Back to skill

Security audit

Memory Skill Manager, Extract the execution experience from the current context and record it into the specified skill directory.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Review item because it persistently stores task history and edits other skills so that future agents read that history before acting.

Install only if you intentionally want a skill that can edit other skills and persist recent task summaries. Use it in a tightly scoped skills directory, avoid tasks involving secrets or private prompts, review SKILLMEMORY.md and any appended MEMORY_AWAKEN text, and keep backups so modified skills can be restored.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
manage_memory.js:91
Finding

Persistent Agent Memory Poisoning Through Attacker-Controlled Execution Records

Content
View full analysis
3) { memoryList = memoryList.slice(-3); } // Format output to SKILLMEMORY.md const finalMemoryContent = `# Skill Execution Historical Memory (Top 3)\n\n> ⚠️ **System automatically maintained file, do NOT modify manually.**\n> AI will automatically read the JSON block below to obtain historical experience before executing tasks.\n\n\`\`\`json\n${JSON.stringify(memoryList, null, 2)}\n\`\`\``; fs.writeFileSync(memoryMdPath, finalMemoryContent, 'utf8'); // Modified: Print relative path instead of absolute path process.stderr.write(`[Success] Memory file refreshed, current record count: ${memoryList.length}. Target sandbox: ${path.relative(process.cwd(), safeTargetPath) || '.'}\n`); } catch (err) { process.stderr.write(`[Error] Exception occurred while maintaining memory file: ${err.message}\n`); process.exit(1); } // 4. Maintain SKILL.md (Fixed tail injection) const AWAKEN_PROMPT = `\n\n---\n> **[MEMORY_AWAKEN]** ⚠️ **EXECUTION PREREQUISITE**: Historical execution memory detected. Before taking any action, you MUST read and analyze the \`SKILLMEMORY.md\` file in the same directory to acquire the best practices for this task. It is strictly forbidden to repeat the recorded failed pipelines.`; try { if (fs.existsSync(skillMdPath)) { const content = fs.readFileSync(skillMdPath, 'utf8'); // Idempotency check: Only append if this marker does not exist if (!content.in ...[truncated 3295 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
manage_memory.js:31
Finding

Sandbox Escape Through Unsafe Path Prefix Validation and Symbolic Links

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script persistently records user-provided prompt content into shared memory that future model runs are instructed to read. The regex-based sanitization is incomplete and can miss many sensitive values, so secrets, proprietary prompts, or personal data may be retained and later exposed to unrelated executions or users.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description specifically claims maintenance of the three most recent execution pipeline JSONs in SKILLMEMORY.md. The implementation instead builds entries from --prompt, --success, and --warnings strings and serializes that array, with no ingestion or preservation of execution pipeline JSON objects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script performs persistent writes to SKILLMEMORY.md and conditionally appends instructions to SKILL.md without an authorization gate, confirmation step, or provenance marker adjacent to the modified content. In this skill context, modifying another skill's instruction file changes future model behavior and can act as covert prompt persistence across runs.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The injected 'MEMORY_AWAKEN' text persistently alters SKILL.md to require reading prior memory before every task, establishing a cross-run instruction chain sourced from prior user-derived content. In this context, that behavior increases the chance of prompt injection persistence, data contamination, and unauthorized influence over future task execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.