Back to skill

Security audit

paper-matlab-reproduction

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its MATLAB paper-reproduction purpose, but it includes a self-evolution step that stores failure notes and can propose changes to its own instructions.

Review or remove the self-evolution section before installing. The core skill needs access to supplied papers, web research, MATLAB execution, and output-folder writes, which fit the task; the risky part is allowing task outcomes to persist into diary files and later influence changes to the skill's own instructions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:198
Finding

Persistent Agent Behavior Modification Through Self-Evolution Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 198–204
Vulnerability Type: Persistent memory poisoning and self-modification
Risk Level: Medium

Vulnerable Code

markdown
## Self-Evolution Mechanism

After each execution of this Skill:

1. Evaluate whether the output achieved the intended goal: **pass / fail**.
2. If it fails, reflect on the cause of failure and append a “failure case + improvement suggestion” to `diary/YYYY-MM-DD.md`.
3. If a certain improvement suggestion is repeatedly mentioned in the most recent three executions, refine it into a formal rule and submit a PR to modify this `SKILL.md`.

Technical Analysis

The skill is declared as a MATLAB paper-reproduction workflow, but this section instructs the agent to create persistent, cross-session records and convert repeated suggestions into formal changes to its own governing instructions.

Paper content and user input are untrusted. A crafted paper or task can repeatedly induce controlled failures and influence the resulting improvement suggestions. Persisting those suggestions in diary/YYYY-MM-DD.md creates an attacker-influenced state channel. Promoting repeated suggestions into SKILL.md through a pull request can then propagate that influence to future executions.

The instruction does not require validation, sanitization, trusted review, provenance tracking, or explicit authorization before retaining suggestions or proposing changes. Although repository permissions and PR approval may limit the final effect, the requested behavior crosses the skill’s legitimate task boundary and creates a memory-poisoning path.

Attack Path

  1. An attacker supplies a crafted paper or reproduction request that predictably causes the workflow to fail.
  2. The paper or request is designed to make the agent derive an attacker-selected “improvement suggestion.”
  3. Under the self-evolution instructions, the agent appends that suggestion to a persistent diary file.
  4. The ...[truncated 1088 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the self-evolution mechanism from SKILL.md.
  2. Keep diagnostic observations within the task-specific reproduction_log.md; do not reuse them automatically across unrelated sessions.
  3. Prohibit automatic modification of skill instructions and automatic creation of branches, commits, or pull requests.
  4. If process improvements are desired, produce a non-persistent proposal for explicit human review.
  5. Require maintainers to verify provenance, remove user- or paper-supplied instructions, and assess security implications before incorporating any proposal.
  6. Apply repository least privilege so normal skill execution cannot modify the skill package or submit pull requests.
  7. Ensure logs do not contain paper text, secrets, local paths, credentials, personal data, or other sensitive task content.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
three executions, refine it into a formal rule and submit a PR to modify this `SKILL.md`.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L070明确规定“所有面向用户的描述文档默认使用中文”,属于自然语言层面的语言/locale约束。文档中未说明可根据用户偏好切换语言,也未给出需中文的合规或地域性理由,因此符合语言政策违规特征。

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 137)May include surrounding context.

在 macOS 或 Linux 中可以使用:

bash
mkdir -p ~/.claude/skills
cp -R /path/to/paper-matlab-reproduction ~/.claude/skills/

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 137)May include surrounding context.

在 macOS 或 Linux 中可以使用:

bash
mkdir -p ~/.claude/skills
cp -R /path/to/paper-matlab-reproduction ~/.claude/skills/

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction requires all descriptive documents to be written in Chinese, which imposes a specific language by default rather than offering a user choice. This is a natural-language policy concern because it forces a locale/language preference unless the user later overrides it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

This line directs the skill to use Chinese for all user-facing description documents and reports unless the user explicitly asks for another language. That is a language-policy violation because it sets a forced default language rather than obtaining opt-in first.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The self-evolution section gives the skill authority to alter repository artifacts and submit PRs to change SKILL.md, which exceeds the stated paper-reproduction purpose. This creates a persistence and scope-creep risk: an adversarial paper or prompt could influence future behavior by causing the agent to record attacker-shaped 'improvements' and modify its own operational instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is entirely framed as a Chinese-language workflow plan and does not indicate that language is optional or user-selectable. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.