Back to skill

Security audit

Self Improving 1.2.16

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it installs persistent agent memory and workspace steering with consent and validation gaps that users should review carefully.

Install only if you are comfortable with an agent keeping local, cross-session notes about corrections and preferences. Review proposed memory entries and workspace config changes before accepting them, avoid storing sensitive information, and treat export and deletion operations carefully because retained archives may remain unless explicitly removed.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
setup.md:75
Finding

Persistent Learned Rules Can Poison Future Agent Behavior

Content
View full analysis
.md` - Project-only override → append to `~/self-improving/projects/.md` - Keep entries short, concrete, and one lesson per bullet; if scope is ambiguous, default to domain rather than global - After a correction or strong reusable lesson, ...[truncated 2704 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.md:90
Finding

Unpinned External Skill Is Installed Before Security Review

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
boundaries.md:45
Finding

Complete Memory Deletion Request Creates a Retained Export Copy

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The setup text says workspace integration should add steering to AGENTS, SOUL, and HEARTBEAT files, which implies modifying user or project-controlled files. Without a prominent warning and explicit confirmation, this creates an integrity and trust risk because the skill may alter repository or workspace behavior in ways the user did not anticipate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to automatically log user corrections, preferences, and repeated patterns into persistent local files, but the behavior description does not present a clear just-in-time privacy warning or consent step where collection occurs. Because these signals are plain-language user statements, the agent can easily persist sensitive personal preferences or other private information that the user did not realize would be retained long-term.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatic logging of user-provided corrections and preferences into persistent memory can capture sensitive personal data, confidential project details, or regulated information embedded in normal conversation. Even though the skill mentions boundaries elsewhere, the logging workflow itself is broad and free-form, making accidental retention of sensitive data likely in practice.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill provides plain-language commands to reveal learned memory and export all stored files, which increases the chance that accumulated sensitive data can be surfaced wholesale in response to a prompt. If memory contains confidential or personal information, a casual or ambiguous request could trigger over-disclosure beyond the user's immediate intent.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
- Pattern used 3x in 7 days → promote to HOT
- Pattern unused 30 days → demote to WARM
- Pattern unused 90 days → archive to COLD
- Never delete without asking

### 4. Namespace Isolation
- Project patterns stay in `projects/{name}.md`

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · boundaries.md (reported line 11)May include surrounding context.

md
| Financial | Card numbers, bank accounts, crypto seeds | Fraud risk |
| Medical | Diagnoses, medications, conditions | Privacy, HIPAA |
| Biometric | Voice patterns, behavioral fingerprints | Identity theft |
| Third parties | Info about other people | No consent obtained |
| Location patterns | Home/work addresses, routines | Physical safety |
| Access patterns | What systems user has access to | Privilege escalation |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template explicitly instructs creation of persistent files and directories under ~/self-improving, which modifies user-local state and stores ongoing memory without any warning, consent step, or limits on what may be written. In the context of a self-improving/proactive agent, this is more dangerous because it normalizes autonomous persistence and can lead to silent retention of sensitive user data, corrections, or workflow history across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file explicitly states that the agent will add and compact entries in the user's memory file automatically, but it does not describe any user consent, review, or approval flow. Persistently modifying a cross-session memory store can cause privacy issues, unwanted retention of sensitive data, and behavioral drift if incorrect or adversarial information is written into memory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes commands to search, display, forget, and export persisted memory, but it provides no notice, consent flow, retention policy, or access-control guidance for handling user data. In a self-improving agent context, this creates a real privacy risk because users may not realize their inputs and corrections are being stored and can later be revealed or exported.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The memory display and export features are designed to retain and later reveal user-provided information, which can expose private data if invoked accidentally, by another user in a shared context, or after sensitive information was stored. Because the skill centralizes recall across tiers, the blast radius of any disclosure is broader than a transient session-only feature.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automatic correction workflow directs background writes to multiple memory files whenever the user corrects the agent, without requiring explicit consent or warning that persistence is happening. Silent background storage is dangerous because it can capture sensitive user preferences, technical details, or contextual information across sessions without informed awareness.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The automatic correction-handling logic preserves user inputs, timestamps, counters, and context across files and sessions, which constitutes persistent profiling and historical retention of user behavior. Even if intended to improve assistance quality, this is risky because it creates a durable record that may later be surfaced, misapplied in a different context, or disclosed through memory inspection/export.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guidance explicitly recommends 'aggressive learning' with 'minimal confirmation' for power users, while the broader skill is designed to persist corrections and preferences into memory files. That creates a real privacy and consent risk: the agent may store user preferences, behavioral patterns, or project details without clear notice or explicit opt-in, increasing the chance of over-collection and unintended long-term retention.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example for handling changed preferences explicitly keeps archived records of prior user statements for future reference, which extends retention of historical personal preferences beyond immediate task needs. While lower impact than broad export or automatic logging, it still creates avoidable privacy risk and can lead to unnecessary storage of outdated or sensitive behavioral history.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.