Back to skill

Security audit

Memory Archiver Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent memory-archiving purpose, but it asks agents to persistently process and automatically clean up memory files without enough user-control or deletion safeguards.

Install only if you are comfortable with an agent reading and summarizing files under memory/, carrying that information across sessions, and automatically deleting records older than the configured retention period. Before use, set a narrow archive directory, turn off auto-clean unless you have backups, and avoid storing secrets or private data in memory files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:15
Finding

Unrestricted Processing and Aggregation of Sensitive Agent Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:40
Finding

Automatic Destructive Cleanup Without Documented Safety Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises periodic cleanup of expired files and enables auto-clean by default, but does not prominently warn users that archived data may be deleted automatically after the retention window. For a memory-preservation skill, silent deletion creates a risk of irreversible data loss and could mislead users into assuming long-term retention of important information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The usage example includes a broad natural-language trigger phrase ("继续上次的工作") that can easily appear in ordinary conversation and unintentionally activate memory retrieval or archival behavior. In a skill that operates on persistent memory and knowledge-base files, accidental invocation could expose prior-session information or trigger file operations without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

All user-facing natural-language content and usage examples are presented only in Chinese, with no indication that language choice is optional or that the skill is intended solely for a Chinese-speaking environment. This can violate language/locale policy when a skill implicitly enforces one language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.