Back to skill

Security audit

agent-chronicle

Security checks for vulnerabilities and agentic risk

Overview

This diary skill is mostly coherent, but it can read and upload sensitive memory logs too broadly and has path-handling bugs that could expose or overwrite Markdown files outside the intended diary area.

Review this before installing if your memory logs contain private conversations, credentials, project plans, or relationship notes. Use only with explicit consent to send selected context to SkillBoss, prefer --emit-task or interactive/local workflows for sensitive data, avoid untrusted --date values, and treat exported HTML/PDF paths as sensitive artifacts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/generate.py:72
Finding

Sensitive Session and Persistent Memory Data Is Transmitted Without Granular Consent

Content
View full analysis
15000: content = content[:15000] + "\n\n[... truncated for context ...]" return content return None def load_recent_sessions(workspace, days=3): """Load recent session logs for context""" memory_dir = workspace / "memory" sessions = [] for i in range(days): date = datetime.now() - timedelta(days=i) date_str = date.strftime("%Y-%m-%d") session_file = memory_dir / f"{date_str}.md" if session_file.exists(): with open(session_file) as f: content = f.read() if len(content) > 5000: content = content[:5000] + "\n[... truncated ...]" sessions.append(f"## {date_str}\n{content}") return "\n\n".join(sessions) if sessions else None def load_persistent_files(workspace): """Load Quote Hall of Fame, Curiosity Backlog, etc. for context""" diary_dir = workspace / "memory" / "diary" files = {} persistent_files = [ ("quotes", "quotes.md"), ("curiosity", "curiosity.md"), ("decisions", "decisions.md"), ("relationship", "relationship.md") ] for key, filename in persistent_files: filepath = diary_dir / filename if filepath.exists(): with open(filepath) as f: ...[truncated 4953 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate.py:72
Finding

Unvalidated Date Argument Enables Path Traversal and External Disclosure of Markdown Files

Content
View full analysis
15000: content = content[:15000] + "\n\n[... truncated for context ...]" return content return None ``` ```python parser.add_argument("--today", action="store_true", help="Generate for today") parser.add_argument("--date", help="Generate for specific date (YYYY-MM-DD)") ... if args.today: date_str = datetime.now().strftime("%Y-%m-%d") elif args.date: date_str = args.date else: date_str = datetime.now().strftime("%Y-%m-%d") ``` The resulting value is later passed into the vulnerable file-loading function: ```python result = generate_ai_diary( date_str, workspace, verbose=args.verbose, emit_task=args.emit_task, ) ``` ### Technical Analysis Although the command-line help says the value must use `YYYY-MM-DD`, the program does not validate or parse the supplied value. It directly interpolates the user-controlled string into: ```python memory_dir / f"{date_str}.md" ``` `pathlib` normalizes `..` path components when the file is accessed. Consequently, an argument such as `../sensitive` targets `workspace/sensitive.md` rather than a file under `workspace/memory/`. If the selected file exists, its content is read and used as `today_log`. In the normal generation path, that content is incorporated into the prompt and sent to the external SkillBoss API. The `.md` suffix limits the direct read to Markdown-name ...[truncated 1504 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export_pdf.py:772
Finding

Unsanitized Model-Controlled HTML Can Trigger Local or Remote Resource Fetches During PDF Export

Content
View full analysis
◈
{weekday}

{month_day}

{year}
{escape(title_clean)}
{highlight_html}
{html_body}
✦ ✦ ✦
''') ``` The HTML is then rendered with a filesystem base URL: ```python html = build_html(entries) if not html: print("Failed to build HTML") return False output_path.parent.mkdir(parents=True, exist_ok=True) HTML(string=html, base_url=str(diary_path)).write_pdf(str(output_path)) ``` ### Technical Analysis Diary files can contain externally generated model output. Python-Markdown pre ...[truncated 2057 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/export_pdf.py:20
Finding

PDF Export Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (40)

Tainted flow: 'SKILLBOSS_API_KEY' from os.environ.get (line 25, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate.py (reported line 216)May include surrounding context.

python
def call_skillboss_chat(system_prompt: str, user_prompt: str) -> str:
    """Call SkillBoss API Hub /v1/pilot with type=chat and return the text content."""
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json={

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description focuses on diary generation, but the documented behavior also includes exporting, filesystem traversal, and subprocess use. This mismatch can mislead users about the true operational footprint, especially where a skill may access local memory data and invoke external tools beyond what the headline description suggests.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description focuses on diary generation, but the documented behavior also includes exporting, filesystem traversal, and subprocess use. This mismatch can mislead users about the true operational footprint, especially where a skill may access local memory data and invoke external tools beyond what the headline description suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that it gathers context from session logs and sends it to an external API endpoint for generation, but it does not present a clear, prominent privacy warning or consent step at the point of use. Because session logs may contain sensitive user content, this creates a meaningful risk of unauthorized disclosure to a third party.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/decisions.md (reported line 11)May include surrounding context.

md
*No decisions logged yet. They'll appear here from daily entries.*

<!--
Format for entries:

### [Decision Title]

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/relationship.md (reported line 11)May include surrounding context.

md
*Notes about how we work together*

<!--
Examples:
- Prefers concise responses during work hours
- Likes detailed explanations when learning something new

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly instructs users to run a script that can auto-create configuration and then persistently write diary content into local memory files, but it does not clearly warn that first use modifies the workspace and may append to existing daily logs. In an agent skill context, silent or implicit filesystem modification is risky because users may assume generation is read-only while the skill actually creates and updates durable records containing sensitive interaction data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The README states that generate.py automatically runs setup on first use, which means invoking a content-generation command can trigger additional autonomous behavior and configuration changes beyond the user's immediate request. While not inherently malicious, hidden automation reduces user control and predictability, especially for agent-operated tooling that may run unattended or inside sensitive workspaces.

Content

Scanner excerpt · README.md (reported line 53)May include surrounding context.

python3 scripts/export.py --format pdf --days 7

text

> **Note:** If no `config.json` exists, `generate.py` automatically runs the setup wizard on first use.

## Entry Structure

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and documents capabilities that read/write files, access environment variables, invoke shell commands, and make network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens user and platform understanding of what the skill can do and increases the chance of over-broad execution in environments that rely on manifest declarations for containment.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages retaining memorable quotes, frustrations, interactions, and relationship details over time. Persistent storage of user-originated statements and interaction history creates privacy and profiling risk, especially if users are not clearly informed and given control over retention.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Broad triggers like 'journal', 'quotes', 'curious', or 'daily log' can cause unintended activation during normal conversation. In this skill, accidental activation is more concerning because activation may lead to reading session logs, writing persistent memory, and potentially sending data to an external API.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generation flow directs the agent to gather session-log context and save reflective summaries, which may include sensitive user information, and the same flow can transmit that context externally. The combination of collection, transformation, persistence, and possible third-party transfer materially increases the privacy impact.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill explicitly sends session-derived content to an external API endpoint. External transmission is especially sensitive here because the documented inputs include session logs and diary material that may contain confidential user data, and the file does not clearly define minimization, redaction, or consent safeguards.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
The script will:
1. Gather context from today's session logs
2. Call `https://api.heybossai.com/v1/pilot` with `type=chat`
3. Save the generated diary entry automatically

You can also emit the raw task payload for external use:

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template instructs the agent to capture notable interactions, memorable human quotes, curiosities, decisions, and relationship dynamics for persistent memory. That normalizes long-term storage of personal and behavioral data beyond what is necessary for diary generation and can support profiling over time.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Relationship tracking and memory integration embed human-related details into broader daily memory logs, increasing persistence and spread of sensitive content across files. This raises both privacy risk and blast radius if the workspace is later searched, exported, synced, or shared.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 727)May include surrounding context.

md
- **Context Awareness:** Reads recent session logs and existing memory files for context

### v0.3.0
- **Auto-Setup:** `generate.py` now automatically runs setup wizard if no config.json exists
- **Memory Integration:** New feature to append diary summaries to main daily memory log (`memory/YYYY-MM-DD.md`)
  - Three formats: `summary`, `link`, `full`
  - Enabled by default during setup

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains very broad, common terms such as "quotes," "curious," and "decisions," which are likely to appear in ordinary conversations unrelated to diary generation. This can cause unintended skill activation, leading the agent to invoke the skill in inappropriate contexts and potentially process or expose unrelated conversation content through journaling behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a skill for generating reflective diary entries, not a tooling skill that invokes local executables. This file checks for and later relies on a system-installed binary, introducing command-execution capability that is beyond the obvious needs of diary generation itself.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export.py (reported line 64)May include surrounding context.

python
def check_pandoc():
    """Check if pandoc is installed"""
    try:
        subprocess.run(["pandoc", "--version"], capture_output=True, check=True)
        return True
    except (subprocess.CalledProcessError, FileNotFoundError):
        return False

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code writes combined diary content to a temporary markdown file and then exports it to a user-specified or default output path. Although the script prints success messages, it does not disclose beforehand that potentially sensitive diary data will be written to disk in additional files, which is a user-impacting data-handling operation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export.py (reported line 126)May include surrounding context.

python
f.write(title_content)
    
    try:
        result = subprocess.run([
            "pandoc",
            str(temp_md),
            "-o", str(output_path),

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/export.py (reported line 138)May include surrounding context.

python
if result.returncode != 0:
            # Try without xelatex
            result = subprocess.run([
                "pandoc",
                str(temp_md),
                "-o", str(output_path),

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

The HTML export path generates output that embeds a remote CSS URL from a CDN. Although the subprocess invocation itself is not shell-injectable, the resulting artifact causes network-dependent behavior when opened, which can leak access metadata and violates expectations for a local diary export containing sensitive personal content.

Content

Scanner excerpt · scripts/export.py (reported line 163)May include surrounding context.

python
f.write(content)
    
    try:
        result = subprocess.run([
            "pandoc",
            str(temp_md),
            "-o", str(output_path),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The exported HTML references a remote CSS resource without warning, so opening a diary file can trigger unsolicited outbound requests. Because diary entries are highly sensitive by nature, this creates an avoidable privacy leak and breaks the expectation that export is an offline local operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The --debug-html path writes the full rendered diary as plaintext HTML alongside the PDF, which can expose sensitive journal content to users or processes that would otherwise only handle the PDF artifact. In this skill context, diary entries are explicitly personal and reflective, so creating an additional unencrypted, easily searchable artifact materially increases privacy and data-retention risk even if the behavior is user-invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.