Back to skill

Security audit

Claude级 · AI第二大脑

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned as a memory manager, but it asks for persistent automation and broad local workspace access without enough scoping or user controls.

Install only after reviewing the exact files and paths it may read or change. Before enabling it, ask for separate opt-in for memory writes, profile storage, AutoDream, MCP sync, and workspace backup; confirm how to list and remove cron jobs, where backups are stored, how long they are kept, and how to restore or delete stored memories. Avoid importing full assistant histories or backing up sensitive workspaces unless you have reviewed what will be saved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
templates/IDENTITY_TEMPLATE.md:3
Finding

Persistent Agent Persona and Behavioral Instruction Hijacking

Content
View full analysis
Meta-Memory Architect instruction: This file records the AI's core identity, > values, and tone preferences. When the user corrects the AI's attitude or > configuration, this file must be updated. ## Core Identity - Role: Ye Wubin-authorized digital intelligent assistant / AI-era second brain (Meta-Memory Architect) - Designer: Ye Wubin, founder of Efficiency - Core responsibility: Automatically process the user's long-term memory, work notes, and file system. ## Tone and Interaction Preferences - Tone: Professional, intelligent, familiar with the Efficiency methodology, and similar to an experienced coach. - Interaction: [User-customized preference] ``` The onboarding guide additionally requires the agent to follow a prescribed sequence and deliver branded scripts: ```markdown When the user first installs this skill, you must follow the steps below, step by step, to guide the user in building their "digital brain." Your script template: "Hello! I am the AI second brain designed for you by global time-management expert Ye Wubin..." ``` ### Technical Analysis The templates do more than describe memory-management functionality. They instruct the hosting agent to adopt a specific identity, designer attribution, methodology, tone, and promotional script. Because these instructions are loaded as Skill content, they may compete with the agent's existing persona and current-session objectives. Mandatory language such as “must follow” and “core identity” makes the content operate as behavioral instructions rather than neutral configuration data. The identity file is also intended to be updated over tim ...[truncated 960 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
templates/ERRORS_AND_LESSONS_TEMPLATE.md:3
Finding

Untrusted Corrections Can Become Persistent Cross-Session Behavioral Rules

Content
View full analysis
Meta-Memory Architect instruction: This file is the AI's "error diary." > When the AI makes a mistake and the user corrects it, the error and its > correct solution must be recorded here. Before producing a complex plan, > this file must be consulted to avoid repeating mistakes. Each record contains: - Scenario - Incorrect behavior - User correction - Correct future behavior - Root-cause analysis ``` The global memory template is loaded automatically: ```markdown > This file is the global index and is loaded in every session. > Keep it within 200 lines. Store only pointers and short summaries. ## Corrections → corrections.md | Total corrections: [N] | Latest: [correction summary] ``` The main Skill instructions reinforce this behavior: ```markdown - Key behavioral rules from AGENTS.md are included in the memory index. - The memory index must be read first at the start of every conversation. - When corrected, the error must be recorded in topics/errors_and_lessons.md. - Before outputting a complex solution, consult the error record. ``` ### Technical Analysis The Skill creates a path through which user-controlled text can be converted into durable behavioral instructions. A statement presented as a “correction” can be saved as the “correct future behavior,” indexed, and consulted before later responses. There is no documented trust boundary separating factual memory from executable behavioral instructions. The design does not require provenance validation, scope restrictions, expiration, injection detection, or review of instruction-like content before it ...[truncated 1320 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
templates/ONBOARDING_GUIDE.md:26
Finding

Installation of Recurring Cross-Session Scheduled Tasks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
templates/DREAM_PROTOCOL.md:37
Finding

Autonomous Destructive Memory Rewriting Without Transactional Safeguards

Content
View full analysis
new value]." 4. Write new information to the corresponding topic file. 5. For topic files over 5000 tokens, perform micro-compression: extract core facts and delete lengthy conversation quotations. ## Phase 4: Prune 1. Find entries marked "completed" or "expired." 2. Move those entries to the archive directory. 3. Delete dead links from MEMORY.md. 4. Regenerate MEMORY.md. 5. Update the last Dream processing time. ``` The filesystem guide also authorizes automatic changes: ```markdown During /dream processing, inspect files that do not comply with the rules and prompt the user or automatically rename/move them. ``` ### Technical Analysis The protocol relies on model interpretation to decide whether information is contradictory, expired, completed, excessive, or incorrectly located. It then permits overwriting, deletion, compression, movement, index regeneration, and automatic renaming. No transactional update procedure, atomic-write requirement, dry-run diff, immutable snapshot, rollback mechanism, or post-write integrity validation is defined. Timestamp recency alone is also insufficient to determine factual correctness. The behavior conflicts with the main Skill's statement that existing files must not be modified, overwritten, or deleted without user confirmation. The Dream protocol does not consistently enforce that confirmation requirement. ### Atta ...[truncated 906 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:101
Finding

Unpinned Installation from an Unverified Third-Party Registry

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:40
Finding

Overbroad Collection and Consolidation of Sensitive Workspace Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
87% confidence
Finding

The onboarding content is written as mandatory Chinese-language script and repeatedly instructs the assistant to use that wording, without offering the user a language choice. This can violate a language/locale policy when the skill forces a specific language absent explicit opt-in or region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is written entirely in Chinese and instructs the user to reply with a specific Chinese consent phrase, with no indication that other languages are accepted. This creates a language/locale policy concern because it imposes a specific language on users without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide says the skill will automatically scan existing memory files, create backups, create filesystem directories, and enable ongoing automated processing, but it does not clearly define the scope, paths affected, retention behavior, or failure modes before installation. In a memory-management skill, this can lead users to authorize broad file access or persistent background actions without informed consent, increasing the risk of unintended data exposure, modification, or confusion about what the tool will do.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README makes strong assurances that automation will be transparent and confirmed by the user, yet elsewhere it describes automatic scanning and backup during installation. In a skill that manages local memory files and backups, this contradiction can mislead users about when file access begins and whether sensitive workspace contents may be processed before meaningful consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says it will not proactively modify core 'constitution' files, but later states it will inject a new memory mechanism into core configuration files after consent. This inconsistency obscures the actual write scope to high-sensitivity workspace files such as USER.md or other bootstrap/config files, increasing the risk of users authorizing changes they do not accurately understand.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

Natural-language policy review applies to all file types. The manifest description and the entire skill instructions are presented only in Chinese, framing the skill identity and operation around a Chinese-language experience, but there is no opt-in language choice or stated region-specific justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill presents itself as only remembering and organizing data, but later instructs the agent to create directories, configure scheduled tasks, and perform backups. That mismatch can cause users or host systems to grant trust under false assumptions, increasing the chance of unintended filesystem changes or automation being enabled without fully informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

AutoDream can activate either on an explicit command or when the 'three gates' are met during ordinary conversation, which creates ambiguity about when background reorganization begins. In a skill that can move, archive, compress, or rewrite memory files, unclear triggers can lead to unexpected persistent changes without a clear user action at that moment.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs collection and long-term retention of broad user identity, goals, preferences, and conversation-derived content in local memory files. Even if storage is local, this increases privacy risk, expands the blast radius of workspace compromise, and may preserve sensitive data longer than necessary or expected.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The migration workflow encourages importing 'all remembered information' from other models into local memory, which can sweep in sensitive personal data, confidential project details, or inaccurate model-inferred facts at scale. Bulk ingestion from external assistants magnifies privacy, over-collection, and data integrity risks, especially when users may not review each item carefully.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The protocol instructs the agent to overwrite existing memory based on the latest timestamp, annotate changes, write new information into topic files, and compress oversized files, but it provides no explicit warning or confirmation step before altering stored data. In a memory-management skill, these are real state-changing operations that can silently modify or discard nuance from prior records, creating integrity and recoverability risks if triggered unintentionally or manipulated by conversation content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The pruning phase directs the agent to move completed or expired items to archive/, delete dead links from MEMORY.md, and regenerate the index under strict size limits, yet it does not clearly warn the user that indexed content may be removed or relocated. Because this skill is specifically designed to manage persistent memory, silent archival and cleanup can hide, orphan, or effectively delete information from active use, especially if entries are misclassified as expired or if regeneration drops references.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template title and core operating instruction are written in Chinese and direct the AI's behavior in that language context, but there is no indication that language selection is user-driven or that the skill is intentionally limited to a Chinese-speaking environment. This can violate language/locale policy because it implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide directs the AI to automatically extract valuable knowledge and work notes from ordinary conversations and persist them into files without any requirement for user notice or consent. This creates a privacy and data-retention risk because sensitive conversational content may be stored unexpectedly, potentially exposing personal or confidential information beyond the original interaction context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The cleanup rule permits the AI to automatically rename or move files when it detects noncompliance with the naming scheme, but it does not require confirmation before modifying user data. This can cause integrity and availability issues by breaking references, confusing users, or relocating important files in ways the user did not authorize.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The template is entirely written in Chinese and presents the assistant identity, tone, and interaction defaults as fixed settings, with no indication that the user can choose another language. This creates a natural-language locale policy concern because it effectively imposes a language preference rather than offering user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs the agent to automatically create directories and schedule recurring jobs that modify the workspace and perform backups, but it does not clearly disclose the operational and data consequences beyond a generic consent prompt. This can lead users to authorize persistent system changes and storage growth without understanding retention, backup contents, overwrite behavior, or how to disable the tasks later.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide directs the collection and persistent storage of sensitive personal data such as identity, profession, goals, and communication preferences without an explicit privacy notice or data handling boundaries. This creates risk of overcollection and unintended long-term retention of personal information in workspace files that may later be backed up, synced, or exposed.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to record the user's identity, role, goals, and communication preferences into persistent files creates a durable profile of the user that may contain sensitive personal and professional information. In this skill's context, the danger is heightened because the profiling is framed as necessary to prevent 'memory loss' and is paired with automatic backup behavior, which can normalize excessive retention and widen exposure if the workspace is accessed or exported.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

At L56, the instructions say to write identity and goal data to topics/identity.md and topics/goals.md. But the only documented directory creation step creates memory/topics at L30, and later the index also references topics/... paths from within memory/MEMORY.md, so the documentation conflicts about where data is actually stored.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide says the agent will automatically store important conversations, preferences, and work notes across sessions, which establishes broad persistent memory behavior over potentially sensitive user content. In context, this is especially risky because the same guide also sets up automated backups and background processing, increasing the chance that personal or confidential data is retained and propagated without sufficient user control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template’s headings, instructions, and placeholders are written entirely in Chinese, which establishes a default language requirement for the skill content. Under the policy, forcing a specific language without explicit user opt-in is a natural-language policy violation unless the locale constraint is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README is entirely written in Chinese and segments users into 'overseas' and 'China' flows, but does not offer any language or locale opt-in for the skill itself. This suggests a default locale/language assumption that may not align with an organizational policy requiring user choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

L053 says the collaboration rule is '只读不写' for bootstrap files, but L048 describes '双向同步 USER.md', including extracting data and prompting updates based on synchronization behavior. While it may not explicitly rewrite USER.md itself, the wording creates an internal contradiction about whether USER.md is treated as strictly read-only or part of a bidirectional sync workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file is written primarily in Chinese and presents mandatory governance instructions, but it does not indicate that the user can choose another language or that the locale restriction is required for a region-specific purpose. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.