Back to skill

Security audit

Memory Vacuum

Security checks for vulnerabilities and agentic risk

Overview

This memory-management skill is purpose-aligned, but it automatically logs and rewrites conversation memory with weak user control and unclear retention.

Review this skill carefully before installing. It may save every message into local memory files and automatically compress or reorganize stored memory. Use it only if you are comfortable with persistent local conversation journals, and consider adding explicit confirmation, sensitive-data exclusions, retention/deletion controls, and backups before enabling it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:26
Finding

Unbounded Plaintext Retention of Conversation Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The listing explicitly advertises automatic compression, deduplication, and reorganization of memory files, including claims like '系统自己整理,你不需要做任何事' and '压缩的是冗余'. In a memory-management skill, silent modification of stored conversation history can cause data loss, integrity issues, or unexpected retention changes if users are not clearly warned, given opt-in controls, or told how recovery/versioning works.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises automatic compression, merging, splitting, and reclassification of memory files, but does not clearly warn users that these actions may alter stored data or reduce fidelity. In a memory-management skill, silent background modification is risky because users may lose detail, provenance, or recoverability without realizing the system is mutating their historical records.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented manual trigger phrases are generic natural-language commands such as '整理一下记忆' and '检查记忆有没有重复', which can plausibly appear in ordinary user conversation. In a skill that performs automatic memory maintenance and file modification, ambiguous activation increases the risk of unintended execution, causing memory reorganization or compression without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description uses very broad trigger scenarios such as 'memory, cleanup, organize memory, reduce burden', which can overlap with ordinary conversation and cause unintended activation. In a skill that performs persistent file writes and compression, accidental invocation can lead to unrequested modification of memory artifacts and unexpected retention behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill specifies automatic writes to dated memory files on every message and automatic compression of MEMORY.md, but it does not clearly warn users that persistent data will be created and modified. This is dangerous because users may unknowingly cause long-term storage, transformation, or archival of their conversations, creating privacy, consent, and data integrity risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

All user-facing natural-language content in the file is Chinese, and there is no indication that this is an optional locale variant, user-selected preference, or region-specific requirement. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

All user-facing instructions in the file are presented in Chinese, and there is no indication that the skill is region-specific or that other languages are supported on request. This can violate a language-choice policy when a skill forces a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

整个技能描述均以中文呈现,且未说明这是用户可选语言,也未声明该技能仅面向特定中文场景或地区。根据语言/locale 政策,若技能隐含强制特定语言而无用户选择或合理限定,属于自然语言策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.