Back to skill

Security audit

Auto Summarization Loop

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent long-conversation memory skill, but it stores and reuses personal conversation-derived data in privileged prompts without enough safeguards or user controls.

Install only if you are comfortable with the host application persisting conversation summaries and user profile facts. Before production use, require opt-in memory, deletion and retention controls, validation of summarizer output, redaction for sensitive data, and avoid placing untrusted summaries or profile fields in privileged system-role prompts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
scripts/memory_manager.py:94
Finding

Untrusted Conversation Data Is Persisted and Reintroduced as Privileged System Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/memory_manager.py:136
Finding

Conversation History Is Deleted Before Summarization Succeeds

Content
View full analysis
Remediation
View remediation
0` - `working_messages > 0` - `summary_max_tokens > 0` - `0 < soft_limit_ratio < hard_limit_ratio <= 1` 7. Use a durable append-only conversation log if message loss is unacceptable. Compression should alter only the model-facing projection, not the authoritative history. 8. Add tests for missing callbacks, exceptions, cancellation, malformed responses, empty summaries, and boundary values such as zero or negative retention counts. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly recommends storing user profiles and conversation summaries, including personal attributes, but does not document consent, retention limits, minimization, or deletion controls. In a long-lived memory system, this creates privacy and compliance risk because sensitive personal data may be retained and reused beyond user expectations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the system to retain structured personal user information in long-term memory for later reuse, including identity, location, profession, and preferences. This increases the risk of privacy leakage, over-collection, unauthorized profiling, and accidental resurfacing of sensitive data across future interactions, especially when persistence is built into session storage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all prompts, headings, and usage guidance exclusively in Chinese. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code forwards prior conversation content to the summarization callback, and that callback is intended to send the text to an external model. Because the conversation may contain sensitive personal or confidential data and there is no consent, disclosure, minimization, or redaction layer before transfer, this creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code persists extracted user facts into long-term memory with no notice, consent, retention policy, or validation of what facts are stored. This can silently accumulate personal data across sessions, increasing privacy exposure, compliance risk, and the impact of any later prompt leakage or storage compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file-level description is written as a Chinese-only test script description, and the script’s user-facing output strings are also entirely in Chinese. This indicates the skill is designed to operate in a fixed language without offering any user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description and operational guidance are presented in Chinese, and the file does not indicate that this language choice is optional or limited to a region-specific use case. Under the policy, forcing a specific language without user opt-in can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file's natural-language strings define a fixed persona and response style in Chinese, with no indication that the user can choose language or locale preferences. Under the policy, forcing a specific language or locale without opt-in can be a violation unless explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.