Back to skill

Security audit

Autobiographical Memory

Security checks for vulnerabilities and agentic risk

Overview

This memory skill is coherent, but it asks agents to persist and reuse personal context broadly without clear consent, scoping, or sensitivity controls.

Install only if you intentionally want an agent to keep cross-session personal memory. Before using it, define what may be stored, require confirmation for sensitive or inferred facts, keep secrets and regulated data out of memory, review MEMORY.md and daily notes regularly, and delete stale or unwanted entries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:41
Finding

Excessive Personal Memory Access and Persistence Without Explicit Consent Boundaries

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill clearly directs the agent to read local files such as MEMORY.md, USER.md, SOUL.md, TOOLS.md, and memory/YYYY-MM-DD.md, but it does not declare any explicit tool scope or permissions boundaries. That creates an authorization and review gap: an agent may access sensitive local memory files implicitly without a clear contract about what file access is required or allowed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description promotes persistent recording of conversations, decisions, preferences, and personal context across sessions, but it provides no privacy notice, consent requirement, minimization guidance, or retention warning. In a memory skill, that omission is especially dangerous because the normal operation of the skill is to accumulate potentially sensitive personal data over time, increasing exposure and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions say to always write decisions, user preferences, important conversations, mistakes, and identity changes to daily notes, but they do not require filtering out sensitive personal data beyond a narrow example about API keys. This can lead to systematic storage of confidential or regulated information from conversations, making later unauthorized disclosure, over-collection, or secondary misuse more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.