Back to skill

Security audit

Mark Heartflow Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it needs Review because it combines a memory/reflection engine with under-disclosed code execution and privileged memory injection.

Install only if you intentionally want a persistent local cognitive/memory service and are comfortable with it storing conversation traces. Treat the code-execution dispatch routes and memory-to-system-prompt plugin as high-risk: keep them disabled or isolated unless explicitly needed, review and delete stored memories regularly, and avoid exposing the HTTP MCP server beyond localhost.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
src/memory/heartflow-memory.js:242
Finding

Persistent system-prompt injection through attacker-controlled memory

Content
View full analysis
5) { this.learn(`conversation:${uid}`, input, ['conversation', 'user_input']); } // 2. Detected emotional signal is recorded in LEARNED memory. const pain = this._extractPain(judgment); if (pain) { this.learn(`pain:${uid}`, `用户情绪信号: ${pain}`, ['emotion', 'pain']); } // 3. Current context is recorded in EPHEMERAL memory. const what = judgment.whatIsThis; if (what) { this.remember(`context:now`, { whatIsThis: typeof what === 'object' ? (what.scenario || what.category || 'unknown') : 'unknown', shouldRespond: judgment.shouldRespond, }, 3600000); } // 4. Technical-operation input is recorded verbatim in LEARNED memory. if (input.includes('修') || input.includes('改') || input.includes('升级') || input.includes('优化')) { this.learn(`tech:${uid}`, input, ['tech', 'operation']); } return { recorded: true }; } ``` ```javascript // scripts/heartflow-memory-inject.js:73-88 const pains = learnedEntries.filter(e => e.tags?.includes('pain')); const techOps = learnedEntries.filter(e => e.tags?.includes('tech')); if (pains.length > 0) { lines.push(''); lines.push('【情绪信号】'); for (const e of pains.slice(0, 5)) { lines.push(` • ${e.value}`); } } if (techOps.length > 0) { lines.push(''); lines.push('【技术操作记录】'); for (const e of techOps.slice(0, 10) ...[truncated 3348 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/core/code/code-executor.js:545
Finding

Public dispatch route permits unrestricted host shell and Python execution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (701)

Known Vulnerable Dependency: protobufjs==6.11.6 — 11 advisory(ies): CVE-2026-44294 (protobuf.js: Denial of service from crafted field names in generated code); CVE-2026-44293 (protobuf.js: Code injection through bytes field defaults in generated toObject c); CVE-2026-44289 (protobuf.js: Denial of service through unbounded protobuf recursion) +8 more

Critical
Category
Supply Chain
Confidence
97% confidence
Finding

The lockfile pins protobufjs to 6.11.6, and the reported advisories include denial-of-service and code-injection issues in code generation paths. Even though this skill file is only a dependency manifest, shipping a known vulnerable version is a real supply-chain risk because downstream execution paths may invoke the affected parser or generator behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The dispatch allowlist explicitly exposes routes such as codeExecutor.execute, codeExecutor.runTests, and other code-manipulation methods. A centralized dispatcher plus a broad whitelist creates a ready invocation path for arbitrary code-related actions, which is especially dangerous because the skill's stated role is reflective cognition rather than code execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The changelog documents code execution, script execution, and code-generation features that materially exceed the declared purpose of a reflective cognitive engine. Capability drift of this kind is dangerous because operators may grant the skill access based on its benign-sounding description while the actual implementation supports actions that can modify files, execute code, or orchestrate tasks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

JavaScript, Shell, and Python execution are high-risk primitives, especially when attached to a skill whose stated purpose is introspection rather than task execution. Even if intended for benign testing, these primitives can be abused for local command execution, file manipulation, network pivoting, or secret exposure if the surrounding environment grants access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Mini-agent/task-initiation and script-execution features create autonomous action pathways that are not justified by the declared philosophical/cognitive role. In this context, the mismatch increases risk because a user or platform may permit the skill under assumptions appropriate for reflection, while the skill can actually plan and trigger actions with far greater operational impact.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 325)May include surrounding context.

md
167|#### 修复类别一:描述与行为不匹配
   168|- `package.json`:description 精确匹配 SKILL.md 认知/自愈引擎描述
   169|- `CHANGELOG.md`:标注 MarkCode 为可选独立组件,避免误导
   170|- `skills/video-generate/SKILL.md`:移除"自动写入 API 密钥到 .env"危险指令
   171|- `skills/zai-vision/SKILL.md`:添加安全警告,说明数据外传风险
   172|- `skills/desktop-agent/SKILL.md`:添加高风险警告,默认禁用说明
   173|- `skills/browser-automation/SKILL.md`:添加安全警告,说明网络访问范围

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 340)May include surrounding context.

md
182|- `scripts/awakening-integration.js`:添加安全头部,标注为哲学思考框架
   183|
   184|#### 修复类别三:数据泄露风险
   185|- `plugins/agentmemory/__init__.py`:移除 `_preload_agentmemory_dotenv()`,不再自动读取 .env
   186|- `plugins/agentmemory/__init__.py`:`sync_turn()` 默认禁用,需 `AGENTMEMORY_OBSERVE_ENABLED=1` 才发送数据
   187|- `src/core/autonomy/pdca-engine.js`:`saveTrace()` 截断敏感字段,文件权限 0600
   188|

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

md
The ability to pause and ask: *What am I thinking right now? How am I perceiving this situation? Am I projecting?*

This is not error correction. It is a snapshot of the current cognitive state — taken without judgment, stored without modification.

### 2. Dreaming (experience synthesis)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents a philosophical self-reflection engine, while the detected behavior includes operational interfaces, process control, local IPC, file I/O, network services, prompt injection, subprocess execution, model downloading, and in some cases arbitrary code execution. This is dangerous because security review, user consent, and sandbox policy may be based on the benign-sounding description rather than the actual attack surface.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code-engine.js:68

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code-verifier.js:385

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code/code-executor.js:283

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/proactive/self-initiator.js:896

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/core/code-engine.js:1586

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/core/code-verifier.js:366

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/core/code/code-executor.js:472

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/proactive/self-initiator.js:484

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/core/search/hybrid-search.js:51

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/core/search/hybrid-search.js:421

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/utils/atomic-write.js:139