other
- Location
SKILL.md:115- Finding
Automatic External Transmission of Potentially Sensitive Command Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent, but it can automatically send command failures and persistent learning data to a remote service in ways that may expose sensitive information or shape future sessions.
Install only if you are comfortable with errors, corrections, discoveries, and possibly command output being stored on SwarmRecall servers. Avoid using it in repositories or terminals where failures may print secrets, tokens, private code, customer data, or sensitive paths unless you add your own redaction and approval step. Verify SWARMRECALL_API_URL is unset or points only to the intended trusted HTTPS service before use, and treat shared-pool learnings as untrusted suggestions rather than instructions.
SKILL.md:115Automatic External Transmission of Potentially Sensitive Command Output
SKILL.md:117Untrusted Remote and Shared-Pool Learnings Can Poison Agent Behavior and Persistent State
SKILL.md:38API Base URL Override Can Redirect Bearer Credentials and Learning Data
The skill directs the agent to send failed command output, summaries, details, and session learnings to an external service, and such data can easily contain secrets, personal data, tokens, filesystem paths, proprietary code, or internal system details. Although the document mentions consent for user-provided content, the behavioral instruction is broad and automatic enough to create a real risk of sensitive data exfiltration to a third party.
The skill instructs the agent to automatically call remote endpoints on session start without explicit user notice or opt-in at that moment. This creates a privacy and policy risk because merely starting a session can transmit agent context, identifiers, or usage metadata to a third-party service before the user has consented to external communication.
The 'Dreaming Integration' section says the agent should create learnings with category: "best_practice" and archive subsumed learnings, but the earlier endpoint documentation only enumerates categories error | correction | discovery | optimization | preference and the update schema only shows resolution-related fields. This is an active contradiction in the skill documentation about what operations and values are supported.
The instruction hard-codes a specific English-language message for user communication. Under the language/locale policy, forcing a specific language without user choice or documented justification is a natural-language policy violation.
No suspicious patterns detected.