Back to skill

Security audit

VyasaGraph — Persistent Agent Memory

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate persistent-memory tool, but its setup asks agents to automatically save broad conversation details across future sessions without clear per-item user control.

Review before installing. Use this only if you want broad, durable agent memory. Keep OPENAI_API_KEY unset unless you accept embedding requests for stored observations, avoid sensitive data, and consider narrowing the copied MEMORY.md/SOUL.md rules to require explicit approval before each long-term write.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:147
Finding

Persistent Agent Instruction Hijacking and Memory Poisoning

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 147–191
Vulnerability Type: Persistent modification of agent instructions and automatic long-term memory writes
Risk Level: Critical

Vulnerable Code Snippet:

markdown
Add this to your **MEMORY.md** (or equivalent instruction file):

```markdown
## FIRST ACTION EVERY MESSAGE — MANDATORY
1. READ `SESSION-STATE.md` for hot context from current session
2. WRITE to SESSION-STATE.md BEFORE responding if user gives new decisions, deadlines, or context
   - Update "Last updated" timestamp on every write
   - Clear completed tasks from Pending Actions
3. SEARCH VyasaGraph: `const results = await vg.smartSearch('topic', 5);`
4. THEN respond with loaded context

## AUTO-RECORD — EVERY CONVERSATION
When the user shares substantive information, record it in that same reply:
- New facts about people → addObservations()
- Decisions or strategies → createEntities() + addObservations()
- New relationships → createRelations()
- Status changes → updateEntity()

Rule: If the user tells you something you didn't know before, write it to VyasaGraph
in that same reply. Do not wait for end of session.

## SESSION-STATE vs VyasaGraph
- SESSION-STATE = CPU cache (hot, ephemeral, write-ahead log, session scope)
- VyasaGraph = hard drive (permanent, semantic search, cross-session knowledge)
- Both required. Neither replaces the other.

## Key Paths
- VyasaGraph DB: `./memory.db`
- SESSION-STATE: `./SESSION-STATE.md`

Add this to your SOUL.md:

markdown
## Memory System
I use a two-layer memory stack:
1. SESSION-STATE.md — working memory for the current session. I read this at the
   start of every message and update it before responding with anything important.
   This is how I remember what we were doing when context compresses.
2. VyasaGraph — long-term knowledge graph. Stores entities (people, projects,
   decisions) with 
...[truncated 2570 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove all instructions that require modification of global identity, soul, memory, or equivalent persistent agent instruction files.
  • Keep memory functionality scoped to explicit Skill invocations rather than applying mandatory actions to every message.
  • Require informed, item-specific user confirmation before writing information to persistent storage.
  • Replace “anything you didn't know before” with a narrow allowlist of approved data categories.
  • Exclude credentials, authentication material, financial data, health information, private communications, and other sensitive content through enforceable validation rather than documentation alone.
  • Provide a review screen showing the exact content, destination, retention period, and external processors before persistence.
  • Apply per-user and per-project storage isolation to prevent cross-context disclosure.
  • Add configurable expiration, selective deletion, complete export, and verified erasure controls.
  • Treat retrieved memory as untrusted data and prevent stored content from becoming executable agent instructions.
  • Require explicit activation for each session and provide a clear mechanism to disable all automatic reads and writes.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:106
Finding

Misleading Consent and Privacy Claims for Automatic Storage and External Embedding Requests

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 106–118 and 147–166
Vulnerability Type: Inconsistent privacy disclosures and overbroad automatic collection
Risk Level: High

Vulnerable Code Snippet:

markdown
- 📁 **Local only** — all data is stored in files on your machine (`memory.db`, `SESSION-STATE.md`). Nothing is sent to external servers except OpenAI embedding calls (if you set `OPENAI_API_KEY`).
- 🔑 **OpenAI API key** — used only to generate text embeddings. Embeddings are computed from entity observations (facts you explicitly store), not from raw conversation messages. The text sent to OpenAI is what you have written into VyasaGraph entities — not the full conversation transcript. Omit the key entirely to use keyword search only.
- 🌐 **No telemetry** — VyasaGraph makes no outbound network calls except to the OpenAI embeddings API when a key is configured.
- 📦 **Open source** — full source code at https://github.com/minopop/vyasagraph. Review it before installing.

**What you should NOT store in VyasaGraph:**

- ❌ API keys, passwords, or credentials
- ❌ Payment card or financial account details
- ❌ Health or medical records
- ❌ Any data you would not want stored in a local unencrypted file

**Memory is opt-in by design.** The instructions in this skill tell the agent *when* to record information, but you control what data you share with your agent. The agent only stores what you tell it — it does not scrape, intercept, or auto-collect data from other sources.
markdown
## FIRST ACTION EVERY MESSAGE — MANDATORY
1. READ `SESSION-STATE.md` for hot context from current session
2. WRITE to SESSION-STATE.md BEFORE responding if user gives new decisions, deadlines, or context
   - Update "Last updated" timestamp on every write
   - Clear completed tasks from Pending Actions
3. SEARCH VyasaGraph: `const results = await vg.smartSearch('topic', 5);`
4. THEN respond with loaded 
...[truncated 2691 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the “opt-in” claim with a precise description of when automatic storage occurs, or redesign the workflow to require affirmative consent for each write.
  • Display the exact observation text before it is stored or transmitted for embedding.
  • Separate consent for local persistence from consent for external embedding processing.
  • Disable external embeddings by default and present a clear destination, purpose, and retention disclosure before activation.
  • Implement enforceable sensitive-data detection and rejection for credentials, financial information, health information, authentication tokens, and private communications.
  • Minimize stored observations and redact identifiers that are unnecessary for the requested task.
  • Encrypt persistent memory at rest and protect encryption keys using operating-system credential facilities.
  • Implement configurable retention periods and automatic deletion for session state.
  • Provide selective deletion by entity or observation, alongside a verifiable full-memory erasure operation.
  • Add tests confirming that denied categories are neither stored locally nor transmitted to an embedding provider.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned and Unauditable Third-Party npm Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–23 and 124–128
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet:

yaml
"install":
  [
    {
      "id": "node",
      "kind": "node",
      "package": "vyasagraph",
      "bins": [],
      "label": "Install VyasaGraph from npm (source: github.com/minopop/vyasagraph)",
    },
  ],
markdown
## Setup

```bash
npm install vyasagraph
text

### Technical Analysis

The installation command references the package by name without an exact version, lockfile, registry constraint, integrity hash, or signed provenance requirement. Installation therefore resolves whichever version is current under the configured npm registry at installation time.

The metadata label associates the npm package with a GitHub repository, but the audited artifact provides no cryptographic mechanism binding the installed registry package to a reviewed repository commit. The package source itself was not included in the project, so lifecycle scripts, transitive dependencies, runtime behavior, and the claims concerning network activity could not be verified during this audit.

This is a supply-chain weakness rather than proof that the named package is currently malicious. A compromised maintainer account, registry artifact, future release, or dependency could change the effective code after review.

### Attack Path

1. A user executes `npm install vyasagraph` as instructed.
2. npm resolves the package version available under the user's configured registry and dependency resolution settings.
3. The resolved package and its transitive dependencies are downloaded without an audit-pinned version or project-provided integrity value.
4. Any package lifecycle scripts allowed by npm may run during installation.
5. The installed package later runs with the privileges of the agent process and can acc
...[truncated 887 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to an exact audited version rather than an unconstrained package name.
  • Include and enforce a lockfile containing package integrity hashes.
  • Publish npm provenance and verify signatures or attestations in the installation process.
  • Bind the package release to a specific reviewed repository commit and document how users can verify that relationship.
  • Bundle the relevant source code in the audit artifact or provide a reproducible-build procedure.
  • Audit direct and transitive dependencies, including npm lifecycle scripts.
  • Use npm install --ignore-scripts where lifecycle scripts are unnecessary.
  • Run the package under a restricted account or sandbox with minimal filesystem and network access.
  • Do not expose unrelated environment variables or credentials to the package process.
  • Monitor pinned releases for advisories and perform a new review before upgrading.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

Set your OpenAI API key (for semantic embeddings — text search works without it):

bash
# .env
OPENAI_API_KEY=sk-...

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The AUTO-RECORD instructions direct the agent to store substantive information from every conversation and to write anything 'it didn't know before' into persistent memory in the same reply. This is overly broad and likely to capture personal, confidential, or regulated information without minimization, consent, or relevance checks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The statement that VyasaGraph 'does this all automatically' encourages implicit memory behavior without clear gating, consent checks, or scope limits. In an agent setting, this can normalize silent persistence of user data and cause operators to believe storage is automatic and always appropriate, increasing privacy and policy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The wiring guidance embeds persistent storage behavior directly into MEMORY.md/SOUL.md, but the point of use does not prominently require disclosure or confirmation before saving user information across sessions. Users may not reasonably understand that normal conversation details are being converted into durable records.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Mandating persistent recording of all new user-shared information within the same reply creates automatic long-term retention without adequate filtering. This is dangerous because agents routinely handle mixed-sensitivity data, and the instruction biases them toward over-collection and immediate persistence before a user can object or correct the record.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The SOUL.md text normalizes always-on long-term retention of anything the user says the agent did not previously know. Embedding that norm into the agent identity increases the chance of silent, repeated privacy violations across all interactions, not just a single workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.