T01 · Skill Instruction Hijacking
- Location
src/prompt-builder.ts:198- Finding
Agent Identity and Response-Policy Hijacking Through System-Prompt Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill has coherent memory features, but it exposes private memory and changes agent behavior in ways that need review before installation.
Review before installing. Use only on a trusted machine and network, bind the API to localhost or add authentication, avoid storing secrets, do not enable remote LLM or webhook settings unless you accept memory data leaving the device, and be aware that the skill may change the assistant's identity/style and maintain or alter long-term memory automatically.
src/prompt-builder.ts:198Agent Identity and Response-Policy Hijacking Through System-Prompt Injection
src/soul-api.ts:115Unauthenticated Memory API Exposed on All Network Interfaces
src/plugin-entry.ts:87Persistent Prompt Injection Through Untrusted Memory Content
src/context-prep.ts:191Automatic Reading of Arbitrary Local Files Referenced in Chat Messages
The module constructs a prompt telling an LLM to "become" the user and generates replies in the user's identity, with relationship-aware and emotion-aware behavior. Impersonation and acting on behalf of a person are distinct capabilities that are not an obvious requirement of a memory engine.
The Python integration example takes retrieved memories and injects them directly into an external OpenAI chat completion request without any warning that stored user memories may be transmitted to a third party. This omission is dangerous because users may copy the example verbatim and unknowingly exfiltrate sensitive personal data from the local memory store.
The privacy claim 'Nothing ever leaves your machine' directly conflicts with the documented optional remote LLM setup and example integrations that can send memory content to third-party APIs. This can cause users to expose sensitive conversation history under a false assumption of strict local-only processing.
The documented natural-language command set includes destructive memory operations such as 'delete memory' and restoration/pinning controls. In an agent skill, exposing broad state-changing memory commands through ordinary chat increases the risk of prompt-induced memory tampering, unauthorized deletion, or persistence manipulation.
|---------|-------------|
| `我的记忆` / `my memories` | View recent memories |
| `搜索记忆 <词>` / `search memory <kw>` | Search memories |
| `删除记忆 <词>` / `delete memory <kw>` | Remove matching memories |
| `pin 记忆 <词>` / `pin memory <kw>` | Pin memory (never decays) |
| `unpin 记忆 <词>` | Unpin memory |
| `恢复记忆 <词>` / `restore memory <kw>` | Restore deleted memory |
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)