Back to skill

Security audit

export-conversation-summary

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says by exporting a Claude Code conversation, but it saves sensitive internal session history and detailed tool activity into a persistent markdown file without redaction or a clear safety checkpoint.

Review before installing. Use this only when you intentionally want a durable copy of the conversation and its tool activity. Before sharing or committing the generated markdown, check it for secrets, internal paths, command output, private project details, and personal information. Prefer asking for a limited or redacted export when the conversation involved credentials, proprietary code, or sensitive debugging data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill is designed to export the entire conversation log, including user messages, assistant replies, tool operations, commands, file paths, and token metadata, into a markdown document. That is a direct sensitive-data exfiltration/persistence pattern because it transforms internal session data into a durable and potentially shareable file.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The parsing instructions require extraction of all turns plus detailed operational history such as commands, files accessed, searches, agent dispatches, and documentation lookups. This significantly increases sensitivity because operational traces often contain secrets, internal topology, credentials in commands, or proprietary paths not intended for export.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The skill demonstrates direct access to ~/.claude/... internal project/session storage, which is an agent configuration and history area rather than normal workspace content. Reading from this location increases the risk of exposing internal state, session histories, and other sensitive artifacts beyond the user's immediate intent.

Content

Scanner excerpt · skill.md (reported line 172)May include surrounding context.

md
**User says:** "把这轮对话保存成文档"

**Agent does:**
1. Find conversation file: `~/.claude/projects/-Users-yz-dev3-demo3/ca50434c-b83d-4f88-ac4c-6b4c722cb460.jsonl`
2. Launch agent to parse and extract to `docs/2025-02-27-conversation.md`
3. Report: "对话已保存到 `docs/2025-02-27-conversation.md` (536 行)"

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The output specification explicitly preserves verbatim user/model content, code blocks, images, metadata, and evaluation details, creating a rich dossier of session activity. Such comprehensive persistence magnifies disclosure risk if the file is synced, committed, shared, or accessed by others.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill proposes exporting the full conversation, including model operations and dialogue context, without any warning that these logs may contain sensitive data such as secrets, personal information, internal paths, or command history. Users may assume an export is harmless when it actually creates a durable, shareable copy of highly sensitive session data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill's purpose is to create a persistent record of a conversation, which converts ephemeral session content into a long-lived artifact. That persistence increases downstream exposure through backups, version control, local sharing, or later unauthorized access.

Content

Scanner excerpt · skill.md (reported line 19)May include surrounding context.

md
- "Export this conversation" / "Save our chat"
- "把对话保存成文档" / "保存对话记录"
- Document a problem-solving session
- Create a record of what was discussed and changed
- Generate a conversation transcript

## Process

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs reading internal Claude Code JSONL logs from the agent config area and writing them to a persistent markdown file, but omits any safety guidance or consent checkpoint. Accessing internal logs and converting them into an easy-to-share artifact materially raises the chance of unintended disclosure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

Persisting detailed operational metadata alongside the transcript—such as files read/written, commands executed, searches, skills, agents, and token usage—creates a lasting audit trail that may reveal sensitive workflows and internal environment details. This extends the privacy risk beyond mere chat content into behavioral and system-level telemetry.

Content

Scanner excerpt · skill.md (reported line 55)May include surrounding context.

md
For each assistant message, identify:
- Files read (Read tool)
- Files edited/written (Edit/Write tools)
- Searches performed (Grep/Glob tools)
- Commands executed (Bash tool)
- Documentation lookups (Context7, web searches)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The required output format uses Chinese section headers and scoring labels such as 日期, 用户, 模型, 对话统计, and 对话评价, which imposes a specific language/locale. Elsewhere the file mentions preserving original language, but it does not give users an explicit option to choose the export language or justify a Chinese-only locale constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and top-level description say the skill exports conversation context and operations, but the body adds subjective assessment and coaching content not justified by that purpose. This is a scope-expansion issue: users asking for an export may unknowingly trigger additional analysis of their behavior and the model's performance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's stated purpose is exporting a conversation transcript, but it additionally instructs the agent to score the user and model and provide coaching-style evaluations. This introduces unnecessary subjective processing of conversation data and expands the skill's behavior beyond user-requested export, increasing privacy and trust risks.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Requiring inclusion of all rounds and preserving original content/formatting raises the likelihood that sensitive information embedded anywhere in the session will be copied verbatim into the export. This is especially risky because users and tools often surface secrets, stack traces, and internal paths during debugging sessions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.