Back to skill

Security audit

agent-chronicle

Security checks for vulnerabilities and agentic risk

Overview

This diary skill is purpose-aligned but needs Review because it can read personal session and memory content, send it to an external API, and persist profile-like notes without clear safeguards.

Install only if you are comfortable with diary generation using your session logs and memory files, including possible transmission of that context to SkillBoss API Hub. Before use, review or disable memory integration, avoid storing sensitive quotes or relationship notes, prefer dry-run or payload preview where available, and do not run generation on workspaces containing secrets or confidential conversations unless you have verified redaction and data handling.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.md:75
Finding

Uncontrolled Transmission of Sensitive Session and Memory Data to a Third-Party API

Content
View full analysis

Vulnerability Details

File Location: skill.md, lines 75-93; related privacy and context-handling statements at lines 652-658 and 716-729
Vulnerability Type: Sensitive data exposure through external API processing
Risk Level: Medium

Vulnerable Documentation Snippet:

markdown
#### Recommended: Direct generation via SkillBoss API Hub

This skill calls SkillBoss API Hub (`/v1/pilot`) directly for AI generation.
Set `SKILLBOSS_API_KEY` and run:

```bash
python3 scripts/generate.py --today

The script will:

  1. Gather context from today's session logs
  2. Call https://api.heybossai.com/v1/pilot with type=chat
  3. Save the generated diary entry automatically
text

Related claims and behavior include:

```markdown
## Privacy

- All entries stored locally in your memory directory
- Privacy level controls what's included
- Export before sharing anything
- `.gitignore` excludes config.json and exports by default
markdown
- **Context Awareness:** Reads recent session logs and existing memory files for context

Technical Analysis

The documented generation workflow reads recent session logs and existing memory files and then calls the external endpoint https://api.heybossai.com/v1/pilot. These sources can contain confidential conversations, personal information, project details, user quotations, relationship notes, decisions, or credential-like strings.

The documentation does not define an explicit consent boundary, data-field allowlist, secret-detection mechanism, redaction process, payload-size limitation, payload preview requirement, or third-party retention and deletion policy. The available --emit-task option can expose a payload for review, but it is optional rather than a mandatory safeguard.

The statement that all entries are stored locally only describes generated entry storage and does not clearly disclose that source context is transmitted to an extern ...[truncated 2370 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed opt-in before sending any session or memory content to an external API. Keep remote generation disabled by default.
  2. Clearly disclose which files and fields are read, which data is transmitted, the destination hostname, and the provider's retention and deletion policies.
  3. Apply data minimization through a strict allowlist. Do not submit complete session logs or memory files when a bounded summary is sufficient.
  4. Run secret and sensitive-data redaction before constructing the request. Remove API keys, tokens, passwords, private keys, credentials, personal identifiers, and unrelated conversation content.
  5. Make payload preview and confirmation mandatory for the first request and whenever additional source files or categories are selected.
  6. Ensure privacy levels control both generated output and outbound source context. Document the exact filtering rules for each level.
  7. Provide a fully local or interactive generation mode that does not contact third-party services.
  8. Make memory integration opt-in, especially the full format, and warn users that it duplicates potentially sensitive material.
  9. Document request authentication, certificate verification, timeout behavior, logging controls, third-party subprocess behavior, and error handling.
  10. Include the referenced scripts in the auditable package so reviewers can verify file-access boundaries, request construction, redaction, credential handling, and safe persistence behavior.
  11. Revise the privacy section to distinguish local output storage from external processing of source context and generated content.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages persistent collection of memorable human statements and relationship details as part of a diary system. Persistently storing user-derived content increases privacy risk, especially when the same content may later be reused in outputs or sent to an external generation service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes generic phrases like 'journal', 'daily log', and 'quotes', which may cause the skill to activate during unrelated conversations. Unintended activation is dangerous here because the skill is designed to collect, summarize, and persist personal interaction data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that it gathers context from today's session logs and sends a request to an external API, but this flow is not paired with an immediate, explicit privacy warning at the point of use. Users may unknowingly cause sensitive transcripts, quotes, or relationship notes to be transmitted to a third party.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This behavior combines two risky actions: collecting session-log context and incorporating memorable human statements into generated diary entries. Because the generation path uses an external API, sensitive user content can be both persisted locally and disclosed to a third party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The skill explicitly transmits gathered session-log context to https://api.heybossai.com/v1/pilot for diary generation. External transmission of conversational history and personal reflections is a real privacy and data-exposure risk, particularly given the diary's focus on emotional and relationship content.

Content

Scanner excerpt · skill.md (reported line 91)May include surrounding context.

md
The script will:
1. Gather context from today's session logs
2. Call `https://api.heybossai.com/v1/pilot` with `type=chat`
3. Save the generated diary entry automatically

You can also emit the raw task payload for external use:

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The feature set persistently stores quotes, curiosities, decisions, and relationship-related content in memory files, creating a growing profile of the user and their interactions. Such longitudinal storage can expose sensitive personal information if accessed by other tools, future prompts, or unauthorized parties.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Relationship tracking explicitly directs the skill to capture communication style, inside jokes, recurring themes, and learned preferences in persistent memory. This is effectively behavioral profiling of the user, which becomes more sensitive over time and may be reused outside the user's expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation makes a materially misleading privacy claim: it says entries are stored locally, while elsewhere the skill explicitly states that session-log context is sent to the external SkillBoss API for generation. This can cause users to disclose sensitive interaction history under the false assumption that processing is entirely local.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 724)May include surrounding context.

md
- **Context Awareness:** Reads recent session logs and existing memory files for context

### v0.3.0
- **Auto-Setup:** `generate.py` now automatically runs setup wizard if no config.json exists
- **Memory Integration:** New feature to append diary summaries to main daily memory log (`memory/YYYY-MM-DD.md`)
  - Three formats: `summary`, `link`, `full`
  - Enabled by default during setup

Static analysis

No suspicious patterns detected.