Back to skill

Security audit

Deep Research (Gemini)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Gemini research tool, but its file-upload safeguards do not consistently match its promise to exclude sensitive files.

Review this before installing if you may run it over repositories containing secrets. Use --dry-run, prefer directory context over direct sensitive-looking files, restrict agent filesystem access, and manually check/delete Gemini file-search stores after failures or non-blocking runs. Treat exported HTML reports as untrusted unless sanitized or opened in a constrained environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/upload.py:345
Finding

Sensitive-file protections are bypassed for directly specified files

Content
View full analysis
Remediation
View remediation
None: if _is_sensitive_file(path): raise ValueError(f"Refusing to upload sensitive file: {path.name}") if _resolve_mime(path) is None: raise ValueError(f"Unsupported file type: {path.suffix}") ``` 2. Apply the validator to: - Direct `upload.py` files - Single-file `--context` input - `--file --use-file-store` - Inline `--file` input - Every file returned by recursive collection 3. Keep sensitive files denied by default, even if their MIME type is supported. 4. If an override is necessary, require an explicit flag such as `--allow-sensitive-file`, display the destination and filename, and require interactive confirmation. 5. Disable sensitive-file overrides in non-interactive Agent mode unless a separate trusted policy explicitly authorizes them. 6. Add regression tests covering `.env`, `.env.*`, `.npmrc`, `.netrc`, credential JSON files, SSH private-key names, and sensitive extensions through every input mode. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/research.py:833
Finding

Ephemeral context stores can remain remotely retained after errors

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/research.py:788
Finding

HTML report export preserves untrusted active HTML

Content
View full analysis
str: """Convert markdown text to a full HTML document.""" import markdown as _markdown body = _markdown.markdown( report_text, extensions=["fenced_code", "tables", "codehilite"], ) return _HTML_TEMPLATE.format(body=body) ``` ### Technical Analysis `report_text` originates from Gemini-generated output and may be influenced by researched web content, uploaded context, or prompt injection in source documents. It is therefore untrusted. Python-Markdown is used as a formatter, not an HTML sanitizer. Raw HTML supplied in Markdown can be preserved in the generated document. The converted body is then inserted directly into the final HTML template. An attacker who influences model output may cause an exported report to contain scripts, event-handler attributes, deceptive forms, embedded frames, or external resources. The risk is realized when a user opens the generated report in a browser. The PDF conversion path separately supplies a URL fetcher that blocks all URL retrieval, which is an appropriate mitigation for PDF SSRF. That protection does not sanitize HTML reports opened in a browser. ### Attack Path 1. An attacker places prompt-injection content in a researched web page or uploaded context file. 2. The content instructs or induces Gemini to include active raw HTML in its final report. 3. The user requests HTML output through `--format html`. 4. `_md_to_html()` preserves the raw HTML and inserts it into the report document. 5. The user opens the generated report in a browser. 6. Active content executes or initiates browser requests in the local report context. ### Impact Assessment The generated report does not directly execute with the Python process's operating-system ...[truncated 486 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/research.py:1
Finding

Execution-time dependencies use mutable unpinned version ranges

Content
View full analysis
=3.10" # dependencies = [ # "google-genai>=1.0.0", # "rich>=13.0.0", # "markdown>=3.5", # ] # /// ``` The other executable scripts use the same lower-bound-only pattern for `google-genai` and `rich`. ### Technical Analysis The Skill is intended to run through `uv run`, which resolves dependencies from the inline PEP 723 metadata. The dependency declarations use only minimum versions and provide no exact pins, upper bounds, committed lockfile, or package hashes. Consequently, code reviewed during the audit is not sufficient to determine the future runtime dependency set. A later package release satisfying the range can be installed and executed without a corresponding change to the Skill repository. This is particularly significant because dependencies run in a process that may have: - Access to Gemini API keys in environment variables - Read access to user-selected local files - Write access to the working directory - Network access - Authority to manage remote Gemini resources No evidence was found that the currently named packages are typosquatted or intentionally malicious. The vulnerability is the mutable, unaudited resolution policy. ### Attack Path 1. A dependency publisher account or distribution channel is compromised, or a future release introduces malicious behavior. 2. The malicious release retains a version satisfying a declaration such as `google-genai>=1.0.0`. 3. A user or Agent invokes a script with `uv run`. 4. The resolver selects and installs the newer satisfying release. 5. Package import or normal execution runs ...[truncated 787 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (88)

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
90% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · CHANGELOG.md (reported line 17)May include surrounding context.

md
## [2.1.1] - 2026-02-24

### Security
- **CRITICAL: SSRF via WeasyPrint** -- PDF export now uses a custom `url_fetcher` that blocks all URL fetching, preventing SSRF and local file exfiltration via malicious markdown (e.g., `![](file:///etc/passwd)` or `<img src="http://169.254.169.254/">`)
- **YAML frontmatter quoting** -- all SKILL.md values containing colons are now properly double-quoted, and the `metadata` field is single-quoted. Fixes YAML parse failures in Codex, ClawHub scanner, and strict YAML parsers that caused the "suspicious" classification
- **Follow-up sanitization hardened** -- now strips ALL XML-like tags from previous research output (was only stripping `</previous_findings>`), preventing prompt injection via `<system>`, `<instructions>`, or delimiter escape attacks

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · CHANGELOG.md (reported line 65)May include surrounding context.

md
- **Store garbage collection** (`state.py gc`) -- clean up orphaned ephemeral context stores older than 24 hours from crashed runs

### Security
- Removed all `curl | sh` install patterns from documentation (VirusTotal supply chain risk flag)
- Sanitized `--follow-up` output with data delimiters to mitigate prompt injection from compromised previous research output

## [1.3.1] - 2026-02-19

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 27)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAUDE.md (reported line 7)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/file-search-mime-types.md (reported line 125)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/file_search_guide.md (reported line 71)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/research.py (reported line 95)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/research.py (reported line 233)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/research.py (reported line 262)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload.py (reported line 90)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload.py (reported line 194)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 27)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAUDE.md (reported line 7)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/research.py (reported line 262)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload.py (reported line 194)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 27)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAUDE.md (reported line 7)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/research.py (reported line 260)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload.py (reported line 193)May include surrounding context.

python
1. **YAML frontmatter quoting**: All SKILL.md frontmatter values containing colons MUST be double-quoted. The `metadata` field MUST be a single-quoted JSON string (not nested YAML). Test with `python3 -c "import yaml; yaml.safe_load(open('SKILL.md').read().split('---')[1])"` before committing.

2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 17)May include surrounding context.

md
2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

4. **Follow-up sanitization**: The `--follow-up` feature MUST strip all XML-like tags from previous research output before injecting it into the new query. Use `re.sub(r"<[^>]{1,50}>", "", text)` to prevent prompt injection via `<system>`, `<tool_call>`, or delimiter escape attacks.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CLAUDE.md (reported line 9)May include surrounding context.

md
2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

4. **Follow-up sanitization**: The `--follow-up` feature MUST strip all XML-like tags from previous research output before injecting it into the new query. Use `re.sub(r"<[^>]{1,50}>", "", text)` to prevent prompt injection via `<system>`, `<tool_call>`, or delimiter escape attacks.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/research.py (reported line 815)May include surrounding context.

python
2. **Sensitive file filtering**: The `_collect_files` function in research.py and `collect_files` in upload.py MUST skip `.env*`, `credentials.json`, `secrets.*`, private keys (`.pem`, `.key`), and auth tokens (`.npmrc`, `.pypirc`, `.netrc`). Never remove this filtering.

3. **WeasyPrint SSRF protection**: The PDF export (`--format pdf`) MUST use a custom `url_fetcher` that blocks all URL fetching. Never pass WeasyPrint an HTML string without this protection -- AI-generated markdown can contain `![](file:///etc/passwd)` or SSRF payloads.

4. **Follow-up sanitization**: The `--follow-up` feature MUST strip all XML-like tags from previous research output before injecting it into the new query. Use `re.sub(r"<[^>]{1,50}>", "", text)` to prevent prompt injection via `<system>`, `<tool_call>`, or delimiter escape attacks.

Static analysis

No suspicious patterns detected.