Back to skill

Security audit

emotional-memo

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local relationship memo that saves sensitive emotional notes in a JSON file, so users should treat the saved file as private.

Install only if you are comfortable with relationship notes, names, triggers, and follow-ups being saved locally in data/memo.json. Use nicknames, avoid unnecessary details, protect the workspace, and manually delete or secure the file when you no longer want the history retained.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Plaintext Storage of Sensitive Relationship Data with Unenforceable Access Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:17-25, 89-90, 107, 139, 187-188
Vulnerability Type: Plaintext sensitive-data storage and insufficient access control
Risk Level: Medium

Complete Vulnerable Snippets

markdown
All emotional data is stored in `data/memo.json`. Create this file on first use with the following structure:

```json
{
  "couple": {
    "person_a": "",
    "person_b": ""
  },
  "entries": [],
  "patterns": []
}
text

```markdown
2. Ask for the two people's nicknames or names: "What should I call you both?"
3. Create `data/memo.json` with the couple's names and empty entries/patterns arrays
markdown
6. **Close warmly** — "I've kept this safe 💛 Thank you for trusting me with it."
markdown
1. Read all entries from `data/memo.json`
markdown
- **Deletion consent:** Deleting another person's entry requires mutual agreement. One person cannot erase the other's recorded feelings.
- **Privacy:** If one person asks "what did they say about me?", do not reveal specific entries. Instead: "They've shared some feelings. It might be a good conversation to have together 💛"

Technical Analysis

The Skill instructs the Agent to collect and persist names, emotional events, relationship conflicts, triggers, underlying needs, and intensity ratings in a single JSON file. It does not require encryption at rest, restrictive file permissions, authenticated participant identities, participant-specific authorization, integrity protection, consent records, retention limits, or secure deletion.

Both participants' data is placed in the same shared file, and timeline reviews require reading every entry. The stated privacy and mutual-deletion rules are conversational policies rather than enforceable controls. Because the Agent has no documented mechanism for verifying who is speaking, a participant or other workspace user may impersonate another person or bypass the policy by directly accessing the file.

The ...[truncated 1582 chars]

Remediation
View remediation

Remediation Suggestions

  1. Obtain explicit, informed consent from every represented participant before persisting personal information.
  2. Minimize collection by avoiding names and unnecessary free-text details; support pseudonyms and local-only ephemeral sessions.
  3. Encrypt records at rest using a vetted authenticated-encryption mechanism, with keys stored separately from the data.
  4. Create files with restrictive permissions and verify that the storage directory is inaccessible to unrelated users and processes.
  5. Separate each participant's private records and enforce authenticated, participant-specific authorization for reading, updating, exporting, and deleting data.
  6. Do not rely on conversational claims for identity or mutual consent. Use a verifiable approval workflow for shared disclosure and deletion.
  7. Add integrity protection, validated schema updates, atomic writes, and protected backups to prevent undetected tampering or corruption.
  8. Define retention periods and provide authenticated export, revocation, and secure-deletion controls.
  9. Redact sensitive information from logs, backups, diagnostics, and error messages.
  10. Replace the unsupported “kept this safe” statement with an accurate disclosure of storage location, protections, access scope, and residual risks.
  11. Consider storing only consented summaries or pattern identifiers rather than complete descriptions of intimate events.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is explicitly designed to collect and store highly sensitive relationship data, including emotional events, triggers, and follow-up notes, but it does not prominently warn users that this information will be written to disk in data/memo.json. This creates a meaningful privacy and consent risk because users may disclose intimate material without understanding its persistence, local exposure, or later retrieval by the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The recording workflow uses very broad conversational cues like 'something happened', 'I felt...', and 'we had a fight', which can cause the assistant to persist sensitive emotional data when the user may only be venting, roleplaying, or asking for advice. In a relationship-memo skill, unintended writes are especially risky because the stored content is intimate, attributable, and later reused for reminders and pattern detection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The review workflow is activated by generic terms like 'review', 'look back', 'show history', and 'timeline', which can be invoked accidentally during ordinary conversation and cause disclosure of stored relationship history. Because the file contains sensitive interpersonal records, an overly loose retrieval trigger can expose private entries without sufficiently confirming that the user intended a full history readout.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.