Back to skill

Security audit

Talk2UI

Security checks for vulnerabilities and agentic risk

Overview

This SwiftUI helper is mostly on-topic, but it asks to persist user-driven behavior and automatically write and preview files in Xcode without clear approval controls.

Review this skill before installing if you do not want an agent to remember UI preferences, update skill-related files, or automate Xcode. Use it only in a workspace where persistent memory and local preview automation are acceptable, and prefer requiring explicit confirmation before any file write, memory update, or Xcode/AppleScript action.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:40
Finding

Persistent Memory Poisoning Through User-Controlled Preferences and Phrase Mappings

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:40-44, SKILL.md:73-90, and SKILL.md:92-107
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: Medium

Vulnerable Code Snippets

Translated faithfully into English from the source instructions at SKILL.md:40-44:

markdown
## 0. Memory Activation
Before performing any task, memory must be activated.

1. Read user preferences: `view_file .agent/memory/user-preferences.md`
2. Apply preferences: Use user preferences by default instead of system defaults.

Translated faithfully from SKILL.md:73-90:

markdown
User input → Parse keywords → Query cheat-sheet.md
                                  │
                        ┌─────────┴─────────┐
                      Match             No match
                        │                    │
                  Use standard mapping   Trigger learning process
                                            │
                                       Ask user intent
                                            │
                                       Record new mapping

Record location: Chapter 6, "User Custom Area," in `examples/cheat-sheet.md`

Translated faithfully from SKILL.md:92-107:

markdown
## E. Preference Extractor
Actively identify and confirm the user's expression preferences at the end of a conversation.

Trigger timing: Proactively ask at the end of every conversation.

Output format:
Session summary:
- Animation preference: [detected preference]
- Corner-radius preference: [detected preference]
- Spacing preference: [detected preference]

Should these preferences be set as defaults? [Yes/No/Partial selection]

Record location: `.agent/memory/user-preferences.md`

Technical Analysis

The Skill creates a persistent feedback channel between user-controlled conversation content and files consulted during future executions. It requires the Agent to read .agent/memory/user-preferences.md before every task and apply ...[truncated 2405 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make persistent memory access opt-in for each task instead of mandatory.
  2. Store preferences as schema-validated data, such as JSON containing enumerated animation styles and bounded numeric spacing values.
  3. Reject free-form instructions, tool directives, shell commands, file paths, markup directives, and executable content in persisted values.
  4. Separate stored data from executable Agent instructions and explicitly state that memory contents are untrusted data.
  5. Require explicit, informed confirmation before every write and show the exact normalized value and destination.
  6. Restrict writes to a dedicated Skill-specific data file; do not modify SKILL.md or documentation that may be interpreted as instructions.
  7. Apply length limits, character allowlists where appropriate, escaping, and canonicalization before persistence.
  8. Record provenance, timestamp, requesting user, and a reversible change history for each stored preference.
  9. Prevent preferences created by one user or workspace context from being applied to another without authorization.
  10. Add integrity checks and provide a command to inspect, revoke, or reset all remembered values.
  11. Treat examples/cheat-sheet.md as immutable documentation. Store custom mappings in a validated data structure that cannot introduce new Agent instructions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Automatic opening of Xcode and triggering Canvas display via AppleScript gives the skill a local execution and GUI automation capability unrelated to mere natural-language-to-SwiftUI translation. Such automation can be abused to manipulate the developer environment, trigger unintended actions, or chain with other local scripts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation description uses broad conversational patterns for Chinese UI requests, which can cause the skill to trigger in ordinary conversation beyond its intended scope. Overbroad activation increases the chance that its file access, memory, or automation behaviors run in contexts where the user did not intend to invoke them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill activates when the user describes UI requirements in Chinese, which imposes a language constraint. The file does not offer a language choice, opt-in, or explain why Chinese-only use is required for compliance or region-specific reasons.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill expands from UI code generation into persistent memory and preference retention ('Remembering'), which introduces data collection and statefulness not necessary for its stated purpose. In an agent setting, this can lead to unintended storage of user-specific information and behavior drift across sessions without clear consent boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction to always read .agent/memory/user-preferences.md before any task creates routine access to persistent user data without demonstrating necessity for every request. This normalizes broad data access and can expose prior-session information to unrelated tasks or prompt-injection opportunities via the memory file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The beginner-mode trigger phrases are highly generic, so the skill may switch modes for unrelated requests containing common expressions like '教我' or '解释一下'. While lower severity by itself, this broad scope contributes to unexpected behavior and can combine with other risky capabilities in the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Recording new user expressions into examples/cheat-sheet.md makes the skill self-modifying and lets untrusted conversational input alter future behavior. This can persist prompt-injection content, poison mappings, or degrade integrity of the skill over time.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Persisting learned expressions and user preferences into memory files creates a retention and leakage risk for natural-language data that may contain personal habits, project terminology, or sensitive context. Because these files can influence future sessions, they also become a durable prompt-injection surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs writing user preferences into persistent memory and proactively asking to make them defaults, but it does not provide a strong upfront warning about data retention, scope, or review. Users may consent without understanding that natural-language preferences will be stored and reused later.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
ContentUnavailableView {
    Label("No Tasks", systemImage: "checklist")
} description: {
    Text("Add a task to get started.")
} actions: {
    Button("Create Task") { }.buttonStyle(.borderedProminent)
}

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill adds automatic file-writing and Xcode preview automation, including local tool interaction beyond simple code translation. This increases the attack surface by allowing the agent to modify local files and trigger external applications or automation flows that a user may not expect from a design-assistance skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow states that code will be written and Xcode preview automation will run automatically, without a clear user warning or approval checkpoint for file modification and tool control. In practice, silent local changes and application automation are high-risk behaviors for an agent skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.