T06 · System Persistence
- Location
scripts/setup-cron.json:4- Finding
Persistent Scheduled Agents Receive Broad Workspace and Session Capabilities
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent self-improvement memory system, but it asks for persistent jobs that can read conversations and modify durable agent instruction files.
Install only if you intentionally want a persistent self-improvement system that can read conversation history, store local memories, and update agent control-plane files. Before enabling cron, review every job, disable jobs you do not need, remove broad tools such as exec/write/edit where possible, set an explicit session key, avoid raw transcript capture, and require human review before anything is promoted into AGENTS.md, SOUL.md, USER.md, TOOLS.md, or skills.
scripts/setup-cron.json:4Persistent Scheduled Agents Receive Broad Workspace and Session Capabilities
scripts/memory-pipeline.py:87Conversation Transcripts Are Automatically Copied to Plaintext Workspace Files Without Redaction
scripts/learnings.py:1197Untrusted Lesson Content Can Be Promoted into Durable Agent Instruction Files
scripts/daily-memory.sh:56User-Configurable Collector Command Is Evaluated by a Login Shell
The skill advertises a bounded memory/self-improvement workflow, but its documented behavior extends into broad ingestion of conversation content, durable modification of control-plane files, and automated background processing that is more powerful than the headline description suggests. This mismatch is dangerous because operators may approve or install it under a narrower trust assumption while it actually performs persistence and synthesis across multiple files and sessions.
Referenced artifact was not completely inspected
- `hooks/activator.sh` as a pre-prompt / prompt-start reminder.
Referenced artifact was not completely inspected
- `hooks/activator.sh` as a pre-prompt / prompt-start reminder.
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
| **actual-self-improvement** | Execution core | Python CLI (`scripts/learnings.py`), structured logging, JSON evals, search-before-log dedupe |
Referenced artifact was not completely inspected
bash scripts/extract-skill.sh my-skill-name /absolute/path/to/workspace
The README explicitly describes automated or semi-automated writes to workspace state, including memory files and root control-plane Markdown files, but the warning about modification scope and operational risk is limited and easy to miss. In an agent skill that influences files like AGENTS.md, TOOLS.md, MEMORY.md, and related control-plane state, insufficiently prominent warnings can lead users to enable automation that alters agent behavior, persistence, or safety-relevant instructions without fully understanding the blast radius.
The skill explicitly instructs use of shell commands, file reads/writes, environment variables, cron setup, and modification of durable workspace files, but it declares no tool scope or permissions boundary. That creates an over-privileged, ambiguous execution model where a host agent may grant broader capabilities than users expect, increasing the risk of unintended file mutation, persistence, or command execution.
The skill directs collection and persistence of recent conversation content into local files and summaries, creating a durable transcript-derived memory store. Even though it says to skip secrets and hidden thinking, this kind of automated capture materially increases privacy and data-retention risk because user-provided sensitive content can be copied into searchable local storage, exports, and cron-generated artifacts.
The smoke-test command explicitly uses TZ=Asia/Shanghai, which imposes a specific locale/timezone behavior in the instructions. This is a natural-language policy concern because the skill elsewhere presents itself as generally portable, but this example can steer users or agents into a specific locale without opt-in.
The routing guidance explicitly instructs storing user facts and preferences in persistent memory files such as MEMORY.md and daily notes. That is contextually aligned with the skill's purpose, but it still creates a real privacy vulnerability because personal preferences, profile data, and system state may accumulate indefinitely in plaintext workspace files without clear retention, access control, or consent enforcement.
No suspicious patterns detected.