Back to skill

Security audit

Looki Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill provides a disclosed Looki memory API integration, but users should treat it as highly sensitive because it can access wearable-derived personal history and stores an API key in a local config file.

Install only if you intentionally want your agent to query Looki wearable memory data. Before use, confirm the base URL, restrict requests to specific dates or questions, avoid sharing sensitive journal or media details unless needed, and ensure ~/.config/looki/credentials.json is protected with owner-only permissions or use a secret manager if available.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:10
Finding

Plaintext API Key Storage Without Required File Permission Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–31
Vulnerability Type: Plaintext credential storage with insufficient permission requirements
Risk Level: Medium

Vulnerable Code

markdown
**Base URL:** Read from `~/.config/looki/credentials.json` → `base_url` field. If the file does not exist, ask the user for both `base_url` and `api_key`.

**Security:**

- Before first use, validate the `base_url` by sending a GET request to `https://open.looki.ai/api/v1/verify?endpoint={base_url}`. Do not include the API key in this request. If validation fails, inform the user and do not proceed.
- Only send the API key in the `X-API-Key` header to `{base_url}/*` endpoints. Do not send it to any other domain.
- Do not save the API key to agent memory, chat history, or any location other than `~/.config/looki/credentials.json`.

## Setup

**Credentials file:** `~/.config/looki/credentials.json`

On first use, check if this file exists. If it does, read `base_url` and `api_key` from it. If it does not, ask the user for both values and offer to save them to this file.

```json
{
    "base_url": "<YOUR_BASE_URL>",
    "api_key": "<YOUR_API_KEY>"
}
  • base_url — The API endpoint URL provided by the user. Do not assume a default; always ask the user if not already saved.
  • api_key — The user's Looki API key, starting with lk-.

Credentials should only be stored in this file. Do not save the API key to agent memory, environment variables, or any other persistent storage.

text

### Technical Analysis

The Skill instructs the Agent to persist the Looki API key as plaintext JSON in `~/.config/looki/credentials.json`, but it does not require owner-only permissions for either the containing directory or the file. The actual access mode may therefore depend on the Agent's file-writing implementation and the process umask.

If the file is created with overly broad permissions, another local account or process may read the API key. The 
...[truncated 2306 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require creation of ~/.config/looki with owner-only permissions (0700).
  2. Create credentials.json atomically with mode 0600, rather than relying on the process umask.
  3. Refuse to read a credentials file that is group-readable, world-readable, owned by another user, or not a regular file.
  4. Reject symbolic links for both the credentials file and relevant parent path components.
  5. Write credentials through a securely created temporary file in the same protected directory, set its permissions, flush it, and atomically rename it into place.
  6. Prefer an operating-system credential manager or secret store when available, retaining the file only as a documented fallback.
  7. Avoid printing the key in commands, logs, diagnostics, errors, or tool-call transcripts.
  8. Preserve the existing controls that validate base_url without the key and restrict X-API-Key transmission to the validated endpoint.
  9. Document API-key rotation and revocation procedures for suspected exposure.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description does not prominently warn that it accesses extremely sensitive real-world surveillance-style data, including location, conversations, encounters, journals, and realtime events. Without an explicit privacy warning, users may authorize or trigger the skill without understanding the scope of data exposure and the downstream risk of overcollection or disclosure in responses.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
Looki gives you a digital memory captured by the Looki L1 wearable, which sees and hears moments throughout your day. This skill lets AI assistants access your real-world context — the places you went, the people you met, and the things you did — so they can help in ways that go beyond what's on your screen. Use it when you want more personalized, context-aware, data-driven responses.

**Base URL:** Read from `~/.config/looki/credentials.json` → `base_url` field. If the file does not exist, ask the user for both `base_url` and `api_key`.

**Security:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
Looki gives you a digital memory captured by the Looki L1 wearable, which sees and hears moments throughout your day. This skill lets AI assistants access your real-world context — the places you went, the people you met, and the things you did — so they can help in ways that go beyond what's on your screen. Use it when you want more personalized, context-aware, data-driven responses.

**Base URL:** Read from `~/.config/looki/credentials.json` → `base_url` field. If the file does not exist, ask the user for both `base_url` and `api_key`.

**Security:**

Credential Access

High
Category
Privilege Escalation
Confidence
76% confidence
Finding

Instructing the agent to automatically check for and read ~/.config/looki/credentials.json creates a local secret-access behavior that may occur without a fresh, explicit user prompt at time of use. Even though intended for convenience, automatic file access to retrieve API credentials increases the chance of overbroad secret access and normalizes agent-side reading of local sensitive files.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
## Setup

**Credentials file:** `~/.config/looki/credentials.json`

On first use, check if this file exists. If it does, read `base_url` and `api_key` from it. If it does not, ask the user for both values and offer to save them to this file.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is framed for broad personalization and context-aware help, which can cause it to activate on vague user requests that do not clearly indicate informed consent to access highly sensitive wearable-derived memory. Because the underlying data includes places visited, people met, and things done, accidental invocation can expose intimate personal history beyond what the user expected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.