Back to skill

Security audit

Big Seed · 种子 · 日记(AI日记·人生故事·自传·闪念记录·回忆录)| AI Diary, Life Story, Memoir & Journal

Security checks for vulnerabilities and agentic risk

Overview

This journaling skill mostly matches its stated purpose, but it ships diary-like personal data and enables sensitive recurring summaries without well-supported privacy controls.

Review this carefully before installing. The core script does not show malicious code or remote payload execution, but the package should be cleaned of bundled diary data and should add real delete/disable controls before handling private memories. Treat weekly chat summaries as sensitive disclosure because they can reveal facts inferred from your journal even when raw records remain local.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
memory/bigseed-data/seeds.json:4
Finding

Personal Diary Data and Local Media Paths Included in the Distributed Artifact

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to persist user data by invoking a Python script that writes files under memory/bigseed-data/, but the manifest declares no explicit tool scope or allowed-tools restrictions. This creates an authorization ambiguity: a runtime may permit broader file-writing behavior than intended, and reviewers/users cannot verify the exact write boundaries from the manifest.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The weekly workflow proactively compiles sensitive personal seed data into summaries, inferred portraits, and stories, then pushes them into chat. This increases exposure of highly personal information beyond the local store and creates disclosure risk through notification surfaces, chat retention, account compromise, or delivery to the wrong recipient.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The privacy notice claims original seed data stays local and is never uploaded externally, yet the weekly workflow generates summaries, portraits, and stories from that data and pushes them to Feishu chat. Even if raw records are not sent verbatim, derived content can still disclose sensitive personal facts, making the notice materially misleading and undermining informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells users they can say 'delete this seed,' but no documented delete command or workflow exists in the tool interface. This can cause users to rely on a privacy control that is not actually implemented, resulting in retention of sensitive diary content they believed had been removed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The save triggers include common conversational phrases such as '刚想到' and '突然想起', which can appear in ordinary chat without a real intent to store diary data. In a skill that captures intimate personal reflections, accidental activation can silently persist sensitive content the user did not mean to record.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger-word list is broad and not tightly scoped, covering everyday phrases for story generation and recall features without sufficient disambiguation rules. Because this skill processes sensitive journaling data and can generate or push derived personal content, ambiguous activation increases the chance of unintended data use and disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prompt template explicitly instructs automatic extraction of recent personal data and inferred profile information for announcement. Automated inference about habits, emotions, and life patterns can reveal sensitive attributes and amplify privacy harm if surfaced without granular consent or content controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The add command stores highly personal diary content to a local JSON file and also echoes part of that content to stdout immediately after saving. In a journaling/memoir skill, users are especially likely to enter sensitive personal information, so writing it unencrypted and displaying it in terminal output can expose private data through shared machines, shell history captures, terminal logs, screenshots, or redirected output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The story export command emits full seed records and portrait data as JSON to stdout, which can disclose intimate personal data when viewed in a terminal, piped to other tools, logged by wrappers, or captured in CI/agent execution logs. Because this skill is specifically designed to build user profiles and life stories from personal memories, the exported data is likely to be unusually sensitive and rich in identifying details.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states users can disable weekly pushes at any time, but no command or subscription-management workflow is documented to do so. That mismatch can lead to ongoing unsolicited delivery of sensitive personal summaries even after users believe they have opted out.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language content in this JSON file is entirely in Chinese, including user-facing content and tags, with no indication that language selection is optional or that the skill is explicitly region-specific. Under the stated policy, a fixed language/locale without user opt-in or documented justification can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings in the top-level documentation are presented only in Chinese, and the CLI help text throughout the file follows the same pattern. Under the language policy rule, forcing a single language without offering choice or documenting the locale constraint can be a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.