Back to skill

Security audit

金字塔记忆架构

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed memory-organization guide, but it gives agents broad access to workspace memory files and recommends recurring cron and GitHub sync workflows that need review.

Review before installing if your workspace contains private memory, user-profile, tool, cookie, API-key, or repository information. Use this only with explicit file allowlists, keep the cron workflow disabled unless you intentionally want recurring scans, and require separate confirmation before any cleanup or GitHub push.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:381
Finding

Overbroad Workspace Inspection May Expose Sensitive Agent Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 381-389; related sensitive-file definition at line 274
Vulnerability Type: Overbroad access to workspace documents
Risk Level: Medium

Complete Relevant Snippet

English translation of the relevant source text:

markdown
1. Read trigger state: First read memory/redundancy-check-state.json and determine whether the three-day interval has elapsed.
2. Read the contents of all Markdown files.
3. Execute each item in the nine-item checklist.
3. Pyramid compliance:
   a. Extract a dynamic keyword fingerprint by scanning every SKILL.md.
   b. Match the fingerprint against MEMORY.md.
   c. Scan AGENTS.md for operational or technical content.
   d. Scan MEMORY.md for mandatory rules or security boundaries.
   e. Check whether MEMORY.md violates the skill self-containment principle.

The file classification table also states:

markdown
TOOLS.md: Local configuration notes, including device ports and the storage locations of cookies and API keys.

Technical Analysis

The audit procedure instructs the Agent to read every Markdown file in the workspace. This scope is broader than necessary for checking the memory architecture and does not define exclusions for sensitive files.

The same skill explicitly identifies TOOLS.md as a location that may contain device information, cookie locations, and API-key locations. Other automatically injected files, such as USER.md, MEMORY.md, and AGENTS.md, may contain private user details, long-term state, or privileged behavioral configuration. Reading every Markdown file therefore violates least-privilege and data-minimization principles.

There is no confirmed instruction to transmit the inspected information externally. The primary exposure is to the Agent context, model-provider processing, conversation logs, tracing systems, or any downstream component that receives the generated report.

...[truncated 1229 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the instruction to read all Markdown files with an explicit allowlist, such as AGENTS.md, MEMORY.md, HEARTBEAT.md, and selected SKILL.md files.
  2. Exclude TOOLS.md, USER.md, credential documentation, private logs, and unrelated project documents by default.
  3. Require explicit user approval before opening any file classified as sensitive.
  4. Inspect headings, anchors, hashes, or metadata before reading complete file contents.
  5. Redact secret values, cookie material, tokens, user identifiers, hostnames, and local paths from reports.
  6. Add maximum file-count and file-size limits to prevent accidental ingestion of an entire workspace.
  7. State that the generated report must identify affected files and rule categories without reproducing sensitive values.
  8. Run the scan with read-only access and restrict it to the intended workspace root.

T06 · System Persistence

Warning
Location
SKILL.md:307
Finding

Recurring Cron Task Creates Indefinite Cross-Session Persistence

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 307-348
Vulnerability Type: Persistent scheduled Agent execution
Risk Level: Medium

Complete Relevant Snippet

English translation of the relevant source text:

markdown
The redundancy check does not trigger automatically and requires a manually configured trigger.
A cron scheduled task is recommended.

Option: Cron scheduled task — classified as complex, with the complete instructions
written directly into the payload.

1. Add a short anchored section to HEARTBEAT.md.
2. Create a cron task whose payload contains the complete nine-item checklist.
3. Schedule: 0 12 */3 * * — every three days at noon.

The payload first reads memory/redundancy-check-state.json to determine whether
at least three days have elapsed, performs the nine checks, and then updates
memory/redundancy-check-state.json.

The payload also includes the following operational instruction:

markdown
Read memory/redundancy-check-state.json first to determine whether the interval
is at least three days, then execute all nine checks.
...
After completion, update memory/redundancy-check-state.json.

Technical Analysis

The skill recommends installing a recurring cron job that runs an isolated Agent session every three days. It also maintains a persistent state file across runs. This creates execution that survives the original interactive skill invocation.

The persistence is disclosed and requires manual setup, so it is not a covert backdoor. Nevertheless, the design omits important lifecycle and safety controls:

  • No expiration date or maximum execution count
  • No documented removal or disable procedure
  • No unique job identifier or duplicate-registration check
  • No strict workspace scope
  • No execution-time or resource limit
  • No mechanism to verify that the original owner still authorizes the task
  • No restriction preventing the persisted ...[truncated 1729 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed confirmation immediately before creating the cron task.
  2. Display the exact schedule, payload, workspace scope, runtime identity, and files accessed before installation.
  3. Assign a deterministic, unique job identifier and check for an existing job before registration.
  4. Provide documented commands or procedures to list, disable, and permanently remove the task.
  5. Add an expiration date, maximum run count, or periodic reauthorization requirement.
  6. Restrict the payload to an explicit file allowlist and a canonical workspace root.
  7. Execute with minimum permissions, read-only access where possible, and strict time and resource limits.
  8. Store only the minimum timestamp required in the state file and create it with restrictive permissions.
  9. Validate state-file paths to prevent symlink or path-redirection issues.
  10. Record installation and removal events in a local audit log without storing inspected sensitive content.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
| **底层** | `SKILL.md` | 匹配场景时读取 | 技术实现、操作流程、选择器、正则 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
| **底层** | `SKILL.md` | 匹配场景时读取 | 技术实现、操作流程、选择器、正则 |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
- ✅ **推荐多级联链**:AGENTS.md(一行核心)→ MEMORY.md(业务展开)→ SKILL.md(技术实现)

### ⚠️ 隔离场景直写铁律
<!-- #isolated-direct-write -->

**cron 定时任务、子 agent、隔离会话中,禁止使用多级引导(详见 SKILL.md「隔离场景直写铁律」(#isolated-direct-write)),规则必须直写在 prompt 里。**

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger scenarios are extremely broad, covering new-agent creation, workspace initialization, memory design, redundancy checks, trigger allocation, and cron analysis. Overbroad matching increases the chance this skill will be auto-invoked in contexts where its file-modification and synchronization instructions are inappropriate, amplifying accidental execution of high-impact actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as a memory-architecture and workspace-initialization guide, but it also instructs the agent to perform repository synchronization, tagging, and GitHub pushes. That expands the skill from local documentation management into remote side-effecting operations, increasing the chance an agent will publish changes or metadata to external systems without the user explicitly invoking a release workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Publishing to GitHub is not necessary for a memory-architecture skill and creates an unjustified outbound capability. If this skill is auto-selected based on broad matching, an agent could be steered from editing internal memory files into performing remote repository operations, risking accidental code publication, tag creation, or disclosure of sensitive workspace contents.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document says redundancy findings should be reported and confirmed before cleanup, but the execution steps also instruct deletion of lower-layer content in the same workflow. This contradiction can cause an agent to perform destructive edits based on its own interpretation, leading to unauthorized deletion or modification of rules and memory content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.