Back to skill

Security audit

Llm Memory V9

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned and not malicious, but its install hook can import broad private local content into the trusted skill directory while the security manifests understate that filesystem and code-execution behavior.

Install only if you intentionally want a local private configuration directory linked into the skill. Point CNB_PRIVATE_WORKSPACE at a narrow, reviewed directory, avoid broad locations like home folders or synced/shared directories, review any AGENTS.md, TOOLS.md, MEMORY.md, scripts, and config files there, and consider installing with hooks disabled if you do not need private config import.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
hooks/bootstrap-extra-files.py:21
Finding

Unrestricted Import of Attacker-Influenced Content into the Trusted Skill Root

Content
View full analysis
Path | None: """获取私有工作区路径""" private_path = os.getenv('CNB_PRIVATE_WORKSPACE') if private_path: return Path(private_path).expanduser().absolute() return None def link_private_files(private_dir: Path, target_dir: Path) -> list[str]: """ 将私有目录的文件链接到目标目录 Args: private_dir: 私有目录路径 target_dir: 目标目录路径 Returns: 已链接的文件列表 """ linked_files = [] if not private_dir.exists(): print(f"⚠️ 私有目录不存在: {private_dir}") return linked_files for item in private_dir.iterdir(): if item.is_file(): target = target_dir / item.name if not target.exists(): try: # 优先使用软链接,失败则复制 target.symlink_to(item) linked_files.append(item.name) print(f"✅ 已链接: {item.name}") except OSError: # 不支持软链接时使用复制 shutil.copy2(item, target) linked_files.append(item.name) print(f"✅ 已复制: {item.name}") else: print(f"⏭️ 跳过已存在: {item.name}") elif item.is_dir(): # 目录也链接 target = target_dir / item.name if not target.exists(): try: target.symlink_to(item) linked_files.append(f"{item.name}/") print(f"✅ 已链接目录: {item.name}/") except OSError: shutil.copytree(item, target) linked_files.append(f"{item.name}/") print(f"✅ 已复制目录: {item.name}/") ``` ### Technical Analysis The post-install hook accepts `CNB_PRIVATE_WORKSPACE` directly from the process envir ...[truncated 2817 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
_meta.json:27
Finding

Security Manifests Understate Post-Install Code Execution and Filesystem Access

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · hooks/README.md (reported line 34)May include surrounding context.

��本地文件系统

  • ✅ 用户可控:用户完全控制私有目录的位置和内容

使用方法

1. 准备私有配置目录

bash
mkdir -p ~/my-private-config
# 将你的私有文件放入此目录

2. 设置环境变量

bash
# 临时设置(当前会话)
export CNB_PRIVATE_WORKSPACE="~/my-private-config"

# 永久设置(添加到 ~/.bashrc 或 ~/.zshrc)
echo 'export CNB_PRIVATE_WORKSPACE="$HOME/my-private-config"' >> ~/.bashrc

3. 安装技能

bash
clawhub install llm-memory-integration

安装后,钩子会自动将 CNB_PRIVATE_WORKSPACE 目录下的文件链接到技能工作区。

私有目录结构示例

text
~/my-private-config/
├── AGENTS.md          # 自定义 Agent 规则
├── TOOLS.md           # 自定义工具配置
├── MEMORY.md          # 私有记忆文件
└── config/            # 自定义配置目录
    └── llm_config.json

禁用钩子

如果不需要私有配置�

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares a postinstall hook that runs python3 and is documented to perform symlink/copy operations based on an environment variable, but it does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch reduces transparency and can let installation-time file and environment access occur without clear user-facing authorization boundaries, which is especially relevant because the skill processes a user-controlled path pointing to private local files.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

  1. 创建私有配置目录
bash
mkdir -p ~/my-private-config
  1. 设置环境变量

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest uses Chinese-only natural-language descriptions in the description field and hook description, with no indication that the skill is region-specific or that users can choose another language. This creates a language/locale policy concern because the skill's user-facing metadata appears to enforce a specific language without opt-in.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · hooks/README.md (reported line 23)May include surrounding context.

1. 准备私有配置目录

bash
mkdir -p ~/my-private-config
# 将你的私有文件放入此目录

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · hooks/README.md (reported line 23)May include surrounding context.

1. 准备私有配置目录

bash
mkdir -p ~/my-private-config
# 将你的私有文件放入此目录

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and all user-facing messages are written only in Chinese, which imposes a specific language on users. There is no indication that the skill is region-specific, nor any opt-in or alternative language support, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language descriptions in the manifest are written entirely in Chinese, with no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate language/locale policy when a skill imposes a language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README describes that a postinstall hook will link files from a user-specified private directory into the skill workspace, but it does not present this as a clear security warning with the implications spelled out. Because linked files like AGENTS.md, TOOLS.md, and MEMORY.md can influence agent behavior and expose private local content to the installed skill, the omission can cause users to grant workspace access to sensitive material without understanding the trust boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This manifest describes installation and linking behavior in broad natural language but does not specify any explicit activation constraints, negative examples, or narrow invocation context. In a manifest file, such ambiguity can contribute to unintended invocation or misunderstanding of when the skill's install/link behavior applies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings throughout the manifest are written only in Chinese, with no indication that the skill offers language choice or that the locale is intentionally restricted to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON manifest is in scope for vague-trigger review. The description '仅访问用户通过 CNB_PRIVATE_WORKSPACE 指定的目录' describes broad access to whatever directory the environment variable points to, but does not define constraints, allowed contexts, or exclusions, making the activation/scope of file access underspecified in the manifest text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file uses Chinese throughout and does not indicate that the skill is region-specific or provide an opt-in choice for language. That can violate a language/locale policy if users are expected to receive documentation in a selectable or default-neutral language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.