Back to skill

Security audit

Compaction Survival System

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to preserve context across compaction, but it does so by broadly and persistently recording user messages and recovering old memory without clear limits or consent.

Review before installing. This skill may be useful for long sessions, but assume it can retain names, paths, URLs, IDs, preferences, decisions, and possibly whole messages in local memory files. Do not use it around secrets, credentials, regulated personal data, confidential customer data, or shared workspaces unless you add explicit opt-in, redaction, retention limits, and task-scoped recovery.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:24
Finding

Overbroad Plaintext Persistence of Potentially Sensitive User Data

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:35
Finding

Persistent Memory Poisoning Through Unsanitized Recovery of User-Controlled Content

Content
View full analysis
` tag in context - You should know something but don't - Human says "where were we?" / "continue" / "what were we doing?" **Recovery steps (in order):** 1. Read `memory/working-buffer.md` — raw danger-zone exchanges 2. Read `SESSION-STATE.md` — active task state 3. Read today's + yesterday's `memory/YYYY-MM-DD.md` 4. Run `memory_search` if still missing context 5. Extract important context from buffer → update SESSION-STATE.md 6. Report: "Recovered context. Last task was X. Continuing." **NEVER ask "what were we discussing?"** — the buffer has the answer. ``` ### Technical Analysis The WAL protocol explicitly requires the agent to persist what the user said. The recovery protocol subsequently reads that user-controlled content and promotes selected material back into active session state. It does not distinguish factual task data from instructions, quoted text, external document content, or adversarial prompt payloads. No provenance marker, trust label, validation step, expiration rule, or confirmation requirement is defined. The instruction never to ask the user for clarification further reduces the opportunity to detect poisoned or obsolete state. An attacker can therefore place instruction-like content into a message in a form likely to be recorded as a decision, correction, preference, draft change, or specific value. Once written, the content can survive context compaction. D ...[truncated 1591 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:57
Finding

Overbroad Historical Memory Access During Automatic Recovery

Content
View full analysis
` tag in context - You should know something but don't - Human says "where were we?" / "continue" / "what were we doing?" **Recovery steps (in order):** 1. Read `memory/working-buffer.md` — raw danger-zone exchanges 2. Read `SESSION-STATE.md` — active task state 3. Read today's + yesterday's `memory/YYYY-MM-DD.md` 4. Run `memory_search` if still missing context 5. Extract important context from buffer → update SESSION-STATE.md ``` ### Technical Analysis The automatic recovery workflow directs the agent to read the working buffer, active session state, two days of general memory logs, and potentially all searchable memory. Access is triggered by broad conditions such as a user saying “continue” or the agent believing it should know something. The workflow does not require a task identifier, user identity check, workspace boundary, sensitivity filter, or confirmation before expanding the search. If the memory files contain information from unrelated tasks or users, the recovery operation can load that information into the current context. The extraction step can then copy it into active session state. This represents a least-privilege failure at the agent-memory layer. It is not evidence of operating-system privilege escalation, but it can cross logical access boundaries between tasks, sessions, or users when the underlying memory store is shared. ### Attack Path 1. Sensitive information from a prior task or user exists in a daily memory file or searchable memory store. 2. An attacker or unauthorized user starts a session and supplies a broad recovery phrase such as “continue” or “where were we?” 3. The automatic recov ...[truncated 923 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These instructions require writing user-provided details to SESSION-STATE.md before responding, but provide no notice, consent flow, or sensitivity filter. That creates a direct risk of silently retaining personal, confidential, or security-relevant data in persistent storage where it may later be exposed to other skills, users, or sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The working-buffer mechanism persistently logs every exchange after a context threshold, which amounts to broad transcript capture without user awareness. Because it stores both user messages and response summaries, it can accumulate sensitive content at scale and extend the exposure window well beyond the active conversation.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Appending every exchange to a working-buffer file creates a durable conversation log that is broader than the stated goal of preserving critical task state. In the context of an always-on skill, this materially increases the chance of sensitive data collection, cross-context leakage, and later unauthorized reuse during recovery or other memory operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Describing the skill as an always-active behavioral mechanism creates no clear activation boundary, so it can influence routine interactions far beyond a narrow memory-management use case. In practice, that broad scope increases the chance of unintended file writes, silent persistence, and interference with normal user expectations about ephemeral conversation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to act on every incoming message is overly broad and effectively turns all user input into potential logging triggers. That makes the behavior hard to contain and increases the likelihood that sensitive or irrelevant content is captured and persisted without contextual necessity.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The WAL flow instructs the agent to continuously extract and persist corrections, preferences, decisions, and specific values from user messages. This creates a natural-language data retention risk because unstructured conversation often contains credentials, personal data, internal paths, or business-sensitive context that may be logged without discrimination.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The recovery workflow instructs the agent to mine prior logs, daily files, and search tools to reconstruct context from stored user data. While intended to improve continuity, it also increases the likelihood of resurfacing old sensitive material into a new context, including cases where the user did not expect prior content to be recalled or reprocessed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.