other
- Location
SKILL.md:41- Finding
Excessive Personal Memory Access and Persistence Without Explicit Consent Boundaries
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This memory skill is coherent, but it asks agents to persist and reuse personal context broadly without clear consent, scoping, or sensitivity controls.
Install only if you intentionally want an agent to keep cross-session personal memory. Before using it, define what may be stored, require confirmation for sensitive or inferred facts, keep secrets and regulated data out of memory, review MEMORY.md and daily notes regularly, and delete stale or unwanted entries.
SKILL.md:41Excessive Personal Memory Access and Persistence Without Explicit Consent Boundaries
The skill clearly directs the agent to read local files such as MEMORY.md, USER.md, SOUL.md, TOOLS.md, and memory/YYYY-MM-DD.md, but it does not declare any explicit tool scope or permissions boundaries. That creates an authorization and review gap: an agent may access sensitive local memory files implicitly without a clear contract about what file access is required or allowed.
The skill description promotes persistent recording of conversations, decisions, preferences, and personal context across sessions, but it provides no privacy notice, consent requirement, minimization guidance, or retention warning. In a memory skill, that omission is especially dangerous because the normal operation of the skill is to accumulate potentially sensitive personal data over time, increasing exposure and compliance risk.
The instructions say to always write decisions, user preferences, important conversations, mistakes, and identity changes to daily notes, but they do not require filtering out sensitive personal data beyond a narrow example about API keys. This can lead to systematic storage of confidential or regulated information from conversations, making later unauthorized disclosure, over-collection, or secondary misuse more likely.
No suspicious patterns detected.