Back to skill

Security audit

Memory Tasks

Security checks for vulnerabilities and agentic risk

Overview

This skill provides disclosed persistent task notes for resuming work, with a privacy caution about what gets stored.

Install only if you want task state written into Basic Memory across sessions. Treat task notes as persistent records: keep them concise, avoid secrets or private customer data, and periodically close or remove tasks that no longer need to be retained.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly directs the agent to persist work state in a knowledge graph that survives context compaction, but it does not warn that project details, user data, file paths, and operational context may be retained beyond the current session. This creates a privacy and data-minimization risk because agents may store sensitive or proprietary information in long-lived memory without user awareness or filtering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The task-creation instructions encourage recording detailed resume context such as file paths, repos, prior decisions, and what was tried, but provide no safeguards against including secrets, tokens, customer data, or other sensitive operational details. In a persistent memory system, this materially increases the chance of long-term retention and later retrieval of sensitive information that was only needed transiently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.