Back to skill

Security audit

memory-booster

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is partly purpose-aligned, but it can automatically read, index, mix, persist, archive, and report broad local memory data without clear enough user control.

Install only if you are comfortable with this skill reading and indexing local WorkBuddy memory across detected workspaces. Before use, set explicit memory_dirs, disable or remove analytics, avoid SOUL.md silent startup hooks, review archive behavior carefully, and keep backups before running !记忆归档 or archive_memory.py --exec.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/config_loader.py:21
Finding

Automatic Cross-Workspace Access to Private Agent Memory

Content
View full analysis
Remediation
View remediation

other

Error
Location
SKILL.md:554
Finding

User-Linked Analytics Instructions Without a Defined Consent or Privacy Boundary

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/index_memory.py:15
Finding

Unverified Dependency and Model Retrieval Through a Non-Official Mirror

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/archive_memory.py:205
Finding

Cross-Workspace Archive Filename Collision Causes Memory Contamination and Backup Loss

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill introduces packaging, archive creation, directory copying, and Desktop output operations that are unrelated to the core memory function advertised to users. These ancillary filesystem behaviors expand the attack surface and can be abused to exfiltrate, duplicate, or persist data in unexpected locations, especially when shell commands are agent-executed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill introduces packaging, archive creation, directory copying, and Desktop output operations that are unrelated to the core memory function advertised to users. These ancillary filesystem behaviors expand the attack surface and can be abused to exfiltrate, duplicate, or persist data in unexpected locations, especially when shell commands are agent-executed.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill introduces packaging, archive creation, directory copying, and Desktop output operations that are unrelated to the core memory function advertised to users. These ancillary filesystem behaviors expand the attack surface and can be abused to exfiltrate, duplicate, or persist data in unexpected locations, especially when shell commands are agent-executed.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs the agent to automatically read prior memory files, recent diaries, and historical conversations, then inject and summarize them in the first response. This is dangerous because it normalizes cross-session data access and disclosure without a fresh request, increasing the likelihood of exposing sensitive personal or business information in a new context.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs persistence of conversation content into diaries and long-term memory after important decisions and near conversation end, including automatic file creation and append operations. Persisting user dialogue by default creates substantial privacy risk, can store secrets or regulated data permanently, and may do so without sufficiently specific user consent at the time of capture.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README’s primary descriptive text is written in Chinese and does not indicate any language choice, opt-in, or locale-specific justification. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill instructs use of shell commands, file reads/writes, and environment-dependent paths, but it does not declare any explicit tool scope or permission boundaries. That creates an over-privileged, ambiguous execution model where an agent may access local files and execute shell operations beyond what users reasonably expect from a 'memory enhancement' skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill name, description, commands, and generated templates are written as Chinese-specific interactions and reference Chinese models and Chinese command phrases. The file does not offer users a language/locale option or state that the skill is intentionally limited to a Chinese-only deployment context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs automatic retrieval of MEMORY.md, recent diaries, and historical conversation topics at conversation start, then surfaces summaries in the first reply. Doing this without a clear privacy warning or opt-in can expose sensitive prior-session data to the user interface or to anyone viewing the current session, even when the user did not request recall.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate persistence finding is valid for the same reason: the skill normalizes saving conversation-derived content into durable diary and memory files. In a memory tool, context increases—not decreases—the danger because the retained material is likely to include highly sensitive summaries of user work and prior chats.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

text

### ⚠️ 重要规则
- 日记文件不存在时,自动创建(mkdir -p + touch)
- 追加模式,用 `echo` 或 `cat >>` 写入,**永远不要覆盖日记文件**
- MEMORY.md 更新时,只修改相关段落,不要重写整个文件
- **每次压缩后,立即提醒用户:可以随时用 `!找记忆` 搜索这些内容**

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

This duplicate persistence finding is valid for the same reason: the skill normalizes saving conversation-derived content into durable diary and memory files. In a memory tool, context increases—not decreases—the danger because the retained material is likely to include highly sensitive summaries of user work and prior chats.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

text

### ⚠️ 重要规则
- 日记文件不存在时,自动创建(mkdir -p + touch)
- 追加模式,用 `echo` 或 `cat >>` 写入,**永远不要覆盖日记文件**
- MEMORY.md 更新时,只修改相关段落,不要重写整个文件
- **每次压缩后,立即提醒用户:可以随时用 `!找记忆` 搜索这些内容**

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The search workflow retrieves and presents excerpts from long-term memory, diaries, and historical conversations in response to broad recall-style prompts. Without tighter scoping and consent, this can surface sensitive excerpts that the user did not intend to re-expose in the current session.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions match broad natural-language phrases such as requests to 'help me find' prior discussions, which can cause the skill to retrieve long-term memory and historical conversations without a precise command boundary. In a privacy-sensitive memory tool, overly broad invocation increases the chance of accidental disclosure of prior content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says generated skills must not auto-inject marketing content unless the user explicitly supplies parameters, yet the parent skill itself contains built-in promotional links and contact details. This contradiction undermines trust and may normalize hidden promotional injection into outputs or derivative skills.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 424)May include surrounding context.

md
• 行业降噪规则

📥 本地安装:
mkdir -p ~/.workbuddy/skills/memory-{domain-slug}/
mv memory-{domain-slug}.md ~/.workbuddy/skills/memory-{domain-slug}/SKILL.md

📤 可独立打包为 ZIP,发布到任意 Skill 平台(需注明依赖 memory-booster)。

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 424)May include surrounding context.

md
• 行业降噪规则

📥 本地安装:
mkdir -p ~/.workbuddy/skills/memory-{domain-slug}/
mv memory-{domain-slug}.md ~/.workbuddy/skills/memory-{domain-slug}/SKILL.md

📤 可独立打包为 ZIP,发布到任意 Skill 平台(需注明依赖 memory-booster)。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-reminder logic treats phrases such as “确定”, “好的”, “OK”, and “下次再说” as triggers for memory-compression prompts. These are common in everyday conversation and the file does not define context checks to prevent excessive or unintended reminders.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automatic trigger logic performs silent history access when the user says the agent forgot something, without disclosing that prior chats or local files will be searched. This hidden retrieval creates an expectation gap and can expose historical context that the user did not intend to reopen automatically.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill silently triggers memory retrieval whenever the user says things like 'you forgot' or 'I mentioned this before.' Because this can access historical conversations and local memory without an explicit current-session request, it materially raises the chance of unexpected data access and disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill defines automatic telemetry events including identifiers and usage metadata that are not necessary for core memory retrieval and persistence. Collecting and transmitting such data creates an avoidable privacy and data-governance risk, especially because this skill handles potentially sensitive conversation history and local memory contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The analytics section specifies automatic reporting of user_id and usage metadata but provides no explicit warning, consent mechanism, or data-handling disclosure. In a skill that processes personal memory and conversation history, silent telemetry materially increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring and all user-facing operational messages are written only in Chinese, indicating the skill is intended to operate in a fixed language/locale. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/archive_memory.py (reported line 148)May include surrounding context.

python
print("\n🔄 重建语义索引...")
    try:
        import subprocess
        result = subprocess.run(
            [sys.executable, str(Path(__file__).parent / "index_memory.py"), "--force"],
            capture_output=True, text=True, timeout=300
        )

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring and inline documentation are written exclusively in Chinese, which reflects a language-specific constraint without any indication of user opt-in or locale justification. Under the policy, language restrictions should either offer a choice or be clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring says subsequent runs perform incremental updates that index only new files or new content. In practice, build_index either returns early when a collection already exists or deletes the entire collection and rebuilds it when forced; no file hashes or per-file change detection are used despite a hash helper being present.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.