Back to skill

Security audit

Memory Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly performs local memory organization, but one script can move or append files outside the intended memory folder if given crafted arguments.

Review this skill before installing. It stays local and does not show network exfiltration, but back up your memory directory first, avoid passing untrusted names or source paths to categorize.sh, and prefer a patched version that validates filenames and confines all source and destination paths to the intended memory directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
categorize.sh:23
Finding

User-Controlled Destination Path Traversal in Memory Categorization

Content
View full analysis

Vulnerability Details

File Location: categorize.sh, lines 23–25 and 33–72
Vulnerability Type: Path traversal leading to out-of-scope file relocation or modification
Risk Level: High

Vulnerable Code

bash
TYPE="$1"
NAME="$2"
SOURCE="$3"

# Validate source file exists
if [ ! -f "$SOURCE" ]; then
  echo "❌ Source file not found: $SOURCE"
  exit 1
fi

# Determine destination
case "$TYPE" in
  episodic)
    DEST="$MEMORY_DIR/episodic/${NAME}.md"
    ;;
  semantic)
    DEST="$MEMORY_DIR/semantic/${NAME}.md"
    ;;
  procedural)
    DEST="$MEMORY_DIR/procedural/${NAME}.md"
    ;;
  *)
    echo "❌ Unknown type: $TYPE"
    echo "Valid types: episodic, semantic, procedural"
    exit 1
    ;;
esac

# Check if destination exists
if [ -f "$DEST" ]; then
  echo "⚠️  File already exists: $DEST"
  echo ""
  read -p "Merge with existing file? (y/n) " -n 1 -r
  echo ""
  if [[ $REPLY =~ ^[Yy]$ ]]; then
    # Append to existing
    echo "" >> "$DEST"
    echo "---" >> "$DEST"
    echo "# Merged from: $(basename "$SOURCE")" >> "$DEST"
    echo "# Date: $(date +"%Y-%m-%d %H:%M:%S")" >> "$DEST"
    echo "" >> "$DEST"
    cat "$SOURCE" >> "$DEST"
    echo "✅ Merged into: $DEST"
  else
    echo "❌ Cancelled"
    exit 1
  fi
else
  # Move to destination
  mv "$SOURCE" "$DEST"
  echo "✅ Categorized as $TYPE: $DEST"
fi

Technical Analysis

The second command-line argument, NAME, is interpolated directly into DEST without validation or canonicalization. The script does not reject path separators, .. components, absolute-path constructs, or symbolic-link-based escapes. Consequently, a value such as ../../target can resolve outside the selected episodic, semantic, or procedural directory.

The SOURCE argument is also only checked with -f; it is not required to reside inside the expected memory or legacy directory. This allows any file readable by the invoking account to be selected.

If the computed destination does not exist, `mv "$SOURCE" "$D ...[truncated 1813 chars]

Remediation
View remediation

Remediation Suggestions

  1. Restrict NAME to a filename-safe allowlist and reject path syntax:
bash
if [[ ! "$NAME" =~ ^[A-Za-z0-9][A-Za-z0-9._-]*$ ]] ||
   [[ "$NAME" == *".."* ]]; then
  echo "Invalid memory name" >&2
  exit 1
fi
  1. Canonicalize the source and destination with realpath and verify that they remain under explicitly approved roots. Require the source to be under "$MEMORY_DIR/legacy" or another documented import directory.

  2. Create and canonicalize the selected category directory before constructing the destination. Reject any destination whose canonical parent differs from that directory.

  3. Refuse symbolic links for both source and destination, or resolve them and repeat the containment checks after resolution.

  4. Use option terminators for filesystem commands:

bash
mv -- "$SOURCE_REAL" "$DEST"
cat -- "$SOURCE_REAL" >> "$DEST"
  1. Use a temporary file followed by an atomic rename for merge operations. This reduces partial-file corruption if an operation fails.

  2. Avoid interactive confirmation when invoked by unattended agent automation. Require an explicit merge flag and perform all containment validation regardless of that flag.

  3. Run the skill with least-privilege filesystem access so it can read and write only the intended memory hierarchy.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Claiming semantic search and broader memory-management protections when behavior may only amount to basic keyword search and manual categorization can mislead operators about retrieval quality and resilience. The danger is not code execution, but operational misreliance: agents may skip other safeguards or depend on incomplete recall during sensitive workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Claiming semantic search and broader memory-management protections when behavior may only amount to basic keyword search and manual categorization can mislead operators about retrieval quality and resilience. The danger is not code execution, but operational misreliance: agents may skip other safeguards or depend on incomplete recall during sensitive workflows.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Claiming semantic search and broader memory-management protections when behavior may only amount to basic keyword search and manual categorization can mislead operators about retrieval quality and resilience. The danger is not code execution, but operational misreliance: agents may skip other safeguards or depend on incomplete recall during sensitive workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to run organize.sh and explicitly states it migrates flat memory/*.md files into a new structure, but it does not warn that existing user data will be modified or potentially moved in ways that may be hard to undo. In a memory-management skill, these files likely contain important agent context, so unclear migration guidance increases the risk of accidental data loss, broken workflows, or corruption if users run the command without backup or review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Commands that organize, migrate, or categorize memory files can modify local agent state, yet the skill does not prominently warn that these operations may relocate or rewrite existing entries. In a memory-management context, that raises the risk of accidental data movement, confusion, broken references, or effective loss of context if users assume the commands are non-destructive.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a memory-management skill focused on detecting compression risk, saving snapshots, semantic search, and tracking usage patterns. This script instead implements a manual organizer that reclassifies files by moving or appending them into category folders, which is a different user-facing behavior not mentioned in the manifest.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "保存记忆" is broad enough to match ordinary user requests about saving information, which can cause this skill to activate outside its intended scope. In a memory-management skill, unintended activation could expose or persist sensitive conversational context when the user did not explicitly request memory operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger phrase "记忆分析" is ambiguous and may match general discussion about memory, analysis, or context rather than an intentional request to invoke this skill. Because the skill manages local memory, ambiguous activation increases the risk of unauthorized inspection, searching, or transformation of stored conversation data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest presents the description primarily in Chinese while also defining English trigger phrases, but it does not explain supported languages or whether users can choose their preferred locale. This may create an implicit language policy without clear opt-in or documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.