Back to skill

Security audit

Conversation Distill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed conversation-to-notes helper that asks before saving, with some broad trigger and installation-source cautions.

Install this only if you are comfortable with end-of-conversation reminders and with the agent reviewing the current session to suggest items worth saving. Before enabling any KnowMine, Notion, Obsidian, or other MCP write target, review that tool's permissions, and prefer pinned or otherwise verified installation sources where available.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:13
Finding

Unpinned Third-Party Installation Sources

Content
View full analysis
Remediation
View remediation
``` 3. Publish SHA-256 checksums or cryptographic signatures for reviewed releases and document how users should verify them before installation. 4. Use package-lock or equivalent lock metadata where supported to preserve exact transitive dependency versions. 5. Disable or audit package lifecycle scripts before installation where the package manager supports doing so. 6. Protect maintainer accounts with phishing-resistant multi-factor authentication, restricted release permissions, and provenance-enabled publishing. 7. Establish a release process that maps each published version to a reviewed source commit and records the corresponding integrity digest. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes the skill as a closing ritual that scans the full session and classifies content at conversation end, which conflicts with the stated requirement that it should only show a soft reminder and never auto-start. This matters because automatic full-session analysis can process sensitive conversation data without an explicit, contemporaneous opt-in, creating privacy and consent risk even if writing is deferred.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to execute an unpinned npx clawhub@latest install conversation-distill, which trusts whatever code is current at install time. If the package, dependency chain, or publisher account is compromised, users may fetch and run unexpected code during installation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README says nothing is written without confirmation, but also documents an automatic scan/classify workflow triggered at conversation close. Even if no external write occurs, automatic ingestion and structuring of the entire session is still a sensitive data-processing action that users may reasonably not expect from a mere closing phrase.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Broad triggers such as 'thanks', 'got it', and 'done for now' are common conversational closings and can fire unintentionally. In this skill's context, accidental triggering is more dangerous because it may initiate session-wide review of sensitive content or pressure users into a retention workflow they did not explicitly request.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: conversation-distill
description: "At the natural end of a meaningful conversation, show a one-line soft reminder asking the user if they want to distill — do NOT auto-start. Only ask when the conversation had distillation value (decisions, insights, judgments, lessons, open questions, action items). If user says yes, run the full 5-step classify→confirm→write flow. Trigger reminder when: (1) closing phrases detected ('thanks', 'done', 'that's all', '好的就这样') AND conversation had substantive content; (2) user explicitly says 'distill', 'wrap up', '收尾'. Never auto-start without asking first."
version: 1.1.0
tags:
  - knowledge-management

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These trigger rules use very common closing phrases such as 'thanks' and 'got it' to change assistant behavior, which can cause the skill to activate in normal conversation when the user did not actually intend to invoke distillation. While not directly a code-execution issue, this broad prompt-trigger surface can lead to unwanted state transitions, extra prompting, and accidental capture workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Heuristics like '3+ consecutive turns with no new topics' and 'user switches to an unrelated topic' are ambiguous and subjective, making activation boundaries unpredictable. In a conversational agent, vague triggers increase the chance of unintended reminders or premature workflow initiation cues, especially across multilingual or informal chats.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including extremely common phrases like 'good' and 'OK' as ending signals makes the skill easy to trigger during ordinary back-and-forth conversation. This broadens the prompt-injection-like collision surface of the skill and can annoy users or nudge them into a persistence flow they did not request.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The skill recommends installing and running a remote MCP-related package via npx clawhub@latest, which pulls and executes the latest published code at runtime rather than a pinned, reviewed version. That creates a supply-chain risk: if the package or one of its dependencies is compromised or changes behavior, users may execute untrusted code while setting up the integration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.