T09 · Insecure Skill Coding Practices
- Location
references/detection-heuristics.md:68- Finding
Sensitive credentials may be persisted as cognitive-state memory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent agent self-monitoring aid, but it under-controls persistent memory/logging and can cause sensitive conversation details, including credentials, to be saved.
Review before installing. Use this only if you are comfortable with agent memory and local logs, and do not let it persist credentials, tokens, private keys, session cookies, personal data, or sensitive environment details. If using the cron guardian, keep it user-scoped, protect log files, add retention limits, and document how to remove the scheduled job.
references/detection-heuristics.md:68Sensitive credentials may be persisted as cognitive-state memory
templates/guardian-cronjob.yaml:27Optional guardian creates recurring execution without lifecycle or log-retention safeguards
The code substantially aligns with the declared purpose: it detects and reports multiple cognitive-state degradation conditions including context fatigue, attention drift, memory debt, confidence erosion, and skill staleness. It does not perform risky undeclared actions or access sensitive resources. However, there is a mild but material description/behavior mismatch in two respects: first, the script includes an additional cognitive-state detector, Context Fragmentation, that is not mentioned in the declared description. Second, although the description says 'detect, report, and mitigate,' the implementation only detects and reports, with mitigation represented as textual recommendations rather than actual remediation. Because the primary purpose is still close, this is a limited mismatch rather than a severe one.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
signal = "; ".join(signal_parts)
impact = "Following outdated instructions produces errors and wasted effort"
action = "Patch skill with corrected commands/paths before continuing"
return CognitiveState(
name="Skill Staleness",
This section normalizes persisting 'critical facts,' decisions, and other conversation details to memory before they are lost. In a self-monitoring skill, that context makes the issue more dangerous because the retention is framed as routine reliability behavior, which can lead agents to store sensitive user information without necessity, minimization, or consent.
Directing the agent to write a brief session summary to memory or a file introduces session persistence of potentially sensitive conversational content. In this skill's context, persistence is presented as a standard mitigation step, which increases the likelihood of storing confidential requirements, decisions, or environment details without clear boundaries or user approval.
### Context Fatigue → Consolidate & Split
1. Persist all critical facts, decisions, and TODO state to memory
2. Write a brief session summary to memory or a file
3. Suggest `/new` or session split for remaining work
4. If user wants to continue: prioritize ruthlessly, ignore tangent topics
The skill instructs the agent to scan recent exchanges for preferences, decisions, corrections, and environment facts, then batch-write them to memory. That creates a concrete over-collection pattern: broad semantic extraction from conversation into persistent storage, increasing the risk of retaining sensitive personal, project, or environmental data beyond what is needed.
The template establishes recurring execution of a script that reads active session state and, in the non-Hermes example, derives parameters from a session log under /tmp and writes results to a persistent log file. This creates a session-persistence/data-retention surface: session metadata may be repeatedly accessed and stored beyond the immediate interaction, which can expose operational context or sensitive user-derived data if log locations or temporary files are not adequately protected.
# during autonomous/long-running work and alerts the user if degraded.
#
# Usage with Hermes Agent cronjob system:
# hermes cron create --schedule "every 10m" --script scripts/self_check.py
#
# Or as a YAML config for other cron systems:
The skill explicitly recommends appending cognitive state data to a local log file without warning about persistence, retention, or access controls. Even if the example payload is small, operational use can easily expand to include conversation-derived state, timestamps, and workflow details that may be sensitive on shared systems or developer machines.
Passive logging without interrupting the conversation encourages silent retention of state data and normalizes background collection. While the shown example is limited to cognitive-state metadata, the surrounding skill context promotes persistence of conversation-derived information, which makes silent logging a privacy and auditability concern.
This manifest-style YAML template describes usage with a cron system but does not clearly constrain when this skill should be activated beyond generic recurring scheduling. Because it lacks explicit trigger boundaries or exclusion conditions, it could be adopted in broader contexts than intended for autonomous monitoring.
No suspicious patterns detected.