Back to skill

Security audit

neosoul-decision-agent

Security checks for vulnerabilities and agentic risk

Overview

This decision-support skill is not clearly malicious, but it automatically stores personal decision patterns and has inconsistent claims about local-only use versus API, callback, and command-execution capabilities.

Review this skill before installing. It may save your decision history and preferences under ~/decision-making and reuse them later, including in personal or business contexts. Install only if you are comfortable with that persistence, can inspect and delete the files, and can restrict network/API/callback use and command execution in your agent environment.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:157
Finding

Untrusted conversational signals can poison persistent decision memory

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:16
Finding

General command-execution permission exceeds the Skill's legitimate requirements

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest presents the skill as local-only and requiring no credentials, while the body later describes external API integration and API key configuration. This creates a trust-boundary mismatch: operators may enable the skill believing it cannot exfiltrate data or use networked services when the documentation elsewhere suggests it can.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill repeatedly claims it is local-only and does not access external systems, but later documents API keys, API usage, callback URLs, and network/API failure handling. This inconsistency can mislead users and downstream agents about data flow boundaries, causing sensitive decision-history or preference data to be sent externally under false assumptions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is explicitly designed to persist and reuse user preferences and decision history across sessions. That creates a real natural-language data retention risk: accumulated behavioral information may be surfaced later, mishandled, or accessed by other local users/processes if storage is not carefully controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises read/write/exec capability and describes persistent memory files, but the introduction does not prominently warn users that it will create and modify files under ~/decision-making/. Users may provide personal information without realizing it will be retained across sessions on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented callback_url parameter introduces potential outbound transmission, yet no privacy warning explains what data may be sent, when callbacks occur, or how to constrain destinations. In a skill that stores and processes personal decision history, silent callback support materially increases data exfiltration risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions tell the agent to automatically record user statements into memory and decision logs, effectively turning ordinary conversation into ongoing personal data collection. Automatic capture raises privacy risk because users may not realize which statements are being stored or how long they will remain available for later reuse.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Prompting the agent to proactively reference historical preferences back to the user increases the chance that retained private behavioral data will be disclosed in contexts where the user did not expect it. This is especially risky in shared screens, logs, demos, or multi-user environments where old personal patterns may be revealed inadvertently.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example normalizes quoting stored historical patterns from memory files back into responses, reinforcing a workflow that exposes retained personal data as standard behavior. This increases the likelihood of over-disclosure of behavioral preferences and past decisions in future conversations or logs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document claims it does not store personal sensitive information, but the core design persists user preferences, personal-life decision patterns, reversals, and decision history to local files. Even if not labeled as 'sensitive,' this behavioral history can become sensitive personal data and create privacy and disclosure risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The display name, summary, description, and nearly all user-facing instructions are written only in Chinese, with no indication that users may choose another language. This can constitute a language/locale policy issue when the skill effectively defaults to a single language without opt-in or an explicit documented constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.