Back to skill

Security audit

Pre-Compact Resume Card

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned but needs Review because it automatically stores, reloads, and injects session and project memory content without enough scoping or sanitization.

Review the scripts before installing. Use this only in projects where saving full session transcripts and reloading prior context is acceptable, keep thinking/session-logs and .claude/session-resume-card.md out of version control, avoid secrets in chats or memory files, and prefer a pinned or manual install. Consider narrowing the hook matchers and adding sanitization or confirmation before restored text is treated as context.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
scripts/pre-compact.sh:70
Finding

Persistent Prompt Injection Through Unsanitized Resume State

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/session-start.sh:26
Finding

Undocumented Injection of Persistent Agent Memory into Session Context

Content
View full analysis
/dev/null || echo "(no memory index)" echo "" ``` ### Technical Analysis The stated purpose of the skill is to restore a pre-compaction resume card. However, the SessionStart hook additionally reads the first 20 lines of `memory/MEMORY.md` and emits them into every new session. This access is not required to load `.claude/session-resume-card.md` and broadens the data consumed by the skill. The memory content is neither sanitized nor clearly isolated as untrusted data. If the file contains sensitive information, it is exposed to the Agent context. If an attacker or another process can modify the file, it can also become an additional prompt-injection channel. The script runs with the permissions of the user launching the Agent. It does not create new operating-system privileges, but it uses existing access to read and inject repository memory beyond the skill's core resume-card function. ### Attack Path 1. Sensitive information or malicious instructions are placed in `memory/MEMORY.md`. 2. A new Agent session starts and automatically executes `scripts/session-start.sh`. 3. The script reads the first 20 lines of the memory file. 4. Those lines are inserted into the startup context without validation. 5. Sensitive data becomes available in the active context, or malicious text influences subsequent Agent actions. ### Impact Assessment Potential impact includes: - Exposure of sensitive information stored in the repository memory index. - Manipulation of Agent behavior through poisoned memory content. - Expansion of the skill's effective data access beyond its documented primary purpose. - Repeated exposure or influence on every session startup. The accessible ...[truncated 152 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Mutable Unpinned Package Executed During Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A description-behavior mismatch is especially dangerous in a hook-based skill because users may grant trust based on the stated purpose while the actual code performs broader repository enumeration and reads memory-like files. Hidden collection of git history, project structure, or local notes can expose sensitive data and indicates deceptive packaging.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
Or manually: copy `scripts/pre-compact.sh` and `scripts/session-start.sh` into your project's `.claude/scripts/`, then register the hooks in `.claude/settings.j

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
Or manually: copy `scripts/pre-compact.sh` and `scripts/session-start.sh` into your project's `.claude/scripts/`, then register the hooks in `.claude/settings.j

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/pre-compact.sh (reported line 33)May include surrounding context.

sh
mkdir -p "$BACKUP_DIR"
  TIMESTAMP=$(date +%Y%m%d_%H%M%S)
  cp "$TRANSCRIPT_PATH" "$BACKUP_DIR/session_${TRIGGER}_${TIMESTAMP}.jsonl"
  ls -t "$BACKUP_DIR"/session_*.jsonl 2>/dev/null | tail -n +31 | xargs rm -f 2>/dev/null || true
fi

# --- Resume Card: estado operativo real ---

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/pre-compact.sh (reported line 135)May include surrounding context.

sh
# Next step
  echo "### Next step"
  if [ -f "${PROJECT_DIR}/.claude/current-task.md" ]; then
    head -n 3 "${PROJECT_DIR}/.claude/current-task.md"
  else
    echo "Continuar última acción del assistant"
  fi

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The script reads and prints a file from the agent configuration directory (.claude/session-resume-card.md) directly into session context. Accessing .claude is sensitive because it can expose internal agent state, prior instructions, secrets, or attacker-planted prompt content that will be injected into the next session; in this skill, that behavior is the core feature, which makes the risk real rather than incidental.

Content

Scanner excerpt · scripts/session-start.sh (reported line 34)May include surrounding context.

sh
# Resume Card: inyectar estado pre-compaction si existe
if [ -f .claude/session-resume-card.md ]; then
  echo "### Resume Card (estado pre-compaction)"
  cat .claude/session-resume-card.md
  echo ""
fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill describes file-reading behavior and hook-driven script execution but does not declare any explicit tool scope or permissions boundaries. That makes the effective access surface unclear to users and reviewers, increasing the chance that a hook can read sensitive local files without informed consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx clawhub@latest install pulls and executes the latest published package version at install time, which is a supply-chain risk because the resolved code can change without review. If the package or one of its dependencies is compromised, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Registering both hooks with empty matchers causes them to run broadly across sessions and contexts, which increases the blast radius of any unsafe behavior in the scripts. In this skill, that means transcript parsing, file reads, and resume-card injection may occur when not needed, potentially exposing unrelated project or session data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Both hooks use an empty matcher, which causes the commands to run for all matching lifecycle events without any scoping or restriction. In this skill, that means shell scripts execute automatically at every PreCompact and SessionStart, increasing the chance of unintended execution, surprise persistence, or abuse if the scripts are modified or the skill is installed in an untrusted repository.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script copies the full session transcript into a persistent project-local backup directory without any consent, minimization, or visibility controls. Because transcripts can contain sensitive prompts, code, secrets, or internal discussion, this increases data retention and exposure beyond the original runtime context.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Backing up entire conversation transcripts into plain files creates persistent copies of potentially sensitive prompts, responses, and embedded secrets. In a project directory context, those files may be read by other tools, synced, committed, or exposed through weaker filesystem controls.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script extracts recent user and assistant content from the transcript and writes it into a persistent markdown resume card. This republishes conversational content into another file, broadening access and retention surface for potentially sensitive data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Multiple output strings such as 'Proyecto activo', 'Cambios en curso', and 'Continuar última acción del assistant' are hard-coded in Spanish. This imposes a locale on users without any documented opt-in or language selection mechanism.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script removes older backup files beyond the most recent 30 using rm -f, which is a destructive operation. Although this cleanup may be intentional, the script provides no user-facing notice or confirmation that retained backups will be deleted.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.