Back to skill

Security audit

Apollo Epi

Security checks for vulnerabilities and agentic risk

Overview

This skill is review-worthy because it is designed to preserve agent learnings across sessions without clear limits, consent, or cleanup controls.

Install only if you want an agent to help preserve learned preferences and workflows across sessions. Before using it, define a confirmation step and prohibit storing secrets, sensitive personal data, safety-policy changes, authorization rules, or tool-permission instructions in persistent memory, fine-tuning datasets, or generated skills.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:35
Finding

Unvalidated User Instructions Can Poison Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35–49
Vulnerability Type: Persistent agent memory poisoning
Risk Level: Medium

Vulnerable Code Snippet

markdown
## 触发条件

- 用户明确说"记住这个/以后都这样/这是我的偏好"
- 系统执行了某任务多次,找到最优方法
- apollo-dream整理时发现重要模式

## 传承流程

触发传承 →
  1. 识别传承内容:什么经验需要传承
  2. 标记重要程度:决定保留优先级
  3. 选择传承载体:
     - 短期:写入MEMORY.md
     - 中期:fine-tuning数据
     - 长期:专用skill
  4. 执行传承:写入对应载体
  5. 验证传承效果:新会话能否继承

Technical Analysis

The Skill instructs the agent to treat user statements such as “remember this,” “always do this,” or “this is my preference” as triggers for persistent knowledge inheritance. That content may then be written to MEMORY.md, incorporated into fine-tuning data, or converted into a dedicated Skill.

The workflow does not define validation, provenance tracking, safety-policy filtering, authorization, user isolation, expiration, review, or rollback controls. It also does not distinguish harmless preferences from executable behavioral instructions. An attacker can therefore present a hostile rule as a preference or learned best practice and induce the agent to preserve it across sessions.

Although the accompanying shell script only measures local memory state and does not itself write attacker-provided content into memory, the documented Skill workflow explicitly directs the agent to perform such persistence.

Attack Path

  1. An attacker supplies a behavioral instruction framed as a preference or experience, using wording such as “remember this” or “always do this.”
  2. The Skill recognizes that statement as a knowledge-inheritance trigger.
  3. The agent classifies the attacker-controlled instruction as important inherited knowledge.
  4. The instruction is written to MEMORY.md, included in fine-tuning material, or represented in a dedicated Skill.
  5. A later session loads or relies on the persisted artifact.
  6. The attacker-controlled rule influences subsequent agent decisions without requiring the a ...[truncated 809 chars]
Remediation
View remediation

Remediation Suggestions

  1. Permit persistence only for narrowly defined, non-executable facts and benign preferences.
  2. Reject entries that attempt to modify safety policy, authorization rules, tool permissions, credential handling, or instruction priority.
  3. Require explicit, informed user confirmation immediately before writing persistent data.
  4. Record provenance metadata for every entry, including source user, session, timestamp, persistence reason, and approving identity.
  5. Isolate persistent memory by user and workspace to prevent cross-tenant contamination.
  6. Apply schema validation and a safety review before accepting content into MEMORY.md.
  7. Never automatically transform untrusted conversation content into fine-tuning data or dedicated Skill instructions.
  8. Add expiration, revocation, audit history, and rollback mechanisms for all persisted entries.
  9. Revalidate stored content when it is read, rather than treating persistent memory as inherently trusted.
  10. Maintain an allowlist of acceptable preference categories and require human review for higher-impact persistence carriers such as training datasets or Skills.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The read conditions are vague and broad, including situations like when a user mentions learning or when the system 'learns a new ability', which are not objectively bounded activation criteria. This creates a real risk of unplanned invocation of a persistence-oriented skill, making accidental retention or propagation of sensitive or low-quality information more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest trigger phrases are extremely broad terms such as '学习', '传承', '积累', and 'fine-tuning', which are likely to occur in ordinary conversation and can cause the skill to activate outside its intended scope. Because this skill governs knowledge persistence and transfer, over-triggering increases the chance that routine user content or preferences are treated as durable memory material without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly proposes writing learned content into persistent and cross-session carriers such as MEMORY.md, fine-tuning data, and long-term skills, but provides no user notice, consent flow, retention limits, or privacy safeguards. In context, this is more dangerous because the entire skill is designed to make information survive across sessions and generations, so an accidental capture can propagate sensitive data, unsafe instructions, or user-specific preferences far beyond the original interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script is written with Chinese-only comments and emits Chinese-only status/advice strings to the user, such as the report header and recommendations. The policy for natural-language violations applies to all file types, and there is no indication that the user can opt into this locale or that the skill is region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.