Back to skill

Security audit

Mark Heartflow Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a cognitive memory engine, but it also exposes powerful code execution, persistent memory injection, and unauthenticated local memory access that are not safely scoped.

Install only if you are prepared to run it in an isolated environment, disable or gate code execution, avoid the unauthenticated HTTP MCP server, and review/delete stored memory before allowing it into prompts.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
src/memory/heartflow-memory.js:242
Finding

Persistent System-Prompt Injection Through Raw User Memory

Content
View full analysis
5) { this.learn(`conversation:${uid}`, input, ['conversation', 'user_input']); } // 2. Detected emotion/pain → store in LEARNED const pain = this._extractPain(judgment); if (pain) { this.learn(`pain:${uid}`, `User emotional signal: ${pain}`, ['emotion', 'pain']); } // 3. Determined scenario → store in EPHEMERAL const what = judgment.whatIsThis; if (what) { this.remember(`context:now`, { whatIsThis: typeof what === 'object' ? (what.scenario || what.category || 'unknown') : 'unknown', shouldRespond: judgment.shouldRespond, }, 3600000); } // 4. Important technical operation → store in LEARNED if (input.includes('修') || input.includes('改') || input.includes('升级') || input.includes('优化')) { this.learn(`tech:${uid}`, input, ['tech', 'operation']); } ``` `scripts/heartflow-memory-inject.js:78-95`: ```javascript if (techOps.length > 0) { lines.push(''); lines.push('【技术操作记录】'); for (const e of techOps.slice(0, 10)) { const ts = e.lastAccessed ? new Date(e.lastAccessed).toLocaleDateString('zh-CN') : '?'; lines.push(` • (${ts}) ${e.value}`); } } lines.push(''); const output = lines.join('\n'); // Output to stdout for use by AGENTS.md / Hermes process.stdout.write(output); ``` `plugins/heartflow-memory-inject.py:142-164`: ```python inject_text = _run_inject() if not inject_text: return {} # Filter sensitive memories inject_text = _filter_sensitive(inject_text) if input_type == "greeting": inject_text = "" if inject_text: boundary_note = ( "\n[Memory notice: the followin ...[truncated 2996 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/core/code/code-executor.js:442
Finding

Dispatchable Unsandboxed JavaScript, Shell, and Python Execution

Content
View full analysis
context[k]); // Use new Function to create a sandbox function const fn = new Function( ...contextKeys, `"use strict"; ${code}` ); // Timed execution const result = this._executeWithTimeout(fn, timeout, contextValues); ``` `src/core/code/code-executor.js:526-549`: ```javascript // Dangerous command check const dangerCheck = checkDangerousCommand(code); if (dangerCheck.dangerous) { return { status: ExecStatus.SANDBOX_BLOCKED, output: '', error: `Dangerous command blocked: ${dangerCheck.reason}`, truncated: false, execError: ExecError.SANDBOX }; } try { const result = execSync(code, { timeout, encoding: 'utf-8', maxBuffer: MAX_OUTPUT_LIMIT, shell: '/bin/bash' }); ``` `src/core/code/code-executor.js:591-611`: ```javascript const tmpFile = path.join( require('os').tmpdir(), `code_exec_${Date.now()}_${Math.random().toString(36).slice(2, 8)}.py` ); try { fs.writeFileSync(tmpFile, code, 'utf-8'); const pythonCmd = this._getPythonCommand(); const result = execSync(`${pythonCmd} "${tmpFile}"`, { timeout, encoding: 'utf-8', maxBuffer: MAX_OUTPUT_LIMIT }); ``` `src/core/heartflow.js:906-908`: ```javascript // codeExecutor.* — code execution engine 'codeExecutor.execute', 'codeExecutor.runTests', 'codeExecutor.sandbox', 'codeExecutor.healthCheck', ``` ### Technical Analysis The ordinary `execute()` interface is distinct from the separately named `sandbox()` method and does n ...[truncated 3130 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
mcp/mcp-server-http.js:388
Finding

Unauthenticated Local HTTP Interface Exposes Cross-Session Memory

Content
View full analysis
{ if (layer !== 'all' && layer !== l) return; try { const r = typeof mem.searchByKeywords === 'function' ? mem.searchByKeywords(query, limit) : typeof mem.search === 'function' ? mem.search(query, l, limit) : null; results[l] = r || { error: 'search not available' }; } catch (e) { results[l] = { error: e.message }; } }); } else { results.error = 'memory instance unavailable'; } return { query, layer, limit, results, timestamp: Date.now() }; } ``` `mcp/mcp-server-http.js:407-414`: ```javascript res.writeHead(200, { 'Content-Type': 'text/event-stream', 'Cache-Control': 'no-cache', 'Connection': 'keep-alive', 'Access-Control-Allow-Origin': '*', 'X-Accel-Buffering': 'no' }); ``` `mcp/mcp-server-http.js:460-467`: ```javascript res. ...[truncated 3044 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (697)

Known Vulnerable Dependency: protobufjs==6.11.6 — 11 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +8 more

Critical
Category
Supply Chain
Confidence
94% confidence
Finding

The lockfile pins protobufjs to 6.11.6, and the static finding cites multiple published advisories including denial-of-service and code-injection issues. Even though this file is only dependency metadata, shipping a version with known flaws is a real supply-chain risk because downstream code generation or parsing paths in protobufjs can be triggered by attacker-controlled schema or message content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The shell executor passes attacker-controlled code directly to execSync with /bin/bash, enabling arbitrary OS command execution. The regex blacklist is incomplete and easily bypassed, so the implementation cannot safely prevent destructive actions, data exfiltration, or persistence.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 342)May include surrounding context.

md
167|#### 修复类别一:描述与行为不匹配
   168|- `package.json`:description 精确匹配 SKILL.md 认知/自愈引擎描述
   169|- `CHANGELOG.md`:标注 MarkCode 为可选独立组件,避免误导
   170|- `skills/video-generate/SKILL.md`:移除"自动写入 API 密钥到 .env"危险指令
   171|- `skills/zai-vision/SKILL.md`:添加安全警告,说明数据外传风险
   172|- `skills/desktop-agent/SKILL.md`:添加高风险警告,默认禁用说明
   173|- `skills/browser-automation/SKILL.md`:添加安全警告,说明网络访问范围

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 357)May include surrounding context.

md
182|- `scripts/awakening-integration.js`:添加安全头部,标注为哲学思考框架
   183|
   184|#### 修复类别三:数据泄露风险
   185|- `plugins/agentmemory/__init__.py`:移除 `_preload_agentmemory_dotenv()`,不再自动读取 .env
   186|- `plugins/agentmemory/__init__.py`:`sync_turn()` 默认禁用,需 `AGENTMEMORY_OBSERVE_ENABLED=1` 才发送数据
   187|- `src/core/autonomy/pdca-engine.js`:`saveTrace()` 截断敏感字段,文件权限 0600
   188|

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

md
The ability to pause and ask: *What am I thinking right now? How am I perceiving this situation? Am I projecting?*

This is not error correction. It is a snapshot of the current cognitive state — taken without judgment, stored without modification.

### 2. Dreaming (experience synthesis)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a reflective cognition/philosophy engine, but the analyzed behavior set includes operational interfaces, persistence, subprocess execution, network services, and code-handling capabilities that are materially broader than the description. That mismatch is dangerous because reviewers and users may trust and install the skill under false assumptions, leading to over-privileged deployment and unexpected exposure of local resources or execution surfaces.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code-engine.js:68

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code-verifier.js:385

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code/code-executor.js:283

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/proactive/self-initiator.js:896

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/core/code-engine.js:1586

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/core/code-verifier.js:366

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/core/code/code-executor.js:472

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/proactive/self-initiator.js:484

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/core/search/hybrid-search.js:51

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/core/search/hybrid-search.js:421

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/utils/atomic-write.js:139