Back to skill

Security audit

system memory inspector

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local memory-inspection tool, but it persistently records all-process command lines without clear permission controls or privacy warnings.

Install only if you are comfortable with local system-wide process monitoring. Run it under the least-privileged account that still gives useful visibility, add `umask 077` or explicit `0700`/`0600` permissions before deployment, and consider removing or redacting command-line capture before using it on shared or production hosts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:188
Finding

Persistent Storage of Process Command Lines Without Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 188–223
Vulnerability Type: Sensitive information exposure through insecure file permissions
Risk Level: Medium

Vulnerable Code

bash
# Initialize directories
mkdir -p "$SNAPSHOT_DIR" "$TREND_DIR"

# Collect: PID, process name, RSS (MB), VmSize (MB), runtime, command line
echo "# System memory snapshot $TIMESTAMP" > "$snapshot_file"
echo "# PID|NAME|RSS|VSZ|TIME|CMD" >> "$snapshot_file"

# Command line (truncated)
cmd=$(cat "$pid_dir/cmdline" 2>/dev/null | tr '\0' ' ' | cut -c1-50 || echo "[kernel]")
[ -z "$cmd" ] && cmd="[$name]"

echo "$pid|$name|$rss_mb|$vsz_mb|$etime|$cmd" >> "$snapshot_file"

The configured storage location is /var/log/memory-inspector.

Technical Analysis

The script reads command-line arguments from /proc/<pid>/cmdline for every eligible process and persists the first 50 characters in timestamped snapshot files. Command-line arguments may contain passwords, API tokens, session credentials, database connection strings, internal paths, or other sensitive operational information.

Capturing command lines is not necessary for the declared memory-growth calculation, which only requires process identity, timestamps, and memory values. Moreover, the script neither establishes a restrictive umask nor explicitly assigns secure permissions to the directory and generated files. Their effective permissions therefore depend on the invoking environment. A common default umask may create files readable by users other than the intended administrator.

Running the scanner with elevated privileges increases the exposure because it may permit the collection of command lines belonging to services and users that an unprivileged scanner could not inspect.

Attack Path

  1. An administrator or scheduled job runs the scanner with sufficient privileges to inspect system-wide process metadata.
  2. A process has sensiti ...[truncated 1149 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not collect process command lines by default. Memory trend analysis should use only PID, process name, start time, RSS, and virtual-memory measurements.
  2. If command-line collection is explicitly required, make it opt-in and clearly warn that arguments may contain secrets.
  3. Set a restrictive process mask before creating any storage:
    bash
    umask 077
    
  4. Create the storage directories with explicit access controls:
    bash
    install -d -m 0700 "$SNAPSHOT_DIR" "$TREND_DIR"
    
  5. Create snapshots and reports with mode 0600, verify ownership, and reject unsafe pre-existing directories or symbolic links.
  6. Redact common secret-bearing arguments, including passwords, tokens, authorization headers, keys, and credential-bearing URLs. Prefer allowlisting safe metadata over pattern-based redaction.
  7. Run the scanner under a dedicated least-privileged account and grant only the process visibility required for the monitoring objective.
  8. Establish explicit retention and secure-deletion policies for snapshots, reports, cron logs, and exited-process trend records.
  9. Document who may access the monitoring data and avoid placing sensitive output in broadly readable logs.
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 479)May include surrounding context.

md
cleanup_old_data() {
    # 只保留最近 $MAX_HISTORY 个快照
    cd "$SNAPSHOT_DIR" && ls -t *.snapshot 2>/dev/null | tail -n +$((MAX_HISTORY+1)) | xargs -r rm -f
    
    # 清理已不存在进程的趋势文件
    for trend_file in "$TREND_DIR"/*.dat; do

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation describes memory inspection but does not clearly warn that the skill persistently records all-process snapshots, including command-line data, under /var/log. This lack of transparency can cause operators to deploy it without understanding the privacy and data-retention implications, increasing the chance of unintentional exposure of sensitive operational data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The usage section instructs users to run the script via cron and read reports but omits operational warnings that it writes files under /var/log and deletes old snapshots during cleanup. This can lead to accidental data retention, unexpected disk usage, or loss of forensic history, and it obscures that sensitive process metadata may be created on every run.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script collects and persists full process command lines from /proc//cmdline into snapshot files and reports. Command lines often contain secrets such as API tokens, database passwords, internal hostnames, file paths, and user data passed as arguments, so this expands the skill from memory inspection into sensitive process metadata collection and disclosure. Because the data is written to /var/log and echoed in reports, any user or process with access to those files may obtain information unrelated to the stated purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The documented purpose centers on periodic scanning, recording snapshots, and analyzing trends, but the cleanup routine actively renames per-process trend files to '.exited' when processes disappear. Although local persistence is expected, altering historical tracking artifacts for lifecycle management is broader than the described inspection behavior and is not mentioned in the manifest or documentation sections describing stored outputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.