Back to skill

Security audit

记忆编排器

Security checks for vulnerabilities and agentic risk

Overview

This memory-management skill is coherent but should be reviewed because it encourages broad, long-lived storage of user data with weak safeguards.

Review before installing. Use this only if you want an agent to manage persistent memory, and avoid saving sensitive personal, account, business, legal, medical, or credential-like data unless storage location, retention, deletion, and access controls are clear. Prefer explicit approval before save/load/cleanup actions and avoid plaintext cleanup logs containing memory contents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The cleanup log examples include raw memory identifiers and plaintext memory contents, such as user preferences and project background, written to a log file. Logging sensitive content creates a secondary disclosure channel that is often less protected, longer-lived, broadly accessible, and easily overlooked during deletion or compliance workflows.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly recommends storing identity information, core preferences, and key decisions in long-term or never-cleared memory. Persisting this class of personal and high-sensitivity data without minimization, classification, consent, or protection guidance increases the risk of privacy violations, over-retention, and downstream disclosure through retrieval, persistence, or logs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples instruct the agent to store personal user preferences and role-related details, then persist them to disk. Concrete examples strongly influence implementation behavior, so these snippets normalize long-term retention of personal data and may cause agents to save sensitive content locally without access controls or user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill documents loading, saving, and lifecycle management of memory to disk but does not present a clear user-facing warning that these operations can permanently retain, overwrite, archive, or expose user data. In a memory-management skill, silent persistence and retention changes are security-relevant because agents may apply them to sensitive conversation content without meaningful user awareness or consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs saving all memories to a disk file, which may include accumulated user conversations, preferences, and other sensitive data. Without safeguards such as minimization, encryption, path restrictions, and consent, bulk persistence materially increases exposure from local compromise, backup leakage, accidental sharing, or insecure multi-agent environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The automatic cleanup section describes archival, deletion, and logging of memory entries, including expiry-based actions, without an explicit warning that user data may be moved or removed automatically. This is dangerous because users or calling agents may assume memory is stable, while the skill can silently change retention state or delete information that may be sensitive, regulated, or operationally important.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.