Back to skill

Security audit

SwarmRecall Learnings

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent, but it can automatically send command failures and persistent learning data to a remote service in ways that may expose sensitive information or shape future sessions.

Install only if you are comfortable with errors, corrections, discoveries, and possibly command output being stored on SwarmRecall servers. Avoid using it in repositories or terminals where failures may print secrets, tokens, private code, customer data, or sensitive paths unless you add your own redaction and approval step. Verify SWARMRECALL_API_URL is unset or points only to the intended trusted HTTPS service before use, and treat shared-pool learnings as untrusted suggestions rather than instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

other

Error
Location
SKILL.md:115
Finding

Automatic External Transmission of Potentially Sensitive Command Output

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:117
Finding

Untrusted Remote and Shared-Pool Learnings Can Poison Agent Behavior and Persistent State

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:38
Finding

API Base URL Override Can Redirect Bearer Credentials and Learning Data

Content
View full analysis
``` ## API Base URL `https://swarmrecall-api.onrender.com` (override with `SWARMRECALL_API_URL` if set) ``` ### Technical Analysis The Skill permits the API origin to be replaced using the `SWARMRECALL_API_URL` environment variable while requiring the bearer API key to be attached to all API requests. It does not specify an origin allowlist, hostname validation, an HTTPS-only requirement for overrides, certificate constraints, or user confirmation when the destination differs from the documented service. Environment variables can be inherited from process launchers, containers, automation systems, shell profiles, or compromised execution environments. If the override is attacker-controlled, requests can be redirected to an attacker-operated endpoint. Following the documented authentication rule would then disclose the bearer credential in the `Authorization` header, along with any learning data included in requests. ### Attack Path 1. An attacker or compromised launcher sets `SWARMRECALL_API_URL` to an attacker-controlled server. 2. The agent reads the environment variable and replaces the documented SwarmRecall API origin. 3. The agent performs registration, learning, search, pattern, or promotion operations against the substituted endpoint. 4. In accordance with the authentication instructions, the agent includes `Authorization: Bearer `. 5. The attacker captures the bearer key and any transmitted error details, command output, corrections, or metadata. 6. The captured key may then be used against the legitimate service if the token is accepted there, allowing access within the token's authorization scope. 7. The malicious endpoint can also ...[truncated 754 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to send failed command output, summaries, details, and session learnings to an external service, and such data can easily contain secrets, personal data, tokens, filesystem paths, proprietary code, or internal system details. Although the document mentions consent for user-provided content, the behavioral instruction is broad and automatic enough to create a real risk of sensitive data exfiltration to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to automatically call remote endpoints on session start without explicit user notice or opt-in at that moment. This creates a privacy and policy risk because merely starting a session can transmit agent context, identifiers, or usage metadata to a third-party service before the user has consented to external communication.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The 'Dreaming Integration' section says the agent should create learnings with category: "best_practice" and archive subsumed learnings, but the earlier endpoint documentation only enumerates categories error | correction | discovery | optimization | preference and the update schema only shows resolution-related fields. This is an active contradiction in the skill documentation about what operations and values are supported.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction hard-codes a specific English-language message for user communication. Under the language/locale policy, forcing a specific language without user choice or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.