Back to skill

Security audit

personal-context-manager

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate local journaling/context-management skill, but it stores sensitive personal context and includes a cleanup script that can delete user notes without strong safeguards.

Install only if you are comfortable with this skill creating long-lived local records of personal reflections and imported conversations. Before using entropy reduction, run it in dry-run mode and review candidates manually; avoid --force unless you have backups. Redact secrets and third-party private information before saving content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description emphasizes user-facing context management features: recording triggers, organizing cognition, building knowledge connections, and added sprouting/journal functions. The supplied code instead implements an 'entropy reduction' maintenance script. Its main behavior is to inspect markdown files under journal/ and external/, score them as low value using fixed heuristics, produce a deletion candidate list, optionally delete those files with --force, and ensure a core/minimal-kernel file exists. While this is loosely adjacent to context management, the primary function is cleanup and file deletion, which is a significant undeclared capability. The code does not implement the advertised sprouting types or observer-feedback journal features. Therefore the description does not accurately represent the actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly stores personal journal entries, internal judgments, and imported external conversations, but provides no privacy warning, sensitivity guidance, retention notice, or consent boundary. In a journaling/context-management skill, this omission is especially risky because the expected data often includes intimate thoughts, behavioral patterns, and third-party communications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script can permanently delete personal journal and external note files when run with --force, based on weak heuristics such as missing 'inner judgment', zero graph connections, or age over 90 days. In a personal-context skill, this is dangerous because the criteria are subjective and lossy, so valuable user data may be destroyed without robust safeguards, review workflow, backup, or consent-oriented design.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents broad natural-language invocation examples such as journaling, saving content, and generating maps without defining clear activation boundaries or confirmation requirements. In a context-management skill that stores and synthesizes personal information, ambiguous triggers can cause accidental activation, unintended capture of sensitive data, or unexpected persistence of user content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages users to record personal reflections and save external content, but the README does not warn that these inputs may contain highly sensitive personal, behavioral, or third-party information. Because the skill's purpose is long-term context accumulation and knowledge integration, lack of disclosure increases the risk of users unknowingly storing private data that could later be exposed, over-retained, or mishandled.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are overly broad everyday language, which can cause the skill to activate when the user did not intend persistent journaling or knowledge capture. In this skill's context, unintended invocation is more dangerous because activation can lead to collection, structuring, and storage of sensitive personal reflections and third-party conversation content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description, trigger phrases, workflow text, and required output formats are all presented only in Chinese, and the examples instruct interaction in Chinese without any opt-in or language-selection option. This creates a natural-language locale constraint that may violate language-choice policy when the skill is presented as a general-purpose tool.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow instructs the agent to persist personal context and imported external conversations into long-term storage, creating meaningful confidentiality and retention risk. This is dangerous because users may save sensitive diary content, relationship details, work chats, or third-party messages in plaintext without minimization or safeguards.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 'minimal kernel' extraction process scans all notes to build a condensed profile of the user's principles, beliefs, decision mechanisms, and focus areas. That creates an especially sensitive aggregated dossier: even if individual notes seem harmless, the synthesized profile can reveal identity, vulnerabilities, values, routines, and decision patterns in a compact, high-value form.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Repeatedly scanning all notes to generate maps, summaries, and feedback increases the chance that private data will be surfaced, recontextualized, or exposed in broader outputs. In this skill, the context makes it more dangerous because summarization can combine intimate notes and external conversations into derived artifacts that are easier to read, share, or leak than the raw source material.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The invocation example '帮我保存这个' is highly ambiguous and overlaps with ordinary conversation, making accidental activation likely. Because the skill persists content to disk and may organize external messages, a mistaken trigger can result in unintended retention of private or sensitive information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill in that locale without any indication that other languages are supported or that Chinese is required for a region-specific purpose. This can violate language/locale policy expectations when a skill is distributed broadly but implicitly constrained to one language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase is overly broad and the notes explicitly say the skill would activate on the generic keyword “知识,” which can match many unrelated requests. This can cause the skill to intercept prompts outside its intended scope, leading to unintended file operations, privacy-invasive context capture, or incorrect handling of user requests in a context-management workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section explicitly instructs the agent to create persistent storage directories and write user-related data, but it does not require any user notice, confirmation, or consent before modifying the filesystem. In a context-management skill handling personal journals and knowledge artifacts, silent persistence can surprise users, create privacy risks, and normalize later destructive operations such as the mentioned delete-confirmation flow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section defines automatic storage of bridge records to timestamped files, which creates persistent records linking external information with the user's internal judgments. Because the skill is explicitly about personal context, cognition, and journaling, storing these sensitive reflections without a clear warning or consent mechanism increases privacy exposure and the risk of unintended long-term retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prompt explicitly expects automatic tagging, storage, and journal file generation without indicating that the user will be informed or asked to confirm file writes. In a context-management skill handling personal reflections, silent persistence increases privacy risk and can surprise users with durable storage of sensitive content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt expects the skill to accept an external URL, retrieve or process linked content, and store results under external/ without warning about network access or local persistence. This can expose users to unexpected outbound requests, ingestion of untrusted content, and silent storage of third-party material tied to the user's notes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt calls for scanning all notes, identifying high-value judgments, and generating a new summary file, but gives no indication of user consent for broad data access or derived-file creation. Because this skill manages personal context, unrestricted note scanning can aggregate sensitive information and produce secondary artifacts the user did not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrase example “帮我管理一下知识” is overly broad and can match ordinary conversational requests that are not specifically asking to invoke this skill. In an agent setting, this can cause unintended activation, leading the skill to collect, organize, or persist user content when the user may have expected only general assistance.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module documentation frames the script as recognizing and cleaning low-value content while preserving core cognition. However, the implementation unconditionally creates a default minimal-kernel file if missing, which is additive content generation rather than merely cleaning existing content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file includes its top-level description, usage guidance, and most user-facing output in Chinese, but does not indicate that the language is optional or limited to a China-specific use case. That creates a natural-language locale policy concern because the skill effectively imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script automatically creates or updates a core profile file (minimal-kernel.md) even though the described function is entropy reduction of existing content. Silent mutation of a user's core/context files is risky in this skill because it changes persistent personal data and may overwrite expectations about what the tool is allowed to create or maintain.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All slogans, usage instructions, and example invocations are presented only in Chinese, which implicitly constrains interaction language without documenting that limitation or offering alternatives. Under the stated policy, a skill should not force a specific language or locale unless the constraint is explicit and justified or users are given a choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The ambiguity-handling guidance says the assistant should present only four core options: record journal, save external info, refine minimal kernel, and generate a cognitive map. Elsewhere in the same file, the skill explicitly defines two additional user-triggerable capabilities: sprouting and diary feedback. This is an active documentation-level contradiction about what options the skill should surface to users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is entirely in Chinese and provides no indication that the skill supports other languages or lets the user opt into this locale. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.