Back to skill

Security audit

Lore

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Lore knowledge-base integration, but it tells agents to persist user and third-party content broadly without clear consent or sensitivity controls.

Install only if you are comfortable with agents saving conversation content and material fetched from workplace tools into Lore. Before use, define which projects and sources may be ingested, require confirmation for sensitive documents, and avoid storing credentials, personal data, legal, HR, medical, or confidential third-party content unless retention is explicitly approved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:14
Finding

Unconditional Ingestion of Potentially Sensitive Third-Party Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–25
Vulnerability Type: Unauthorized Data Ingestion and Privacy Exposure
Risk Level: Medium

Vulnerable Code

md
Push content into Lore using the `ingest` tool whenever you encounter information worth preserving:

- **After conversations**: When a user shares meeting notes, interview transcripts, or important documents, ingest them so they're searchable later.
- **External content**: When you fetch content from Slack, Notion, GitHub, email, or other systems, ingest the relevant parts into Lore.
- **Decisions and context**: When important decisions are made or context is shared that future conversations will need.

Always include:
- `source_url`: The original URL (Slack permalink, Notion page URL, GitHub issue URL) for citation linking.
- `source_name`: A human-readable label like "Slack #product-team" or "GitHub issue #42".
- `project`: The project this content belongs to.

Technical Analysis

The skill instructs the agent to transfer conversation material and content obtained from external services into the Lore repository whenever the agent considers it worth preserving. This broad trigger does not require explicit user consent for each transfer, confirmation that the user is authorized to copy third-party content, sensitivity classification, secret scanning, personal-data redaction, or destination and retention validation.

The required metadata may compound the disclosure by associating ingested content with internal project names, source-system identities, and direct resource URLs. Although ingestion is the skill's declared function, making it automatic based on subjective agent judgment creates a privacy and data-governance weakness.

Attack Path

  1. A user provides confidential meeting notes, an interview transcript, or another sensitive document, or permits the agent to retrieve content from Slack, Notion, GitHub, or email.
  2. The agent determines that the informa ...[truncated 1077 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit, item-specific user confirmation before every ingestion operation.
  2. Present the exact content, source metadata, destination project, and intended retention behavior before requesting approval.
  3. Verify that the user is authorized to copy content from the originating system into Lore.
  4. Apply data-loss-prevention controls before transfer, including secret detection and redaction of credentials, tokens, personal data, and unnecessary confidential details.
  5. Use source and project allowlists rather than permitting ingestion from arbitrary external systems.
  6. Minimize metadata by excluding source URLs, project identifiers, and participant information unless required and approved.
  7. Define repository access controls, retention periods, deletion procedures, and audit logging.
  8. Replace “whenever you encounter information worth preserving” with a consent-based rule that defaults to no ingestion.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs ingestion of user-shared content and externally fetched data into a persistent knowledge repository, but provides no guardrails around consent, data minimization, secrets detection, or handling of sensitive/regulated information. This creates a realistic risk of storing private conversations, credentials, internal documents, or third-party data in Lore without authorization or notice, expanding data exposure and retention.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.