other
- Location
SKILL.md:35- Finding
Automatic External Capture of Conversation Data Without Granular Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This encrypted memory skill is mostly disclosed, but it automatically stores conversation facts externally and changes runtime/plugin state with too little user control.
Review this carefully before installing. Confirm you are comfortable with automatic extraction of facts from future conversations into external encrypted storage, require an explicit way to pause/delete/export memory, use a pinned and verified plugin version, avoid the wildcard rm -rf reinstall command, and approve any gateway reload or restart yourself.
SKILL.md:35Automatic External Capture of Conversation Data Without Granular Consent
SKILL.md:54Unauthorized Gateway Configuration and Autonomous Runtime Reload
SKILL.md:49Execution of an Unpinned Third-Party Plugin Dependency
SKILL.md:60Broad Recursive Deletion During Reinstallation
SKILL.md:77Detached Pairing Process Without Lifecycle Supervision
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
12词恢复短语**绝不能**进入聊天或代理的LLM上下文。配对流程通过浏览器处理短语生成与导入。绝不要回显它,绝不要要求用户粘贴它,绝不要将其传递给任何工具。如用户无论如何粘贴了一个,告知其已泄露并重新配对以获得新钱包。
**硬性约束 — 安装/重装/升级流程:** 在安装、重装、升级或任何验证步骤期间,代理**绝不能**读取、列出、cat、显示或检查 `credentials.json`、`~/.tool-orchestrator/credentials.json`、`~/.tool-orchestrator*/credentials.json` 或任何凭据/短语/密钥/机密文件 — 无论出于任何原因,包括"验证安装"。这些文件包含加密密钥材料和智能账户地址,**绝不能**进入LLM上下文。绝不要运行 `ls`、`find`、`cat`、`show` 或类似命令针对插件目录来"检查文件"。
## 安装
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
12词恢复短语**绝不能**进入聊天或代理的LLM上下文。配对流程通过浏览器处理短语生成与导入。绝不要回显它,绝不要要求用户粘贴它,绝不要将其传递给任何工具。如用户无论如何粘贴了一个,告知其已泄露并重新配对以获得新钱包。
**硬性约束 — 安装/重装/升级流程:** 在安装、重装、升级或任何验证步骤期间,代理**绝不能**读取、列出、cat、显示或检查 `credentials.json`、`~/.tool-orchestrator/credentials.json`、`~/.tool-orchestrator*/credentials.json` 或任何凭据/短语/密钥/机密文件 — 无论出于任何原因,包括"验证安装"。这些文件包含加密密钥材料和智能账户地址,**绝不能**进入LLM上下文。绝不要运行 `ls`、`find`、`cat`、`show` 或类似命令针对插件目录来"检查文件"。
## 安装
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
12词恢复短语**绝不能**进入聊天或代理的LLM上下文。配对流程通过浏览器处理短语生成与导入。绝不要回显它,绝不要要求用户粘贴它,绝不要将其传递给任何工具。如用户无论如何粘贴了一个,告知其已泄露并重新配对以获得新钱包。
**硬性约束 — 安装/重装/升级流程:** 在安装、重装、升级或任何验证步骤期间,代理**绝不能**读取、列出、cat、显示或检查 `credentials.json`、`~/.tool-orchestrator/credentials.json`、`~/.tool-orchestrator*/credentials.json` 或任何凭据/短语/密钥/机密文件 — 无论出于任何原因,包括"验证安装"。这些文件包含加密密钥材料和智能账户地址,**绝不能**进入LLM上下文。绝不要运行 `ls`、`find`、`cat`、`show` 或类似命令针对插件目录来"检查文件"。
## 安装
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
12词恢复短语**绝不能**进入聊天或代理的LLM上下文。配对流程通过浏览器处理短语生成与导入。绝不要回显它,绝不要要求用户粘贴它,绝不要将其传递给任何工具。如用户无论如何粘贴了一个,告知其已泄露并重新配对以获得新钱包。
**硬性约束 — 安装/重装/升级流程:** 在安装、重装、升级或任何验证步骤期间,代理**绝不能**读取、列出、cat、显示或检查 `credentials.json`、`~/.tool-orchestrator/credentials.json`、`~/.tool-orchestrator*/credentials.json` 或任何凭据/短语/密钥/机密文件 — 无论出于任何原因,包括"验证安装"。这些文件包含加密密钥材料和智能账户地址,**绝不能**进入LLM上下文。绝不要运行 `ls`、`find`、`cat`、`show` 或类似命令针对插件目录来"检查文件"。
## 安装
The specific wildcarded path rm -rf ~/.platform/npm/projects/*tool-orchestrator* is a true destructive-operation risk. Wildcards combined with recursive deletion can match more than intended, and in an automated agent workflow this can lead to accidental removal of unrelated project data or make recovery difficult.
plugins uninstall tool-orchestrator
rm -rf ~/.platform/npm/projects/*tool-orchestrator*
plugins install @tool-orchestrator/tool-orchestrator
plugins enable tool-orchestrator
The specific wildcarded path rm -rf ~/.platform/npm/projects/*tool-orchestrator* is a true destructive-operation risk. Wildcards combined with recursive deletion can match more than intended, and in an automated agent workflow this can lead to accidental removal of unrelated project data or make recovery difficult.
plugins uninstall tool-orchestrator
rm -rf ~/.platform/npm/projects/*tool-orchestrator*
plugins install @tool-orchestrator/tool-orchestrator
plugins enable tool-orchestrator
The skill's display name, summary, description, and all operational instructions are written exclusively in Chinese, with no indication that users may choose another language. This creates a locale/language constraint in the skill's natural-language interface without documented opt-in or region-specific justification.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
通过插件的进程内HTTP路由创建配对会话:
curl -s http://localhost:18789/plugin/tool-orchestrator/pair/init
→ 返回 {"url":"https://…/pair/p/<id>#pk=…","pin":"123456","expires_at_ms":…}
The fallback instruction uses setsid -f to detach a long-lived background process from the agent session. In an exec-capable agent environment, detached processes reduce auditability and can persist beyond the user's intent, potentially leaving unmanaged network-connected tooling running.
→ 返回 `{"url":"https://…/pair/p/<id>#pk=…","pin":"123456","expires_at_ms":…}`
**不要使用 `tr pair --json`。** CLI在子进程中持有配对WebSocket,会被约30秒shell工具超时杀死,WS随后断开,用户提交短语时中继返回502。上述进程内路由完全避免此问题。仅在路由不可达时回退到CLI,且必须分离运行使WS存活: `setsid -f node "$TR_CLI" pair --json < /dev/null`。
2. 原样向用户展示 **url** 和 **pin**(从JSON读取,绝不编造值):"在浏览器中打开 `<url>`,输入PIN `<pin>`,生成或粘贴你的12词恢复短语。完成后回复done。" URL作为纯文本单独一行输出,`#pk=` 片段在反引号/markdown中会损坏。
The reinstall instructions include a recursive deletion command against a wildcarded package path without strong safety guardrails. In an agent context with exec enabled, destructive shell snippets can cause unintended data loss or be misapplied if path expansion behaves unexpectedly or the environment differs from assumptions.
No suspicious patterns detected.