Back to skill

Security audit

SwarmVault

Security checks for vulnerabilities and agentic risk

Overview

SwarmVault is a coherent local knowledge-vault skill, but it asks users to install a mutable global CLI that can persist hooks, intercept agent searches, index sensitive files, and optionally route content to external providers.

Install only if you are comfortable with a global npm CLI reading and writing vault artifacts in your projects. Prefer project-scoped setup, avoid --scope user and --graph-first until reviewed, keep sensitive files like .env out of ingests, use SWARMVAULT_OUT or ignore rules to isolate outputs, and review share/export/provider settings before publishing or sending content to remote services.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
README.md:208
Finding

Agent Hooks Inject Instructions and Intercept Search Tools

Content
View full analysis
swarmvault init && swarmvault ingest . swarmvault install --agent claude --hook --mcp --graph-first # --graph-first opts in to search enforcement swarmvault hook install # git-hook refresh on commit/checkout (pass a repo path when the repo lives below the vault root) ``` ```text For hook-capable agents, the installed hooks guide graph-first reads. The Claude Code hook injects graph-first instructions at session start — answer code-understanding questions with the plain `swarmvault graph query|explain|path` commands (avoid `--json`, which produces much larger output), `swarmvault query`, `swarmvault context build`, or `wiki/graph/report.md`, and read source files only when editing them — plus a graph staleness note. `swarmvault graph query ""` prints the top matches with page paths plus an inline excerpt of the best-matching wiki page, so one command usually answers where-is/what-calls questions without follow-up file reads. By default the hook is advisory: the first broad Grep/Glob/Bash search per session gets a one-time guidance note. Opt in to enforcement with `--graph-first` (persists `hooks.graphFirst: "deny"`), which denies that first search with the same guided redirect — repeating the search is then allowed, so work is never blocked. Either way the hook spawns a background `swarmvault graph update --file ` refresh after every Edit/Write. ``` ### Technical Analysis The documented agent integration installs hooks that inject SwarmVault-controlled instructions at session startup and intercept broad Grep, Glob, and Bash searches. In enforcement mode, the first matching tool invocation is denied and redirected toward SwarmVault-generated graph artifacts and CLI commands. This changes the agent's normal tool-selection behavior and ...[truncated 1729 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
SKILL.md:111
Finding

Persistent Project and User-Scope Hooks Execute the External CLI Across Sessions

Content
View full analysis
[--hook] [--mcp]` to inspect expected files without writing. - `swarmvault install --agent claude --mcp` also registers the SwarmVault MCP server in the project's `.mcp.json`; `swarmvault install --agent claude --hook --scope user` installs the skill, hook, and settings once under `~/.claude` for all repos (the hook no-ops in repos without a compiled graph report). ``` Related persistent Git-hook behavior is documented in `examples/graph-first-agent-workflow.md:33-35`: ```text - After the agent edits a file, a background `swarmvault graph update --file ` refresh runs and `swarmvault graph status .` reports the graph fresh again - Concurrent edit bursts coalesce through the refresh lock plus queue under `state/watch/` instead of stacking compiles - `swarmvault hook install` adds the git `post-commit`/`post-checkout` refresh so branch switches stay current too ``` ### Technical Analysis The Skill instructs users to install project-level and user-level agent hooks, project MCP configuration, and Git `post-commit`/`post-checkout` hooks. These components survive the initial Skill invocation and execute or expose the external `swarmvault` binary during future edits, agent sessions, commits, and checkouts. User-scope installation under `~/.claude` increases the scope beyond a single project. Git ...[truncated 1451 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
README.md:120
Finding

Directory Ingestion Can Route Sensitive Environment Files to Remote Model Providers

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
README.md:7
Finding

Unpinned Global npm Dependency Controls All Executable Behavior

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (23)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
onboarding, examples, command references, or troubleshooting, read the bundled `README.md`, `examples/`, `references/`, and `TROUBLESHOOTING.md` before improvis

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow includes graph share --post and other share/export commands that can publish repository-derived graph artifacts, summaries, and visualizations, but it provides no explicit warning that these outputs may expose proprietary code structure, internal relationships, or sensitive repository metadata. In the context of a tool designed to compile codebases into reviewable artifacts, sharing features are especially risky because users may treat generated reports as harmless abstractions even when they encode confidential implementation details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README prominently encourages ingesting and durably storing highly sensitive materials such as emails, calendars, transcripts, chat exports, screenshots, and research captures, but it does not place an explicit privacy/sensitivity warning near those workflows. In a skill designed for agent-driven automation and persistent disk writes, this omission increases the risk that users will unintentionally centralize secrets, personal data, regulated content, or privileged business information into a long-lived local corpus that may later be queried, exported, shared, or committed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README documents commands that generate share cards, bundles, exports, and post-ready summaries from the compiled vault without a prominent warning that these artifacts may contain sensitive derived knowledge from ingested private sources. Because the tool aggregates and synthesizes many sources into portable outputs, users may disclose confidential information through convenient sharing features even when the original raw sources were intended to stay local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes optional provider-backed synthesis, embeddings, reranking, audio transcription, image handling, and web-backed lint augmentation, but it does not consistently and explicitly warn users that non-code text, media, or search queries may be transmitted to third-party services when those features are configured. In a vault product centered on sensitive local knowledge, this can cause accidental exfiltration of confidential or regulated content under the assumption that all processing remains local-first.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 219)May include surrounding context.

md
For hook-capable agents, the installed hooks guide graph-first reads. The Claude Code hook injects graph-first instructions at session start — answer code-understanding questions with the plain `swarmvault graph query|explain|path` commands (avoid `--json`, which produces much larger output), `swarmvault query`, `swarmvault context build`, or `wiki/graph/report.md`, and read source files only when editing them — plus a graph staleness note. `swarmvault graph query "<seed>"` prints the top matches with page paths plus an inline excerpt of the best-matching wiki page, so one command usually answers where-is/what-calls questions without follow-up file reads. By default the hook is advisory: the first broad Grep/Glob/Bash search per session gets a one-time guidance note. Opt in to enforcement with `--graph-first` (persists `hooks.graphFirst: "deny"`), which denies that first search with the same guided redirect — repeating the search is then allowed, so work is never blocked. Either way the hook spawns a background `swarmvault graph update --file <path>` refresh after every Edit/Write. Searches scoped to vault artifact directories (`wiki/`, `raw/`, `state/`), single files, or search tools filtering piped output are never intercepted. `SWARMVAULT_GRAPH_FIRST=deny|context|off` overrides per session. The Codex, Gemini, Copilot, OpenCode, and Kilo hooks carry the same graph-first guidance with a session note plus a one-time search redirect appropriate to each tool's hook API.

`swarmvault install --agent claude --mcp` also registers the SwarmVault MCP server in the project's `.mcp.json` (`{"mcpServers":{"swarmvault":{"command":"swarmvault","args":["mcp"]}}}`). Claude installs additionally write a project skill bundle at `.claude/skills/swarmvault/SKILL.md`, and `--scope user` installs the skill, hook, and settings once under `~/.claude` for all repos — the hook no-ops in repos without a compiled graph report.

`swarmvault install --agent <agent>` also keeps the host project
...[truncated 25 chars]

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The README states that installation can persist the skill, hook, and settings under ~/.claude for all repositories, creating cross-session and cross-project persistence of agent behavior and configuration. In the context of a tool that can read, index, and persist knowledge artifacts, user-scope installation increases the blast radius of mistakes or unsafe defaults because the integration may silently affect future sessions and unrelated repos unless users understand and consent to that persistence.

Content

Scanner excerpt · README.md (reported line 219)May include surrounding context.

md
For hook-capable agents, the installed hooks guide graph-first reads. The Claude Code hook injects graph-first instructions at session start — answer code-understanding questions with the plain `swarmvault graph query|explain|path` commands (avoid `--json`, which produces much larger output), `swarmvault query`, `swarmvault context build`, or `wiki/graph/report.md`, and read source files only when editing them — plus a graph staleness note. `swarmvault graph query "<seed>"` prints the top matches with page paths plus an inline excerpt of the best-matching wiki page, so one command usually answers where-is/what-calls questions without follow-up file reads. By default the hook is advisory: the first broad Grep/Glob/Bash search per session gets a one-time guidance note. Opt in to enforcement with `--graph-first` (persists `hooks.graphFirst: "deny"`), which denies that first search with the same guided redirect — repeating the search is then allowed, so work is never blocked. Either way the hook spawns a background `swarmvault graph update --file <path>` refresh after every Edit/Write. Searches scoped to vault artifact directories (`wiki/`, `raw/`, `state/`), single files, or search tools filtering piped output are never intercepted. `SWARMVAULT_GRAPH_FIRST=deny|context|off` overrides per session. The Codex, Gemini, Copilot, OpenCode, and Kilo hooks carry the same graph-first guidance with a session note plus a one-time search redirect appropriate to each tool's hook API.

`swarmvault install --agent claude --mcp` also registers the SwarmVault MCP server in the project's `.mcp.json` (`{"mcpServers":{"swarmvault":{"command":"swarmvault","args":["mcp"]}}}`). Claude installs additionally write a project skill bundle at `.claude/skills/swarmvault/SKILL.md`, and `--scope user` installs the skill, hook, and settings once under `~/.claude` for all repos — the hook no-ops in repos without a compiled graph report.

`swarmvault install --agent <agent>` also keeps the host project
...[truncated 25 chars]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill repeatedly instructs the agent to initialize a vault, ingest content, compile artifacts, and persist outputs under project-local directories, but it does not give an upfront warning that these actions create and modify on-disk files and may store sensitive source material, transcripts, chat sessions, or derived knowledge artifacts. In an agent setting, this can cause unintended persistence of confidential data or unexpected repository modifications without sufficiently informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages use of network-capable features such as ingesting URLs and public GitHub repositories, sharing graph artifacts, using MCP, optional web/deep-lint providers, video URL retrieval, and provider-backed processing, but it does not clearly warn that user data, repository contents, or generated artifacts may be transmitted to external services or even published publicly. In a security-sensitive environment, this omission can lead to accidental exfiltration of proprietary or personal information through seemingly routine commands.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · TROUBLESHOOTING.md (reported line 34)May include surrounding context.

md
Audio and video ingest need `tasks.audioProvider` to point at a provider with `audio` capability. Without that, SwarmVault still ingests the source and records an extraction warning instead of failing the whole run.

The quickest fully-local fix is `swarmvault provider setup --local-whisper --apply`, which installs a `local-whisper` provider (whisper.cpp shell-out), downloads the default ggml model into `~/.swarmvault/models/`, and wires `tasks.audioProvider` at it. If the command reports the binary missing, install whisper.cpp first (`brew install whisper-cpp` on macOS, `sudo apt install whisper.cpp` on Debian/Ubuntu) and re-run. Override binary or model paths with `localWhisper.binaryPath` / `localWhisper.modelPath` in `swarmvault.config.json` or `SWARMVAULT_WHISPER_BINARY` in the environment.

Local video extraction also needs `ffmpeg` on PATH or `SWARMVAULT_FFMPEG_BINARY`. Public video URL ingest with `swarmvault ingest --video <url>` or `swarmvault add --video <url>` needs `yt-dlp` on PATH or `SWARMVAULT_YTDLP_BINARY`.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 219)May include surrounding context.

md
- `.claude/settings.json` contains the SwarmVault hook entries and `.claude/hooks/swarmvault-graph-first.js` exists after `install --agent claude --hook`
- `.mcp.json` registers the `swarmvault` MCP server (`{"mcpServers":{"swarmvault":{"command":"swarmvault","args":["mcp"]}}}`) after `--mcp`
- `.claude/skills/swarmvault/SKILL.md` exists as the project skill bundle
- A new Claude Code session starts with injected graph-first instructions plus a staleness note when `wiki/graph/report.md` exists
- With `--graph-first` installed, the first broad Grep/Glob/Bash search in a session is denied once with a redirect to the plain `graph query|explain|path` commands (the deny message warns against `--json`, which produces much larger output); repeating the same search is then allowed. Without the opt-in the hook stays advisory and only adds a one-time guidance note
- Searches scoped to `wiki/`, `raw/`, `state/`, a single file, or search tools filtering piped output pass through without interception

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · examples/graph-first-agent-workflow.md (reported line 27)May include surrounding context.

md
- `.claude/settings.json` contains the SwarmVault hook entries and `.claude/hooks/swarmvault-graph-first.js` exists after `install --agent claude --hook`
- `.mcp.json` registers the `swarmvault` MCP server (`{"mcpServers":{"swarmvault":{"command":"swarmvault","args":["mcp"]}}}`) after `--mcp`
- `.claude/skills/swarmvault/SKILL.md` exists as the project skill bundle
- A new Claude Code session starts with injected graph-first instructions plus a staleness note when `wiki/graph/report.md` exists
- With `--graph-first` installed, the first broad Grep/Glob/Bash search in a session is denied once with a redirect to the plain `graph query|explain|path` commands (the deny message warns against `--json`, which produces much larger output); repeating the same search is then allowed. Without the opt-in the hook stays advisory and only adds a one-time guidance note
- Searches scoped to `wiki/`, `raw/`, `state/`, a single file, or search tools filtering piped output pass through without interception

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The quickstart lists sharing and export commands such as graph share --post, --svg, and --bundle without any adjacent warning that generated artifacts may contain repository structure, extracted knowledge, or other sensitive content. In a local-first knowledge vault, users are likely to ingest private notes, code, and documents, so publishing or exporting artifacts without a disclosure warning creates a realistic risk of accidental data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example explicitly promotes chat, context build, and task start workflows that persist conversation state, handoff packs, decisions, and follow-up data to disk, but it does not warn users that potentially sensitive prompts, repository details, or operational notes will be stored durably. In a repo-analysis skill, this is dangerous because users may assume these are ephemeral assistant interactions and unintentionally retain secrets, internal architecture details, or sensitive work context in local files that can later be committed, synced, or exfiltrated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly states that chat transcripts and structured session state are persisted to disk, but it provides no warning about retention, visibility, or handling of potentially sensitive user content. In a local-first knowledge vault, users may assume data is ephemeral unless clearly told otherwise, which increases the risk of unintentionally storing secrets, personal data, or regulated information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file describes durable extraction and storage of content from many source types, including emails, calendars, Slack exports, transcripts, and other potentially sensitive communications, without any warning about sensitive-data handling. Because this skill is specifically designed to ingest and retain broad local content, the absence of guidance materially raises the chance of collecting confidential or regulated data into long-lived artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes commands such as swarmvault source delete <source-id> and swarmvault chat --delete <session-id> that can remove user data, but the surrounding documentation provides no warning about data loss, reversibility, or the need to confirm the target before running them. Under the markdown-specific SQP-2 criteria, descriptions that omit warnings for behaviors affecting user data should be flagged.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

Commands such as swarmvault graph share --post, swarmvault graph export ..., and swarmvault graph push neo4j --dry-run imply publishing, exporting, or transmitting graph/project data, yet the markdown offers no warning about potential disclosure of sensitive code or metadata. For markdown files, omission of warnings about behaviors affecting privacy or system data integrity is in scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file instructs users to run npm install -g and later similar installation commands, which perform global package installation and alter the host environment. The troubleshooting text presents these steps as routine fixes but does not explicitly warn that they change system state or may require elevated privileges depending on the environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The text states that swarmvault provider setup --local-whisper --apply installs a provider and downloads a default model into ~/.swarmvault/models/. Although the behavior is described, there is no explicit caution that this will download data and write to disk in the user's home directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The documentation includes remote clone and source-add commands that fetch from GitHub and write checkout data locally, but it does not warn users about network access, trust of remote content, or filesystem modifications. While this is normal CLI behavior, omitting notice in a quickstart can mislead users into running commands with side effects they may not expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The quickstart documents chat, context build, task start, and export ai workflows that persist transcripts, context packs, task state, and AI export artifacts to disk, but there is no upfront privacy warning before these examples. Because this tool explicitly stores durable knowledge artifacts, users may unknowingly persist sensitive prompts, repository summaries, or operational context in locations later committed or shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The provider commands include --api-key-env OPENROUTER_API_KEY and provider setup ... --apply, which involve credential use and configuration changes, but the documentation does not warn users to protect secrets or understand where configuration will be stored. This is a markdown omission related to privacy and system-affecting behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.