Back to skill

Security audit

ByteRover Context Tree

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is not clearly malicious, but it needs review because it broadly directs agents to send and persist project context through an external-provider CLI without enough scoping or user control.

Install only after you are comfortable with a global third-party CLI, external LLM processing of project context, and persistent memory files in the repository. Use it deliberately rather than automatically, avoid storing secrets or personal data, prefer pinned and verified package installation, and review exactly what will be curated or synced before running provider or cloud commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Unconditional Skill Instructions Hijack the Agent Workflow

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation
`. - Publish and verify the expected package integrity hash. - Identify the official registry, publisher, and source repository in the installation documentation. - Prefer a project-local, lockfile-controlled dependency over a global installation. - Review package contents and lifecycle scripts before installation. - Where operationally possible, install with lifecycle scripts disabled and enable only separately reviewed setup actions. - Use automated dependency monitoring and require review before updating the pinned version. - Avoid running npm with administrator or root privileges. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:143
Finding

Ambiguous and Potentially Misleading External Data-Disclosure Assurance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The documentation instructs connecting arbitrary external model providers and includes an example with an API key on the command line. Even though the key is a placeholder, this normalizes passing secrets via shell history/process arguments and expands the set of third parties that may receive project context.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

bash
brv providers list
brv providers connect openai --api-key sk-xxx --model gpt-4.1

4. Cloud Sync (Optional)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
98% confidence
Finding

The skill clearly states that brv query and brv curate send supplied text and included file contents to a configured LLM provider, and push/pull send knowledge to ByteRover cloud. Because the skill also tells agents to use these commands broadly and early, it creates a direct exfiltration path for project files, internal context, and possibly sensitive user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
**File access**: The `-f` flag on `brv curate` reads files from the current project directory only. Paths outside the project root are rejected. Maximum 5 files per command, text and document formats only.

**LLM usage**: `brv query` and `brv curate` send context to a configured LLM provider for processing. The LLM sees the query or curate text and any included file contents. No data is sent to ByteRover servers unless you explicitly run `brv push`.

**Cloud sync**: `brv push` and `brv pull` require authentication (`brv login`) and send knowledge to ByteRover's cloud service. All other commands operate without ByteRover authentication.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill says to run brv query before performing any action and includes broad triggers like recalling capabilities, past actions, or checking for relevant rules before acting. This can cause routine prompts and project context to be unnecessarily sent to an external LLM provider, increasing exposure of internal data and making the tool fire in many ordinary situations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The curate guidance is overly broad, including storing meaningful memories from user interactions and important facts about actions taken. This encourages persistent storage of conversational and operational data without clear sensitivity limits, which can capture secrets, proprietary information, or personal data and then expose them later through retrieval or syncing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly encourages persisting user interaction content and recalling it later, but it does not define sensitivity boundaries or retention rules. In a memory-management skill, this is especially risky because the normal workflow is to save and retrieve data, so secrets or sensitive user information could be stored locally, sent to a provider during processing, or propagated further via later sync operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.