Back to skill

Security audit

CompoundOS - AI Operating System

Security checks for vulnerabilities and agentic risk

Overview

This skill is a business automation guide, but it asks agents to store broad business and customer history and perform public or financial actions with weak controls, so it should be reviewed before installation.

Install only after adding explicit guardrails: make agents draft-only by default, require human approval for public posts, outreach batches, deployments, invoices, and payments, restrict connected accounts by department, redact secrets and personal data before storage, partition HR/finance/customer memory, define retention and deletion rules, and require review before captured content changes long-term memory, SOPs, templates, or strategy.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
references/learning-loop.md:58
Finding

Untrusted Inputs Can Poison Persistent Agent Memory and Operational Rules

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
assets/department-prompts.md:359
Finding

Department Agents Are Granted Excessive Authority for Consequential External Actions

Content
View full analysis
$X ``` From `assets/department-prompts.md:121-130`: ```markdown ## Your Autonomy You have full autonomy to: - Write copy and build funnels - Run outreach campaigns - Optimize conversions You need approval for: - New offers or pricing changes - Major funnel rebuilds - Product pivots ``` From `assets/department-prompts.md:278-286`: ```markdown ## Your Autonomy You have full autonomy to: - Ship minor features and fixes - Create documentation and tutorials - Suggest upsell opportunities You need approval for: - Major features - Pricing changes - Product direction shifts - New product lines ``` From `assets/department-prompts.md:359-368`: ```markdown ## Your Autonomy You have full autonomy to: - Record transactions and generate reports - Send invoices and process payments - Track expenses You need approval for: - Major purchases (> $X) - Pricing changes - Tax filings ``` ### Technical Analysis The templates delegate direct authority to publish posts, create campaigns, conduct outreach, ship software changes, send invoices, and process payments. These are externally visible or financially consequential operations. The distinction between “minor” and “major” actions is undefined, and the placeholde ...[truncated 1782 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:79
Finding

Broad Auto-Capture Creates an Uncontrolled Repository of Sensitive Business and Personal Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document explicitly promotes comprehensive auto-capture of decisions, actions, outcomes, and context without any data minimization, consent, or privacy safeguards. In a learning/memory skill, this creates a strong risk of collecting sensitive personal, customer, operational, or confidential data and reusing it in later contexts.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
90% confidence
Finding

The instruction to capture context, timing, and participants encourages collection of surrounding conversational and identity metadata that may reveal private relationships, internal operations, or sensitive situational details. In a memory-driven agent system, this metadata can later leak through prompts, summaries, or strategic updates even if the original data was not meant for reuse.

Content

Scanner excerpt · references/learning-loop.md (reported line 13)May include surrounding context.

md
┌─────────────────────────────────────────────────────────┐
│ 1. AUTO-CAPTURE                                         │
│    • Log all decisions, actions, outcomes               │
│    • Capture context, timing, participants              │
│    • Tag by department, project, category              │
└────────────────────┬────────────────────────────────────┘
                     ↓

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The auto-capture section explicitly includes department agent output and customer interactions, both of which can contain confidential business data, user inputs, and embedded secrets. Because the captured data is intended for later processing and feedback to other components, the skill increases the chance of sensitive information being surfaced, propagated, or leaked across the system.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Automatically capturing customer interactions is particularly risky because those interactions commonly contain personal data, support case details, billing information, or other sensitive content. The skill provides no warning, filtering, or handling rules, so it normalizes indiscriminate ingestion of customer data into memory systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends placing a strategic business document into permanent agent instructions, which can cause long-term storage and repeated exposure of sensitive business context such as goals, bottlenecks, positioning, and internal priorities. That persistent context may be surfaced unintentionally in later outputs, inherited by downstream workflows, or retained beyond intended business need.

Content

No source excerpt is available for this finding.

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
91% confidence
Finding

Using permanent instructions for strategic context is a form of persistent context injection: information from one stage is embedded into future model behavior across sessions. While intended to improve consistency, it can unintentionally bias later decisions, expose sensitive context in unrelated conversations, and make it harder to revoke or compartmentalize confidential business information.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
### Step 2: Create Agent with Strategy

Feed strategic document into AI agent's permanent instructions. This ensures:
- Every decision is filtered through the strategy
- Agent can push back on misaligned requests
- Context is maintained across sessions

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs operators to log all decisions, actions, and outcomes into a knowledge system without any data-minimization, consent, retention, or access-control guidance. In a business OS context, this can capture customer data, employee data, credentials, commercial strategy, or regulated information and make it persistently retrievable by other agents or future tasks.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to log all decisions, actions, and outcomes promotes indiscriminate retention of natural-language task history. This increases the chance that sensitive user inputs, confidential documents, personal data, or operational secrets are stored verbatim and later leaked through prompts, retrieval, or agent-to-agent sharing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The best-practice guidance says 'Capture everything' and treats Auto-Capture as non-negotiable, which encourages blanket collection of inputs and outputs regardless of sensitivity. In this skill's self-improving multi-agent architecture, overcollection is more dangerous because captured data is likely to propagate across components and remain available over time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Finance Department Agent template explicitly grants autonomy to "send invoices and process payments" without any built-in warning, dual approval, or safety constraint around actions that can move funds or expose sensitive financial data. In a reusable prompt template, this omission can cause downstream agents to be deployed with authority over billing and payment operations without human verification, increasing the risk of fraudulent, erroneous, or privacy-impacting financial actions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file advocates retaining broad interaction and outcome data as part of a self-improvement loop, which creates over-collection and downstream leakage risk. Even if initially benign, persistent storage of comprehensive operational and customer-related history expands the attack surface and increases misuse potential.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Appending all captured entries to daily and long-term memory files creates durable retention of potentially sensitive information, including content that may no longer be necessary. Long-term persistence magnifies harm from accidental disclosure, unauthorized access, model reuse, or future context leakage.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The implementation checklist reinforces broad automated collection as a deployment goal, making over-collection a designed behavior rather than an incidental one. In practice, this can cause sensitive content to be captured at scale before privacy or security controls are added.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The checklist operationalizes auto-capture for all agent outputs, which may include prompts, private context, internal reasoning artifacts, secrets, or user-provided sensitive data. Turning this into automation increases the likelihood of broad, silent collection and persistence of information that should not be retained.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.