Back to skill

Security audit

Continuity Framework

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is not clearly malicious, but it needs review because it encourages persistent, possibly automatic storage of personal conversation-derived memories without clear consent, retention, or deletion controls.

Install only if you want a local continuity system that may retain personal conversation context across sessions. Before enabling heartbeat use, choose a dedicated memory directory, review what is written there, avoid storing secrets or regulated data, and make sure you have a deletion or retention process for questions, identity notes, and reflection logs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code aligns partially with the theme of continuity and surfacing follow-up questions, but the core declared functionality is not actually implemented. The main analysis routine is a placeholder that returns empty memories, questions, identity updates, and notes. There is no real structured memory extraction, no confidence scoring in practice, and no automatic reflection trigger such as a heartbeat. What the code truly does is manage markdown/json files for pending questions, identity text, and reflection logs, and provide CLI commands to display or manually edit them. This is a material description-versus-behavior mismatch because the declared primary value proposition centers on automated reflection and memory extraction, while the actual code is mostly scaffolding and manual/local persistence.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents environment-variable use and persistent file writes but does not declare any tool scope or permissions boundary. In an agent system, undeclared capabilities reduce transparency and can enable broader-than-expected access to local state or retention of sensitive data, especially when the skill is triggered automatically via heartbeat.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly proposes long-term storage of user facts, preferences, relationship dynamics, commitments, and significant moments, yet provides no user-facing privacy, consent, or retention warning. Because this data is highly personal and meant to persist across sessions, silent collection and resurfacing materially increases privacy risk and the chance of inappropriate profiling or disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented file structure creates durable memory, identity, relationship, and reflection files that may contain sensitive personal data, but the skill gives no warning about confidentiality, access control, retention, or deletion. This is more dangerous in context because the skill is designed for ongoing cross-session profiling and may be invoked asynchronously, increasing the likelihood of unnoticed accumulation of sensitive records.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is explicitly designed to retain and resurface conversation-derived information across sessions, including memories, questions, and identity notes. In this context, that behavior is functional rather than malicious, but it still creates a genuine privacy and data-handling risk because personal or sensitive information may be stored in plain-language files and reused without strong safeguards.

Content

No source excerpt is available for this finding.

Tainted flow: 'QUESTIONS_FILE' from os.environ.get (line 22, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/continuity.py (reported line 79)May include surrounding context.

python
"""Save questions to file."""
    ensure_dirs()
    
    with open(QUESTIONS_FILE, 'w') as f:
        f.write("# Pending Questions\n\n")
        f.write(f"_Generated from reflection. Last updated: {datetime.now(timezone.utc).isoformat()}_\n\n")

Tainted flow: 'IDENTITY_FILE' from os.environ.get (line 23, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/continuity.py (reported line 123)May include surrounding context.

python
"""Save identity/self-model."""
    ensure_dirs()
    
    with open(IDENTITY_FILE, 'w') as f:
        f.write("# Identity\n\n")
        f.write(f"_Last updated: {datetime.now(timezone.utc).isoformat()}_\n\n")

Ssd 3

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The comments describe loading full recent session transcripts and extracting memories and identity updates, signaling broad collection and retention of conversation content. In a memory integration skill, this context makes the issue more sensitive because transcript-wide processing can sweep up credentials, health data, or other sensitive material beyond what is necessary for continuity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persistently stores reflection analysis derived from session content into timestamped local files without any explicit consent, retention notice, or minimization controls. In a continuity/memory skill, this increases privacy risk because sensitive conversation-derived data may be retained longer than users expect and later exposed through local compromise, backups, or accidental sharing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The reflection command writes timestamped analysis artifacts to disk, enabling durable retention of conversation-derived information. Because this skill's purpose is cross-session memory, the persistence is more dangerous than in a transient logging tool: retained personal context can accumulate over time and be surfaced later in ways users did not anticipate.

Content

No source excerpt is available for this finding.

Tainted flow: 'reflection_file' from os.environ.get (line 220, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/continuity.py (reported line 221)May include surrounding context.

python
# Save reflection log
        reflection_file = REFLECTIONS_DIR / f"{datetime.now().strftime('%Y-%m-%d-%H%M')}.json"
        with open(reflection_file, 'w') as f:
            json.dump({
                "timestamp": datetime.now(timezone.utc).isoformat(),
                "analysis": analysis

Static analysis

No suspicious patterns detected.