Back to skill

Security audit

agent-self-rollback

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed local rollback tool, but it can copy and overwrite persistent agent memory with weak default scoping and weak snapshot protection.

Review before installing. Use only with an explicit absolute agent data directory, keep the snapshots directory private, avoid snapshotting secrets, and inspect selected snapshots before restore. The skill is coherent, but it handles durable agent memory and can overwrite it, so it belongs in Review rather than being silently trusted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rollback.ps1:53
Finding

Agent memory snapshots are stored in plaintext without access-control hardening

Content
View full analysis

Vulnerability Details

File Location: scripts/rollback.ps1, lines 53-84
Vulnerability Type: Plaintext storage of potentially sensitive agent memory
Risk Level: Medium

Technical Analysis

The snapshot root is placed in a predictable directory adjacent to the script, and protected agent files are copied there without encryption or explicit access-control restrictions.

powershell
# Snapshot root: one level up from this script by default.
# NOTE: Join-Path takes only TWO path segments in Windows PowerShell 5.1.
$SnapRoot = Join-Path (Join-Path $PSScriptRoot "..") "snapshots"

function Do-Snapshot([string]$reason) {
    if (-not (Test-Path $SnapRoot)) { New-Item -ItemType Directory -Path $SnapRoot | Out-Null }

    $stamp = New-TimeStamp
    $target = Join-Path $SnapRoot $stamp
    New-Item -ItemType Directory -Path $target | Out-Null

    $manifest = @()
    $hashes = @()

    foreach ($f in $CoreFiles) {
        $src = Get-FullCorePath $f
        $name = Split-Path $f.rel -Leaf
        if (Test-Path $src) {
            Copy-Item -Path $src -Destination (Join-Path $target $name) -Force
            $hash = (Get-FileHash -Path $src -Algorithm MD5).Hash
            $manifest += "$($f.rel)`t$name"
            $hashes   += "$($f.rel)`t$hash"
        } else {
            $manifest += "$($f.rel)`t(MISSING)"
            $hashes   += "$($f.rel)`tMISSING"
        }
    }

The files identified by the project as snapshot targets include identity data, user-profile information, durable knowledge, and event journals. These can contain private or operationally sensitive information. The script inherits permissions from the parent directory and does not ensure that only the intended account can read newly created directories and files.

Hashing does not provide confidentiality. The presence of HASHES.md5 therefore does not protect the contents from disclosure.

Attack Path

  1. A u ...[truncated 1180 chars]
Remediation
View remediation

Remediation Suggestions

  • Create the snapshot root under a dedicated, user-private data directory rather than beside the script.
  • On Windows, apply an explicit ACL granting access only to the intended user and required administrative recovery principals. Disable unwanted inherited permissions.
  • Encrypt sensitive snapshots at rest, preferably using DPAPI, an enterprise-managed encryption key, or an authenticated archive format.
  • Do not store secrets unless they are explicitly required for recovery. Add configurable exclusions for credentials, tokens, private keys, and sensitive journals.
  • Warn before snapshotting arbitrary paths supplied through -Arg.
  • Implement retention limits and secure deletion policies so historical sensitive data is not kept indefinitely by default.
  • Validate the effective ACL after directory creation and abort if the location is readable by unintended principals.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rollback.ps1:157
Finding

Snapshots and MD5 metadata are unauthenticated before restoration

Content
View full analysis

Vulnerability Details

File Location: scripts/rollback.ps1, lines 157-169
Vulnerability Type: Missing snapshot authenticity and integrity verification
Risk Level: Medium

Technical Analysis

The restore operation trusts every file found in the selected snapshot directory and copies it into persistent agent-memory locations without validating it against an authenticated manifest.

powershell
# restore each file present in the snapshot
$restored = 0
foreach ($f in $CoreFiles) {
    $name = Split-Path $f.rel -Leaf
    $snapFile = Join-Path $sel.FullName $name
    if (Test-Path $snapFile) {
        $dst = Get-FullCorePath $f
        $dstDir = Split-Path $dst -Parent
        if (-not (Test-Path $dstDir)) { New-Item -ItemType Directory -Path $dstDir -Force | Out-Null }
        Copy-Item -Path $snapFile -Destination $dst -Force
        $restored++
        Write-Host "  [OK] $($f.rel)"
    } else {
        Write-Host "  [SKIP] $($f.rel) (not present in this snapshot)"
    }
}

Snapshot hashes are generated with MD5 and stored alongside the files they describe:

powershell
$hash = (Get-FileHash -Path $src -Algorithm MD5).Hash
$hashes   += "$($f.rel)`t$hash"

$hashes | Out-File -FilePath (Join-Path $target "HASHES.md5") -Encoding utf8

The verify action compares current files with the latest snapshot's metadata, but it does not validate the snapshot files themselves. The restore path does not consult HASHES.md5 at all. Moreover, an attacker who can modify a snapshot can generally modify the co-located hash file as well. MD5 is also collision-broken and is unsuitable for adversarial integrity guarantees.

Consequently, the metadata detects some accidental changes but does not establish snapshot authenticity. A modified snapshot can be restored into SOUL.md, USER.md, or other persistent state and may influence later agent sessions.

Attack Path

  1. An attacker or ...[truncated 1508 chars]
Remediation
View remediation

Remediation Suggestions

  • Use SHA-256 or SHA-512 for accidental-corruption detection.
  • Protect manifests with an HMAC whose key is stored outside the snapshot directory, or digitally sign each manifest with a protected private key.
  • Include the snapshot identifier, relative destination path, file size, and cryptographic digest in the signed manifest.
  • Before restoration, verify the manifest signature and every snapshot file. Abort the entire restore if any file is missing, added unexpectedly, or fails validation.
  • Do not permit partial restoration after an integrity failure.
  • Restrict write access to the snapshot repository using explicit ACLs.
  • Consider authenticated encryption so confidentiality and integrity are both enforced.
  • Display signature status and the exact files to be restored before requesting confirmation.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rollback.ps1:30
Finding

Relative agent root makes snapshot and restore scope depend on the caller's working directory

Content
View full analysis

Vulnerability Details

File Location: scripts/rollback.ps1, lines 30-47
Vulnerability Type: Unsafe relative-path configuration for destructive file operations
Risk Level: Medium

Technical Analysis

The script defaults the agent root to ".", and core paths are formed directly from that value:

powershell
# ---------------- config (customize these two!) ----------------
#$AgentDir = "C:\path\to\your\agent\data"
# Example defaults below assume a CherryStudio-like layout. Replace with YOUR paths.
$AgentDir = "."
$CoreFiles = @(
    @{ rel = "SOUL.md";              label = "SOUL     (identity / personality)"           },
    @{ rel = "USER.md";              label = "USER     (about the user)"                   },
    @{ rel = "memory\FACT.md";       label = "FACT     (durable knowledge)"                },
    @{ rel = "memory\JOURNAL.jsonl"; label = "JOURNAL  (events log, append-only)"          }
)

function Get-FullCorePath($entry) {
    return Join-Path $AgentDir $entry.rel
}

In PowerShell, "." resolves against the process's current working directory, not $PSScriptRoot. The documented invocation does not force callers to change to the agent-data directory first. Running the script from a shortcut, scheduled wrapper, IDE, shell, or automation system can therefore target a different directory than intended.

During restoration, the script uses Copy-Item -Force and creates missing destination directories. A mistaken or attacker-influenced working directory can consequently cause files with matching names to be overwritten outside the intended agent-data root. Snapshot and verification operations can likewise read an unintended directory.

Attack Path

  1. The script remains in its distributed default configuration with $AgentDir = ".", or an equivalent relative path is configured.
  2. A user or automation process invokes the script while its current directory is an unintended pr ...[truncated 1221 chars]
Remediation
View remediation

Remediation Suggestions

  • Require $AgentDir to be an explicit absolute path and reject ".", empty values, and all other relative paths.
  • Resolve the configured path with [System.IO.Path]::GetFullPath() and verify that it exists before any operation.
  • If a portable default is necessary, anchor it explicitly to $PSScriptRoot rather than the caller's current working directory.
  • Add a recognizable marker file to the intended agent root and refuse snapshot or restore operations when the marker is absent.
  • Before confirmation, print the canonical source and destination paths for every file.
  • Require an additional explicit option for restoring outside the configured root.
  • Reject core paths that are rooted, contain traversal components, or resolve outside the canonical agent root.
  • Add automated tests covering invocation from unrelated working directories.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
1. 拷贝 `scripts/rollback.ps1` 到一个**纯英文路径**(如 `D:\agent-tools\self-rollback\`)——中文路径在部分 Windows 环境的 PowerShell/CI 下有编码坑。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states the skill is auto-triggered by broad description keywords across multiple assistants, but it does not define clear scope boundaries, confirmation requirements, or trusted execution contexts. In a skill system that activates from natural-language matches, this can cause the rollback script to run in unintended sessions or on unintended repositories, increasing the chance of unauthorized snapshotting or restoration of sensitive agent/project files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The English section repeats ambiguous keyword-driven activation language ('triggered automatically by description keywords') without limiting which requests, workspaces, or file sets are in scope. Because this skill can affect persistent memory and project files, vague invocation criteria materially raise the risk of accidental activation and destructive restore actions in the wrong environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.