Back to skill

Security audit

Daily Learning Summary

Security checks for vulnerabilities and agentic risk

Overview

This skill creates local daily learning summaries from declared workspace logs, with privacy considerations but no hidden network, credential, or destructive behavior found.

Install only if you are comfortable with the skill reading local memory activity files and creating persistent daily summaries. Keep memory/learning private or excluded from synced/shared repositories if the logs may include sensitive activity history.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documentation states that the tool automatically reads multiple activity and state files and writes a derived daily log, but it does not clearly warn users about the privacy implications of aggregating behavioral data into a persistent archive. This can increase exposure of sensitive usage history, mistakes, interests, or internal state, especially in shared workspaces or synced repositories.

Static analysis

No suspicious patterns detected.