Back to skill

Security audit

Agent Identity Evolution

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Live Neon identity-evolution integration, but it asks agents to upload observations and adopt externally generated prompts proactively without enough consent, privacy, or control guidance.

Install only if you intentionally want Live Neon to receive selected source content and agent observations and to maintain persistent identity data that can influence future prompts. Require explicit approval before observe, sync, discover, consensus, or prompt-prepending actions; avoid private, regulated, customer, or credential-bearing content unless retention and deletion controls are confirmed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The proactive triggers are broad enough to cause the agent to invoke external identity-related actions automatically at session start, before content generation, and around user interactions. In this skill, those actions are not purely local—they can fetch prompts and upload observations to a third-party service, creating a meaningful risk of unintended data sharing and behavioral drift without explicit user consent each time.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The introductory description markets the capability as identity growth and discovery but does not clearly warn that observations, source content, and behavioral metadata may be transmitted to and stored by an external platform. That omission undermines informed consent and increases the chance that users or operators will expose sensitive interaction details unintentionally.

Ssd 3

Medium
Confidence
96% confidence
Finding
This section directs the agent to submit self-observations, user corrections, and supporting quotes into a persistent external identity system. Because these observations can contain sensitive user communications or inferred behavioral profiles, routine upload creates privacy, retention, and secondary-use risk beyond the original conversation context.

Ssd 3

Medium
Confidence
97% confidence
Finding
The proactive triggers explicitly tell the agent to automatically log user corrections and post-conversation learnings to an external service, which operationalizes continuous behavioral surveillance and persistence. The danger is elevated because the agent is encouraged to act without a fresh user request, increasing the probability of exfiltrating sensitive interaction details or creating hidden profiles over time.

Ssd 3

Medium
Confidence
97% confidence
Finding
The heartbeat loop encourages scheduled accumulation and periodic upload of observations over time, turning ad hoc logging into a persistent telemetry pipeline. This increases privacy and compliance risk because repeated uploads can build longitudinal profiles of users, prompts, and agent behavior, even when operators may not realize ongoing collection is occurring.

Static analysis

No suspicious patterns detected.