence is more dangerous because it targets high-trust artifacts like CLAUDE.md, AGENTS.md, docs, and memory, which can influence future agent behavior across sessions.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
### 第四步:实际修改(用工具,不只是描述)

你必须**真的用 Edit 修改现有文件、用 Write 创建新文件、用删除命令清理废弃文件**。"我会怎么改"的描述不算完成。

**顺序建议**:先改 docs/(改错影响外部)→ 再改 CLAUDE.md/AGENTS.md → 最后理记忆。先动外部优先级最高的,即使中途被打断,读者看到的也是对齐的最新状态。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is written entirely in Chinese and does not provide an alternative language option or indicate that the skill is intentionally region-specific. Under the policy rule for language/locale, this is a natural-language constraint that can exclude users who did not opt into that language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill reference is written in Chinese and does not indicate that language choice is optional or limited to a China-specific workflow. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.