T01 · Skill Instruction Hijacking
- Location
scripts/memory_manager.py:94- Finding
Untrusted Conversation Data Is Persisted and Reintroduced as Privileged System Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent long-conversation memory skill, but it stores and reuses personal conversation-derived data in privileged prompts without enough safeguards or user controls.
Install only if you are comfortable with the host application persisting conversation summaries and user profile facts. Before production use, require opt-in memory, deletion and retention controls, validation of summarizer output, redaction for sensitive data, and avoid placing untrusted summaries or profile fields in privileged system-role prompts.
scripts/memory_manager.py:94Untrusted Conversation Data Is Persisted and Reintroduced as Privileged System Content
scripts/memory_manager.py:136Conversation History Is Deleted Before Summarization Succeeds
The skill explicitly recommends storing user profiles and conversation summaries, including personal attributes, but does not document consent, retention limits, minimization, or deletion controls. In a long-lived memory system, this creates privacy and compliance risk because sensitive personal data may be retained and reused beyond user expectations.
The skill directs the system to retain structured personal user information in long-term memory for later reuse, including identity, location, profession, and preferences. This increases the risk of privacy leakage, over-collection, unauthorized profiling, and accidental resurfacing of sensitive data across future interactions, especially when persistence is built into session storage.
This markdown file presents all prompts, headings, and usage guidance exclusively in Chinese. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.
The code forwards prior conversation content to the summarization callback, and that callback is intended to send the text to an external model. Because the conversation may contain sensitive personal or confidential data and there is no consent, disclosure, minimization, or redaction layer before transfer, this creates a real privacy and data-handling risk.
The code persists extracted user facts into long-term memory with no notice, consent, retention policy, or validation of what facts are stored. This can silently accumulate personal data across sessions, increasing privacy exposure, compliance risk, and the impact of any later prompt leakage or storage compromise.
The file-level description is written as a Chinese-only test script description, and the script’s user-facing output strings are also entirely in Chinese. This indicates the skill is designed to operate in a fixed language without offering any user choice or documenting a justified locale restriction.
The natural-language description and operational guidance are presented in Chinese, and the file does not indicate that this language choice is optional or limited to a region-specific use case. Under the policy, forcing a specific language without user opt-in can be a locale/language policy issue.
The file's natural-language strings define a fixed persona and response style in Chinese, with no indication that the user can choose language or locale preferences. Under the policy, forcing a specific language or locale without opt-in can be a violation unless explicitly justified.
No suspicious patterns detected.