Back to skill

Security audit

Archon Brain

Security checks for vulnerabilities and agentic risk

Overview

Archon is a local management assistant, but it should be reviewed because broad activation triggers and automatic profile/log updates can expose or change sensitive work records without clear confirmation.

Install only if you want a Chinese-language, local-first management assistant that keeps detailed personal and workplace records in the workspace. Use it in a dedicated folder, review any proposed or automatic writes to profile/growth-areas.md and daily logs, and be aware that broad trigger words may cause it to load sensitive context during ordinary conversations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Vague Triggers

High
Confidence
97% confidence
Finding
The top-level trigger list contains very broad everyday terms such as '今天', '准备', '总结', and '要不要', which are likely to appear in ordinary conversation unrelated to this skill. That increases the chance of unintended activation, causing the agent to start loading workspace context, summarizing sensitive records, or writing files when the user did not intend to invoke Archon.

Vague Triggers

High
Confidence
96% confidence
Finding
The decision workflow is triggered by ambiguous phrases like '选择', '纠结', '要不要', and 'compare', which commonly occur in normal discussion. In this skill's context, unintended activation is especially risky because the workflow immediately reads profile, decision history, signals, and possibly project records, expanding access to sensitive workspace data without clear user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
The workflow selection table uses very broad trigger words such as '今天', '总结', '团队', and '开会', which are common in normal conversation and can cause unintended skill routing. In an agentic system, accidental invocation of the wrong workflow can lead to unnecessary context loading, file writes, or state changes, especially because this prompt also instructs the agent to proactively write files and track workflow state.

Ssd 3

Medium
Confidence
90% confidence
Finding
The skill is designed as a persistent assistant that tracks the user's values, preferences, growth areas, and organizational context over time. Even without external exfiltration, this broad cross-session collection and retention of sensitive personal and workplace information increases confidentiality risk, especially if the workspace is later accessed by another tool, skill, or person, or if the agent overuses unrelated context in responses.

Ssd 3

Medium
Confidence
94% confidence
Finding
The mandatory scan checkpoint instructs the agent to extract and summarize decisions, team signals, project updates, and profile updates from daily logs, which may contain highly sensitive personal and organizational details. Because the scan is compulsory and precedes user confirmation, the agent is told to surface potentially confidential inferences by default, increasing the chance of oversharing and unnecessary exposure within the conversation.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill defines a general safety rule that profile updates should be proposed to the user, but the archon-coach workflow later overrides that by mandating direct modification of `profile/growth-areas.md`. This creates an integrity and consent problem: sensitive personal profile data can be changed automatically based on the agent's interpretation, leading to inaccurate or privacy-sensitive records being persisted without explicit approval.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The status-reporting workflow instructs the agent to generate output in a "foreign-company + internet-style format" and sets a default style, but does not offer the user a language or locale/style choice. This imposes a specific communication convention without explicit opt-in or justification as a region-specific requirement.

Ssd 3

Medium
Confidence
92% confidence
Finding
The global context loading order directs the agent to load schemas, profile files, organizational files, project files, recent logs, and historical records for any workflow. This default broad aggregation violates least-privilege principles, because many workflows may not need all of that data, and it increases the blast radius of accidental disclosure, irrelevant sensitive influence on outputs, or misuse by overly broad triggers.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This markdown template uses Chinese section headings and labels throughout the body, which implicitly requires output in a specific language. The file does not offer any user opt-in, alternative locale, or justification that the template is intended only for a Chinese-language context.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
This markdown template uses Chinese section headings such as '摘要', '核心洞察', and '适用场景' with no indication that the language is optional or region-specific. That creates a natural-language policy concern because the skill appears to force a specific language without user opt-in.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The markdown template headings and governance labels are entirely in Chinese, which imposes a specific language on users of the skill. The file does not offer an opt-in language choice or document a justified region-specific constraint, so it creates a natural-language locale policy issue.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The markdown template contains required section headings in Chinese ("对上汇报口径" and "横向同步口径") while the rest of the document is in English. This imposes a specific language/locale in the skill output without any visible user opt-in or justification that the template is intended only for a Chinese-language reporting context.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown template uses Chinese section headings throughout, which imposes a specific language on users. The file does not provide any opt-in, alternative locale, or justification that the skill is intended only for a Chinese-language context.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
The instruction "Use Chinese for all content" imposes a fixed language policy. Under the language/locale policy rule, this is a violation because the file does not offer user opt-in or indicate a justified region-specific constraint.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
This markdown template uses Chinese-only headings such as "今日要点" and "明日计划", which imposes a specific language on users without any opt-in or explanation. Under the language/locale policy rule, this is a natural-language policy issue because the file does not offer alternatives or state that the template is intentionally region-specific.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
The markdown template uses Chinese headings and labels throughout, which imposes a specific language on users. The file does not indicate that the skill is region-specific or provide any user opt-in or language alternative, which matches the language/locale policy violation criteria.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The markdown template includes section headings in both English and Chinese, such as '年度 Objectives' and '关键里程碑', but provides no indication that users can choose their preferred language or locale. This can violate a language/locale policy when a skill imposes or mixes languages without explicit opt-in or justification.

Natural-Language Policy Violations

Low
Confidence
97% confidence
Finding
The template uses a Chinese section heading at L08 ('风险台账') and Chinese column labels at L10 while later using an English heading at L13 ('当前 Top Risks'). This imposes a locale/language choice on users without any opt-in or documented justification, which matches the language policy violation criteria.

Natural-Language Policy Violations

Low
Confidence
97% confidence
Finding
The template uses Chinese section headings throughout, which imposes a specific language/locale on users by default. The file does not indicate that Chinese is optional, configurable, or justified as a region-specific requirement.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
This schema includes multiple fixed headings in Chinese in some templates and English in others, which can steer downstream skill outputs toward a mixed or implicit locale without stating that the user may choose their preferred language. The policy requires avoiding forced language or locale defaults unless documented and justified.

Static analysis

No suspicious patterns detected.