Back to skill

Security audit

记忆堡垒(专业版)

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a memory tool, but it asks for broad file and shell authority while also encouraging automatic memory capture, cloud sync, and unrelated system administration actions.

Review carefully before installing. Use only in workspaces where durable memory and possible cloud synchronization are acceptable, avoid storing secrets or sensitive personal/business data, disable or constrain automatic extraction where possible, and do not follow the unrelated system administration sections unless you separately trust and intend that capability.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Intent-Code Divergence

High
Confidence
91% confidence
Finding
The later sections radically shift from an AI memory-management skill into broad OS/system optimization, process control, service management, disk operations, and firewall functionality. This capability drift is dangerous because it can mislead an agent or user into invoking high-privilege administrative actions outside the declared trust boundary of the skill.

Context-Inappropriate Capability

High
Confidence
93% confidence
Finding
The documentation introduces broad system administration actions such as process, service, disk, and firewall management that are unrelated to memory persistence for AI agents. In a skill that already has Bash, Read, Write, and Edit permissions, this overbroad scope increases the risk of destructive or unauthorized host modifications if an agent follows the misleading instructions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger guidance says to use the skill broadly for AI model calls, intelligent dialogue, agent orchestration, and LLM applications, which can cause the skill to activate in many unrelated contexts. Because the skill persists data and can use Bash and cloud sync features, over-triggering raises the chance of unnecessary retention, unexpected writes, or unsafe side effects.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The example trigger phrase is overly vague and likely to appear in ordinary conversation, which can cause accidental skill invocation. In this skill, accidental invocation is more dangerous because the documented behavior includes persisting user statements and synchronizing memory across stores and cloud services.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The cloud sync section promotes cross-device synchronization but does not clearly warn users that conversation-derived memory may be transmitted off-device to external services. This creates a privacy and data-governance risk, especially if sensitive business, personal, or regulated information is stored automatically.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The automatic fact extraction section describes analyzing conversations and storing extracted facts, but it does not clearly warn that sensitive content may be captured without per-item human review. This is risky because users may disclose secrets, personal data, or confidential decisions in normal conversation that then become durable memory artifacts.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill encourages automatic retention and propagation of conversation-derived data into long-term and cloud-backed memory systems. This is dangerous because it normalizes silent collection and wider distribution of potentially sensitive information beyond the immediate session, expanding exposure and breach impact.

Ssd 3

Medium
Confidence
96% confidence
Finding
The WAL rules explicitly instruct the agent to persist user preferences, decisions, deadlines, corrections, and facts before responding. This creates a strong risk of storing sensitive or incorrect data without validation or consent, and makes accidental disclosure more likely because the data becomes durable across sessions and systems.

Ssd 3

Medium
Confidence
93% confidence
Finding
The scenario guidance normalizes storing broad categories of discussions, meeting records, stakeholder feedback, contacts, and project context in long-term and cloud-backed memory. This is dangerous because it encourages over-collection and cross-context aggregation of sensitive organizational and personal data beyond what is necessary for the immediate task.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.