T02 · Agent Memory Poisoning
- Location
SKILL.md:76- Finding
Unfiltered persistence of sensitive and attacker-controlled conversation content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent memory-summarization purpose, but it asks agents to persist conversation history, personal data, verification codes, and temporary links, including through scheduled unattended runs.
Review this skill carefully before installing. It may save private conversation details, personal preferences, project information, verification codes, and temporary links into files that can persist across sessions or be picked up by other tools. Avoid scheduled mode unless you have confirmed what will be written, where the files live, how sensitive content is filtered, and how old memory is removed.
SKILL.md:76Unfiltered persistence of sensitive and attacker-controlled conversation content
The skill is designed to extract conversation content and persist it into structured files, but it does not clearly warn users about privacy risks, sensitive-data retention, or downstream access to stored memory. This creates a real risk of users unintentionally causing personal, confidential, or regulated data to be written to disk without informed consent.
The cron and heartbeat integration enable unattended, repeated extraction and persistence of conversation data, increasing the chance that sensitive information is stored without active user review. Scheduled execution makes the risk worse because data collection can continue automatically even when the user is not consciously invoking the feature.
The scheduled payload instructs the agent to analyze daily conversations and write extracted content into persistent memory files automatically. In context, this amplifies the privacy risk because the collection is broad, periodic, and unattended, making accidental retention of confidential or regulated data much more likely.
The skill explicitly instructs scanning full conversation history and storing personal preferences, contact information, and temporary sensitive information such as verification codes or temporary links into persistent files. Persisting these categories materially increases exposure risk because secrets and personal data may outlive their original context, be accessible to other tools/users, or be mishandled during later processing.
L155 states '蒸馏不删除记忆文件,只提取和整理', which asserts a no-deletion behavior. However, the manifest and workflow describe '自动清理过期内容' and '标记或删除过期内容' (L003, L017, L121), so the documentation contradicts itself on whether deletion can occur.
The schema mixes an English title with Chinese-only descriptions for the file and all properties, and hard-codes the default timezone to Asia/Shanghai. This creates a natural-language and locale constraint without offering users any language or locale choice or documenting that the configuration is intended only for a China-specific deployment.
The manifest description, trigger phrases, and user instructions are presented in Chinese throughout the file. This effectively imposes a language/locale requirement on users without any explicit opt-in, alternative language support, or documented justification for a China-specific audience.
No suspicious patterns detected.