Back to skill

Security audit

Llm Memory Interface Only

Security checks for vulnerabilities and agentic risk

Overview

This skill is an interface-only memory/search/vector package and does not ship code that accesses data, runs commands, uses the network, or persists anything.

Install this as a low-risk interface package. Review the separate private implementation package before installing or using it, because that implementation is explicitly outside this artifact and may add network, storage, credential, or memory behavior not present here.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s descriptive and warning text is presented in Chinese throughout, including the title, security note, and usage guidance. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description contains only Chinese text for key behavioral statements such as 'interface-only package' and 'implemented by private package.' This imposes a specific language/locale in user-facing metadata without offering a language choice or documenting why Chinese-only text is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is written only in Chinese ("纯接口包,无运行时依赖"), which can impose a language-specific constraint on users without offering a language choice or documenting a justified locale limitation. The file provides no indication that this skill is region-specific or that non-Chinese users can opt in to this locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s natural-language docstrings and comments are written entirely in Chinese, and there is no indication that the skill offers a language choice or that the interface is intentionally limited to a Chinese-speaking context. Under the policy rule for language/locale constraints, this can be treated as a forced locale in natural-language-facing skill materials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This interface file uses Chinese throughout its natural-language docstrings and comments, with no indication that other languages are supported or that Chinese is an intentional opt-in choice. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains user-/developer-facing natural language exclusively in Chinese in the module docstring and interface documentation. Under the stated policy, forcing a specific language without user opt-in can be a language/locale policy violation, and no alternative language option or justification is provided here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.