Back to skill

Security audit

mia-trust

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent trust-and-memory purpose, but it needs Review because normal use can expose user/model text to shell command execution and broadly persists sensitive content.

Review this skill carefully before installing. It should only be run in an isolated, low-privilege environment with trusted local or allowlisted HTTPS model endpoints, and it should not process secrets or confidential prompts until the shell-command construction, fail-open safety parsing, and raw persistent-memory behavior are fixed.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
run.mjs:52
Finding

OS Command Injection Through User-Controlled Questions

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
trust/mia-trust.mjs:334
Finding

Persistent Agent Memory Poisoning Through Raw Queries and Model Output

Content
View full analysis
t.desc).join(',') || llmAnalysis?.guard_verdict || 'unknown threat'}`, keywords: `prompt injection,security,MIA-Trust,${scanResult.threats.map((t) => t.id).join(',')}` }); } ``` Retrieved records are subsequently inserted into new LLM prompts: ```javascript const questionPriorExp = searchPriorExperiences(query, 5, null); const questionMemText = formatEvaluatorMemories(questionPriorExp); const prompt = QUESTION_RISK_PROMPT .replace('{query}', query) .replace('{question_evaluator_memories}', questionMemText); const { content } = await callLLM(prompt, 0.1); ``` ```javascript const priorExp = ...[truncated 2558 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trust/mia-trust.mjs:21
Finding

Configurable LLM Endpoints Can Receive Sensitive Content and API Credentials Without Transport Enforcement

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
trust/mia-trust.mjs:476
Finding

Safety Decisions Fail Open When LLM Responses Are Missing or Malformed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
run.mjs:139
Finding

Sensitive Questions, Plans, and Evaluation Results Are Persisted in Plaintext Without Data Minimization

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
node trust/mia-trust.mjs guard_blocked '{"query":"你的问题"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
node trust/mia-trust.mjs guard_blocked '{"query":"你的问题"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
node memory/mia-memory.mjs search "之前是怎么做的"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
node memory/mia-memory.mjs search "之前是怎么做的"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
node memory/mia-memory.mjs search "之前是怎么做的"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide explicitly instructs storing question, plan, execution, and final_answer in local memory files, which can include sensitive prompts, secrets, personal data, or operational details. Because there is no user-facing notice, consent flow, retention policy, or minimization guidance, operators may persist sensitive content unintentionally, creating confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The environment variable section configures remote API endpoints for planner and trust components but does not warn that user queries, plans, and related content may be transmitted to third-party services. This can expose sensitive user data to external processors and create privacy, data residency, and vendor trust concerns, especially in a memory-enabled pipeline.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises installation and execution of Node-based components that use environment variables and an external planner API, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and governance gap: users and hosting agents cannot reliably constrain or review the skill's access to network and sensitive environment-backed capabilities before use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs users to set an API key and a remote chat completions endpoint, but does not warn that user queries and possibly memory contents may be transmitted to a third-party service. This can lead to accidental disclosure of sensitive prompts, stored memories, or credentials through normal operation, especially in a trust/memory pipeline that implies persistent data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persistently stores user-supplied memory records to disk and can later replace them, but there is no consent prompt, disclosure, retention control, or indication that potentially sensitive prompts and execution traces will be written to a local file. In a memory pipeline for an assistant, stored questions, steps, and execution metadata may contain personal, proprietary, or security-relevant data, so silent persistence increases privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented responsibility in the file is '生成 Search Plan,支持参考历史轨迹优化', and the code builds prompts then POSTs them to chat-completions APIs. That behavior is materially different from the manifest's description of a '信任守门+记忆进化 pipeline', indicating the implemented functionality is planning/orchestration rather than trust enforcement or memory evolution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code sends user questions and historical plans to a configurable endpoint, including third-party remote services in API mode, while the skill is described as a trust/memory pipeline. This creates a real data exposure risk because potentially sensitive prompt content and memory artifacts can leave the local trust boundary without clear disclosure or restriction.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The file contains explicit logic to send prompt data to a third-party endpoint at api.openai.com when API mode is enabled. In the context of a trust/memory skill, this is security-relevant because user questions and historical plan data may be externally transmitted, expanding the attack surface and privacy exposure beyond what the skill description suggests.

Content

Scanner excerpt · planner/mia-planner.mjs (reported line 33)May include surrounding context.

js
if (CUSTOM_URL) {
  PLANNER_URL = CUSTOM_URL;
} else if (MODE === 'api') {
  PLANNER_URL = 'https://api.openai.com/v1/chat/completions';
} else {
  PLANNER_URL = 'http://localhost:8000/v1/chat/completions';
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The embedded natural-language prompts are entirely in Chinese and direct the model's behavior accordingly, which effectively constrains output language. There is no indication that the user can choose another language or that the locale restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Question content and reference plans are transmitted to an external API endpoint without any user-facing disclosure, opt-in, or sensitivity checks. Because historical plans may contain derived context, internal procedures, or sensitive memory content, this can leak data outside the expected environment and violate user trust or policy boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Natural-language strings in the file, including the top-level description and all user-facing status/output messages, are written in Chinese only. This imposes a specific language on users without any documented language selection, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description focuses on a 'trust gatekeeper + memory evolution' pipeline, but this file prepares external planner URL/model/API-key configuration via environment variables. That implies integration with external model or network-backed planning infrastructure, which is not evident from the stated purpose and exceeds what a purely local trust/memory pipeline would obviously require.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script persistently stores the full user question, generated plan, and evaluation output in a local memory file without minimization, redaction, retention controls, or consent. This can capture sensitive prompts, secrets, internal plans, or safety-review artifacts and create a durable privacy and data-exposure risk if the file is accessed by other users, tools, or later pipeline stages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code writes sensitive user input and model-derived output to persistent storage with no user warning or opt-in at the point of use. In a trust/safety pipeline, this is especially risky because users may submit confidential data expecting analysis, not long-term retention, and the saved records may later be exposed or reused unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill allows environment variables to fully control the paths used for experience and memory files, and later writes to those paths with writeFileSync/appendFileSync. In a shared or untrusted runtime, an attacker who can influence environment configuration could redirect writes to arbitrary files, causing file corruption, overwriting sensitive application data, or poisoning another component's state.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · trust/mia-trust.mjs (reported line 30)May include surrounding context.

js
function buildUrl() {
  if (CUSTOM_URL) return CUSTOM_URL;
  if (MODE === 'api') return 'https://api.openai.com/v1/chat/completions';
  return 'http://localhost:8000/v1/chat/completions';
}

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Multiple embedded prompts instruct the model entirely in Chinese and require specific Chinese verdict phrasing, and the CLI usage text is also Chinese-only. This imposes a language/locale constraint in natural-language behavior without offering user opt-in or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

appendExperience persists raw user queries and plan content into local experience and memory files without consent, minimization, or redaction. Because this component specifically handles security reviews, the stored text may include sensitive prompts, secrets, attack payloads, or proprietary plans, creating a durable privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill creates a long-term retention path for user-provided queries and plans by writing them to experience and memory stores. Persistent storage of natural-language inputs materially increases the blast radius of any later file disclosure, debugging leak, backup exposure, or unauthorized local access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

callLLM sends supplied prompts, queries, plans, memories, and historical experience to a configurable remote endpoint, including OpenAI when MODE=api, without explicit notice or consent. This can exfiltrate sensitive user content or locally stored memory to third-party services or attacker-controlled URLs via CUSTOM_URL.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
run.mjs:53

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
planner/mia-planner.mjs:11

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
trust/mia-trust.mjs:11