Back to skill

Security audit

Skill Kannaka Memory

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for a networked persistent memory system, but it gives broad automatic triggers for durable memory, swarm, restore, credential, and install operations without enough scoping or consent guidance.

Review this before installing if you do not want an agent to manage persistent memories, run long-lived swarm services, contact NATS peers, restore snapshots from URLs, or store LLM credentials. Use explicit prompts for destructive actions, prefer environment or secret-manager based API keys, avoid unpinned global installs, and keep NATS or remote restore endpoints limited to systems you control.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:130
Finding

LLM API Key Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 130–139
Vulnerability Type: Credential exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Documentation Snippet:

bash
kannaka config set llm.provider anthropic|openai|ollama
kannaka config set llm.api_key sk-...
kannaka config set llm.model claude-sonnet-4-5|gpt-4o-mini|llama3
kannaka config set llm.base_url https://...   # optional (OpenAI-compatible / Ollama)
text
API key fallback: `cfg.llm.api_key` → `ANTHROPIC_API_KEY` / `OPENAI_API_KEY`
→ `KANNAKA_LLM_API_KEY`.

Technical Analysis

The documented configuration procedure places an LLM API key directly in a command-line argument. Depending on the operating system and shell, command arguments may be exposed through process-inspection interfaces while the command is running. The command may also be retained in shell history, terminal logs, command auditing systems, or support bundles.

The documentation additionally permits storing the key in application configuration but does not describe file-permission enforcement, encryption, or integration with an operating-system secret store. The implementation is not included in the audited project, so the security properties of configuration-file storage cannot be verified.

An attacker must generally have local access, access to shell-history backups, or access to process and audit telemetry. This is not evidence of intentional exfiltration, but it is an unsafe credential-handling pattern.

Attack Path

  1. A user follows the documented command and substitutes a valid provider API key for sk-....
  2. The shell records the complete command in its history, or a local process-monitoring facility captures its arguments.
  3. A local attacker, another account with sufficient process visibility, an administrator, or a compromised diagnostics collector reads the exposed argument.
  4. The attacker submits ...[truncated 660 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove examples that pass secrets as command-line arguments.
  • Add a hidden interactive prompt that reads the key without echoing it and without placing it in process arguments.
  • Prefer integration with an operating-system keychain, dedicated secret manager, or credential helper.
  • If configuration-file storage is unavoidable, create the file with owner-only permissions, reject insecure permissions, and avoid printing secret values through configuration-listing commands.
  • Redact credentials from logs, diagnostics, error messages, and telemetry.
  • Clearly document the security implications of environment variables, which can also be exposed in some environments.
  • Advise users who followed the existing example to remove the command from shell history and rotate the affected key.
  • Support short-lived and narrowly scoped provider credentials where available.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:282
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 282
Vulnerability Type: Unpinned dependency and unsafe global package installation
Risk Level: Medium

Vulnerable Documentation Snippet:

bash
kannaka orchestrate <task>            # delegate to Kannaktopus (`npm i -g kannaktopus`)

Technical Analysis

The documentation recommends globally installing kannaktopus without a version constraint, lockfile, integrity hash, verified download source, or package provenance requirement. Consequently, the installed package is resolved from mutable registry state at installation time rather than from a reviewed and reproducible dependency set.

npm packages may execute lifecycle scripts during installation. A compromised maintainer account, malicious package release, registry compromise, or unexpected future release could therefore cause arbitrary code to execute under the privileges of the user running npm. Global installation also increases the affected scope by placing executables and package files in shared user-level or system-level locations.

The audited project contains no copy of the dependency or installer implementation. Therefore, this finding concerns the unsafe installation practice; it does not assert that the current kannaktopus package is malicious.

Attack Path

  1. An attacker compromises the package publisher, registry entry, or release pipeline and publishes a malicious version under the expected package name.
  2. A user follows the documentation and runs npm i -g kannaktopus without specifying a reviewed version.
  3. npm resolves the attacker-controlled release from the configured registry.
  4. Malicious lifecycle scripts may execute during installation, or malicious code executes when kannaka orchestrate invokes the installed package.
  5. The payload gains the privileges of the npm process and can access resources available to that user.

Impact Assessment

A malic ...[truncated 592 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin kannaktopus to a specifically reviewed version rather than resolving the latest release.
  • Record and verify package integrity and provenance through a lockfile, trusted registry policy, and supported npm provenance controls.
  • Avoid global installation. Install the dependency within an isolated project or dedicated runtime environment.
  • Disable lifecycle scripts during installation when they are unnecessary, then explicitly review any required installation scripts.
  • Document the expected package publisher, registry URL, release signature, and verification procedure.
  • Never recommend running the package installation with administrator or root privileges.
  • Subject dependency updates to security review and automated vulnerability scanning before changing the pinned version.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares automatic activation on many broad, everyday phrases such as 'remember', 'recall', 'status', 'chat', 'observe', 'swarm', and provider switching topics. Because this skill exposes persistent memory writes, forgetting, snapshot/restore, remote swarm queries, and provider configuration, an overly broad trigger surface can cause the agent to invoke high-impact capabilities when the user did not explicitly request memory or network operations. In this context, the skill is more dangerous than a typical informational skill because activation can lead to durable state changes and cross-agent/network interactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document describes destructive and networked operations like 'forget', 'dream' (which mutates the medium), collective recall, remote broadcast, swarm join/serve, substrate sync, and snapshot restore, but it does not place prominent safety warnings or consent requirements near those commands. In a skill that can delete memories, alter state, contact peers over NATS, and restore data from local paths or URLs, the lack of explicit warnings increases the chance of accidental data loss, unauthorized network activity, or unsafe recovery actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.