Back to skill

Security audit

Clairvoyance

Security checks for vulnerabilities and agentic risk

Overview

The skill is a read-only reflective tool for user-authorized memories and dream notes, with clear limits against automatic use, writes, scripts, and external calls.

Install only if you are comfortable letting the agent read the specific memory or dream-note files you approve. Use it in private conversations, keep the time range narrow, and avoid authorizing files containing details you do not want summarized or interpreted in the chat transcript.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:19
Finding

Access to Sensitive Agent Memory and Dream Records

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–30
Vulnerability Type: Sensitive Agent Memory Access
Risk Level: Medium

Evidence

markdown
## Sources

Read only the sources authorized for this reading. Typical sources are:

- `MEMORY.md`;
- recent `memory/YYYY-MM-DD.md` notes;
- `memory/.dreams/events.jsonl`;
- `memory/.dreams/phase-signals.json`, when relevant.

Default to the last 7–14 days. Use up to 30 days only when the user approves or the shorter period is too sparse.

Missing files are unavailable. Do not infer their contents. Do not search unrelated folders, messages, email, external services, or third-party records.

Technical Analysis

The Skill directs the Agent to read persistent memory and dream-record files. These resources may contain sensitive personal history, relationships, health-related reflections, behavioral patterns, or other private information.

This access is explicitly constrained: the Skill requires user authorization, limits the default period to 7–14 days, prohibits searching unrelated locations, and is documented as read-only. It therefore does not constitute privilege escalation or malicious memory modification. Nevertheless, processing these files creates a confidentiality risk because sensitive source content and derived conclusions may be exposed through the conversational response.

No executable code, remote payload retrieval, external transmission, persistence mechanism, credential collection, or file modification was identified.

Attack Path

  1. A user invokes the Clairvoyance Skill in a private conversation.
  2. The user authorizes one or more listed memory or dream-record sources.
  3. The Agent reads sensitive records from the authorized paths.
  4. The Agent derives themes or patterns from those records.
  5. Sensitive details or revealing inferences may appear in the generated response.
  6. Anyone who can access the active conversation or its retained transcript may consequently ...[truncated 832 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit confirmation of every source path and the exact time range immediately before reading.
  2. Default to the shortest practical period and require renewed approval before expanding it.
  3. Present a source-access summary before processing and allow users to exclude individual files.
  4. Minimize direct quotations and avoid reproducing unnecessary identifying or highly sensitive details.
  5. Apply output redaction for credentials, authentication tokens, financial information, health details, and third-party personal data.
  6. Remind users that generated interpretations and retained conversation transcripts may reveal information derived from private records.
  7. Ensure the Skill can run only in a verified private conversation and fails closed in shared or ambiguous contexts.
  8. Preserve the existing prohibitions against writes, scripts, external calls, uploads, unrelated searches, and access to another person's data.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.