Back to skill

Security audit

记忆蒸馏器

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent log-compression purpose, but it directs execution of a missing script and modifies persistent memory/log files with weak safeguards.

Review before installing. Use only with logs you are comfortable preserving, add secret and personal-data redaction before compression, avoid shared /tmp output paths, require explicit review before appending to MEMORY.md, and do not move original logs unless you have backups and a rollback plan. The package also needs the missing compressor script supplied and audited before execution.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:87
Finding

Predictable Temporary Files Can Poison Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 87-94 and 217-220
Vulnerability Type: Predictable temporary-file use followed by an unsafe persistent-memory append
Risk Level: Medium

Complete Code Snippet

bash
node scripts/memory-compress.js memory/2026-07-18.md

# Specify an output file
node scripts/memory-compress.js memory/2026-07-18.md /tmp/compressed.md

# Append the compressed output to curated memory
node scripts/memory-compress.js memory/2026-07-18.md /tmp/today.md
cat /tmp/today.md >> MEMORY.md
markdown
## Memory maintenance (every 2-3 days)
1. Run: node scripts/memory-compress.js memory/YYYY-MM-DD.md /tmp/compressed.md
2. Review the compressed result for accuracy
3. Append: cat /tmp/compressed.md >> MEMORY.md
4. Record the maintenance time: date +%s > .last-memory-maintenance

Technical Analysis

The documented workflow uses fixed names in the shared /tmp directory and later appends their contents to persistent Agent memory. Predictable shared temporary paths are vulnerable to pre-creation, stale-file reuse, symlink manipulation, and time-of-check/time-of-use replacement by another local principal able to write to /tmp.

The first example performs the append as a separate command rather than conditionally executing it only after successful compression. If the compressor fails, an existing /tmp/today.md may still be appended. Although the maintenance workflow requests human review, it does not prescribe file ownership, type, permissions, or integrity checks and does not prevent replacement between review and append.

The compressor implementation referenced by these instructions is absent from the audited package, so its handling of existing files and symbolic links cannot be verified. The finding is therefore based on the unsafe workflow explicitly prescribed by SKILL.md, not on unobserved script behavior.

Attack Path

  1. An attacker with access to the same host and shared /tmp directory cr ...[truncated 1260 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a private temporary directory with restrictive permissions:
bash
tmpdir="$(mktemp -d)" || exit 1
chmod 700 "$tmpdir"
trap 'rm -rf -- "$tmpdir"' EXIT
output="$tmpdir/compressed.md"
  1. Append only if compression succeeds:
bash
node scripts/memory-compress.js memory/2026-07-18.md "$output" &&
  cat -- "$output" >> MEMORY.md
  1. Before appending, verify that the output is a regular file, is not a symbolic link, is owned by the current user, and has restrictive permissions.
  2. Keep validation and append in one trusted process where possible to reduce replacement races.
  3. Display and explicitly approve a diff before modifying persistent memory.
  4. Parse generated summaries as untrusted data. Do not treat instructions embedded in source logs or summaries as Agent directives.
  5. Prefer an atomic update: construct a validated replacement file in the same directory as MEMORY.md, synchronize it, and rename it into place.
  6. Bundle and audit the referenced scripts/memory-compress.js implementation, including its existing-file, symbolic-link, path-validation, and error-handling behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list includes broad, generic phrases like '日志归档' and '上下文压缩' that could match routine user requests and invoke the skill unexpectedly. In a skill with exec capability and file-modifying workflows, accidental invocation increases the chance of unintended processing of sensitive logs or follow-on destructive actions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The 'zero data loss' and fallback extraction requirements encourage retaining nearly all salient log content and reproducing it in summaries, which raises the chance that secrets, personal data, or sensitive operational details are carried into derived memory artifacts. Because the skill is specifically designed for AI agent logs, the source material is likely to contain prompts, tokens, internal paths, incident details, or user content that should be minimized rather than preserved.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Requiring 100% source-trace coverage and line-level backreferences creates a direct bridge from summary artifacts to sensitive raw logs, making summaries a discovery index for confidential material. Even when the summary itself is brief, exact file paths, section names, and line numbers can expose internal structure and materially simplify retrieval of secrets or private conversation content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs moving original logs to an archive after compression without an explicit warning that this changes the filesystem and may impair access, tooling assumptions, or retention workflows. Even if 'mv' is not deletion, it is a state-changing operation that can effectively hide data, break references, or cause loss if archive paths are not backed up or later cleaned.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The long-conversation compression workflow explicitly preserves and reloads conversation history, which can perpetuate sensitive user inputs, system prompts, credentials, and other contextual secrets across future sessions. Reloading distilled history back into context also increases the blast radius of any earlier accidental disclosure by making that data repeatedly available to later tools, prompts, or users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.