Back to skill

Security audit

Self Improving Agent (Fixed)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple self-improvement logger/analyzer with disclosed local logging, but users should understand it may analyze conversations and keep improvement notes in workspace files.

Before installing, decide whether you are comfortable with conversation-quality analysis and local retention of improvement notes. Use it only in workspaces where improvement_log.md can safely contain derived insights, and disable or avoid automatic analysis for sensitive conversations until the skill provides clearer consent, retention, and purge controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description presents automatic conversation analysis and learning logs without warning users that conversation-derived data may be persistently stored. This is dangerous because users may disclose sensitive or regulated information under the assumption that the interaction is ephemeral, while the skill silently retains summaries or insights to disk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill advertises behavior that reads and writes local files such as ./improvement_log.md and ./SOUL.md, but it does not declare any permissions or allowed-tools scope. This creates an authorization and transparency gap: a host may enable the skill without clearly constraining or surfacing its filesystem access, increasing the chance of unintended data exposure or tampering.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The statement that the skill 'automatically analyzes conversations after each session' is an overly broad auto-activation trigger with no scope limits, exclusions, or consent boundary. In practice, this can cause the skill to run on sensitive conversations, process data unrelated to improvement tasks, and persist outputs without the user intentionally invoking it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description claims a broadly capable 'self-improving agent system for continuous optimization' without defining boundaries, triggers, or prohibited behaviors. In agent ecosystems, vague self-improvement and optimization claims can enable unsafe invocation, scope creep, or downstream components granting excessive autonomy because the skill appears generally applicable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The heuristic checks only Chinese and English keywords when interpreting user feedback, which embeds a language preference into the skill's behavior without offering user choice or documenting the limitation. This can disadvantage users providing feedback in other languages and constitutes a locale/language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.