Back to skill

Security audit

Memory Distill

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent memory-summarization purpose, but it asks agents to persist conversation history, personal data, verification codes, and temporary links, including through scheduled unattended runs.

Review this skill carefully before installing. It may save private conversation details, personal preferences, project information, verification codes, and temporary links into files that can persist across sessions or be picked up by other tools. Avoid scheduled mode unless you have confirmed what will be written, where the files live, how sensitive content is filtered, and how old memory is removed.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:76
Finding

Unfiltered persistence of sensitive and attacker-controlled conversation content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to extract conversation content and persist it into structured files, but it does not clearly warn users about privacy risks, sensitive-data retention, or downstream access to stored memory. This creates a real risk of users unintentionally causing personal, confidential, or regulated data to be written to disk without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The cron and heartbeat integration enable unattended, repeated extraction and persistence of conversation data, increasing the chance that sensitive information is stored without active user review. Scheduled execution makes the risk worse because data collection can continue automatically even when the user is not consciously invoking the feature.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The scheduled payload instructs the agent to analyze daily conversations and write extracted content into persistent memory files automatically. In context, this amplifies the privacy risk because the collection is broad, periodic, and unattended, making accidental retention of confidential or regulated data much more likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs scanning full conversation history and storing personal preferences, contact information, and temporary sensitive information such as verification codes or temporary links into persistent files. Persisting these categories materially increases exposure risk because secrets and personal data may outlive their original context, be accessible to other tools/users, or be mishandled during later processing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

L155 states '蒸馏不删除记忆文件,只提取和整理', which asserts a no-deletion behavior. However, the manifest and workflow describe '自动清理过期内容' and '标记或删除过期内容' (L003, L017, L121), so the documentation contradicts itself on whether deletion can occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The schema mixes an English title with Chinese-only descriptions for the file and all properties, and hard-codes the default timezone to Asia/Shanghai. This creates a natural-language and locale constraint without offering users any language or locale choice or documenting that the configuration is intended only for a China-specific deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description, trigger phrases, and user instructions are presented in Chinese throughout the file. This effectively imposes a language/locale requirement on users without any explicit opt-in, alternative language support, or documented justification for a China-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.