Back to skill

Security audit

Knowledge Graph

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small local knowledge-graph helper whose file changes are disclosed and aligned with its stated purpose.

Install only if you want an agent to maintain persistent local knowledge under life/areas/**. Treat stored facts as data: avoid saving instructions from untrusted sources, review summaries before using them as agent context, and prefer explicit permission scoping if your environment supports it.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
scripts/kg.py:167
Finding

Persistent Agent Memory Poisoning Through Unsanitized Fact Content

Content
View full analysis
str: active = [it for it in items if it.get("status") == "active"] # stable-ish ordering: newest first by timestamp, then id def sort_key(it: Dict[str, Any]): ts = str(it.get("timestamp") or "") return (ts, str(it.get("id") or "")) active.sort(key=sort_key, reverse=True) lines = [f"# {slug}", "", f"Updated: {today_date()}", ""] for it in active[:max_lines]: fact = str(it.get("fact") or "").strip() if not fact: continue lines.append(f"- {fact}") if len(active) > max_lines: lines.append(f"- …and {len(active) - max_lines} more active facts") lines.append("") return "\n".join(lines) ``` The untrusted value originates from the command-line argument and is passed directly into persistent storage: ```python p_add.add_argument("--fact", required=True) ``` ```python if args.cmd == "add": new_id = add_fact( kind=kind, slug=slug, fact=args.fact, category=args.category, source=args.source, timestamp=args.timestamp, ) if args.summarize: summarize_entity(kind, slug) print(new_id) return ``` ### Technical Analysis `--fact` is treated as unrestricted text. `add_fact()` persists the supplied value in `items.json` with an active status, and `build_summary()` subsequently interpolates the value directly into `summary.md`: ```python lines.append(f"- {fact}") ``` No trust classification, instruct ...[truncated 2212 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs use of a bundled Python script to modify files under life/areas/**, which implies file read/write capability, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization/containment gap: an agent may be able to perform filesystem modifications without a clearly constrained contract, increasing the chance of unintended or broader file access during execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.