Back to skill

Security audit

永久记忆系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is a persistent memory logger that is mostly purpose-aligned, but it stores and reloads broad conversation data, including private details, without clear consent, minimization, or safety boundaries.

Review before installing. Only use this skill if you are comfortable with conversations and private details being saved locally and reused later. Avoid entering secrets, credentials, regulated data, or sensitive personal information unless the skill is redesigned with explicit opt-in, review/delete controls, sensitive-data filtering, and safeguards that treat saved memory as untrusted data.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:17
Finding

Persistent Prompt Injection Through Untrusted Conversation Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/archive.py:10
Finding

Unencrypted Indefinite Storage of Conversations and Sensitive Personal Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (24)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown advertises automatic persistent storage into local files but does not present a clear warning that conversation data will be written and retained. Without upfront notice and consent framing, users may disclose sensitive information believing the conversation is ephemeral when it is actually being archived permanently.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly states that every conversation is automatically recorded, semantically searchable, and preserved across restarts, establishing a persistent data collection and reuse channel. In the context of an agent skill, this is dangerous because it normalizes blanket retention of user-provided content, including potentially sensitive credentials, personal data, or confidential business information, without visible minimization or consent controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The usage section promotes automatic behavior but does not prominently warn users that conversations will be persistently written to memory files and reused later. This creates a privacy and trust risk because users may disclose secrets or personal information assuming a normal transient chat, not durable storage.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The usage instructions say that telling the agent important things will automatically write them to memory and that new sessions will automatically load prior memory context. This creates a durable cross-session instruction and data flow that can unintentionally reintroduce stale, sensitive, or user-specific information into later conversations, increasing privacy leakage and context-poisoning risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

Describing a date-partitioned 'original conversation diary' strongly implies retention of raw dialogue history rather than minimized summaries. Raw transcript storage materially increases the blast radius of accidental collection because any sensitive user input may be preserved indefinitely and become searchable or reloadable later.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description significantly overstates the code's functionality. The code does implement a basic archival mechanism for memory entries in a persistent local file, which partially aligns with 'memory archiving.' However, it does not automatically record conversations, does not perform semantic search, does not implement conversation-triggered behavior, and does not provide any actual cross-session retrieval/inheritance logic. Additionally, although intended to append, the script rewrites the whole file when adding an entry to an existing category, so the '永不覆盖' claim is inaccurate. Overall, the actual behavior is a narrow manual file append utility, not the broader automatic permanent memory system described.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states that important conversation data will be permanently written to local memory files, but it does not provide a clear privacy warning or informed-consent flow. Silent persistence of user data is dangerous because users may disclose sensitive information under the assumption that the session is ephemeral.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs immediate in-conversation writes of important user information into persistent memory and later reuse in future sessions. Real-time durable storage of user-provided data is dangerous because it can capture sensitive details before the user understands or approves the retention behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs storing private data such as contact details and addresses without requiring consent, minimization, or any sensitivity checks. Persisting real-world identifiers raises the risk of privacy violations, data leakage, and regulatory noncompliance if the files are later exposed or reused inappropriately.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs the agent to permanently retain all conversation content, including private contact and address data, across sessions. In this context, persistent cross-session storage without strict consent and minimization creates a significant privacy and data-handling risk, especially because the retained files become a long-lived target for unauthorized access or accidental reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation says all dialogue, including casual chat, is logged to dated memory files, yet no warning or opt-in is provided for this comprehensive capture. Blanket retention greatly expands the amount of sensitive or incidental personal data collected and stored across sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listing markets permanent recording of every conversation and append-only retention with no minimization, overwrite, or expiry. That creates a strong semantic instruction toward indiscriminate long-term storage of all user-provided data, which is especially dangerous for a cross-session memory skill because it can accumulate sensitive information, increase breach impact, and make accidental disclosure persist indefinitely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listing explicitly promises that every conversation is automatically and permanently recorded, but provides no warning, consent flow, retention limits, or guidance about sensitive data. In a memory skill, this broad default capture can lead to unintentional storage of secrets, personal data, or regulated information across sessions and devices.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The listing uses broad trigger phrasing such as asking whether the system 'remembers last time,' which can cause the skill to activate in situations the user may not intend. In a memory skill, ambiguous retrieval triggers increase the chance of pulling or acting on stored conversation data without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Claims that the system remembers everything the user says and archives every conversation imply extremely broad retention with no visible minimization, purpose limitation, or consent controls. In the context of a cross-session memory skill, that makes overcollection especially dangerous because sensitive personal, business, or security-relevant information can accumulate and remain searchable over time.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Describing archival as occurring automatically after every conversation without clear constraints signals persistent storage of user content by default. That behavior is dangerous because it can capture sensitive information, credentials, personal data, or confidential project details without an explicit opt-in boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The entire skill documentation and all example invocations are presented only in Chinese, with no indication that other languages are supported or that this locale restriction is optional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README defines automatic activation in very broad terms such as 'tell the agent important things' and 'new session automatically loads memory context' without clear boundaries, consent gates, or scoping rules. Ambiguous triggers in a persistence skill are dangerous because they can cause over-collection, unexpected retention, and unintended recall of sensitive user data across sessions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill clearly instructs reading and writing persistent local files (MEMORY.md and memory/*.md) but does not declare any tool scope or permissions boundary. That makes the capability opaque to users and reviewers, and increases the risk of unintended file access or silent persistence of sensitive data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases for activation are extremely broad ('memory/history/previously said/remember what'), so the skill may activate during ordinary conversation without clear user intent. In a persistence-oriented skill, overbroad activation materially increases the chance of collecting and retaining data users did not expect to store.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example memory format stores '回复语言:中文', which suggests a fixed language preference in the skill's documented behavior. Because there is no indication that language is user-selected or optional, this may violate language/locale choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s docstrings and user-facing CLI messages are entirely in Chinese, which imposes a specific language choice on users without offering any alternative or opt-in. This is a natural-language policy concern because the skill does not document that it is intentionally Chinese-only or provide locale selection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script writes user-provided content into a long-lived file under the user's home directory with no consent prompt, visibility control, or retention limits. In the context of a 'permanent memory' skill that auto-archives conversations across sessions, this can silently persist sensitive personal, credential, or proprietary data beyond the user's expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The invocation language is broad enough that users may expect the skill to trigger on vague references like prior decisions or memory-related phrases without clear boundaries. In a system that stores conversation history permanently, ambiguous triggers increase the risk of over-collection and unexpected activation, especially when users do not realize what content will be archived or recalled.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.